We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

BitLocker question

Yolina
Yolina Posts: 2,262 Forumite
Laptop with Win 8 Pro and BitLocker. Before I go about encrypting the drives, how does it work in the event of restoring a backup from external HDD or having to use Windows recovery media? I'm just slightly worried it could all turn into a ginormous PITA...
Now free from the incompetence of vodafail
«1

Comments

  • John_Gray
    John_Gray Posts: 5,845 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    You could do worse than to read through what Wikipedia says about BitLocker.
    Then read What Bitlocker does, and what it doesn't do.

    Yes, undoubtedly a PITA. Truecrypt is probably better - but it depends on precisely what you are trying to achieve!
  • Yolina
    Yolina Posts: 2,262 Forumite
    edited 13 May 2013 at 1:46PM
    I know what it does, but thanks :)

    My question was more specific:
    Let's assume my drives are BitLocked and something goes wrong with the laptop. If I need to use the recovery partition/physical recovery media, or restore a full image then how does it all play together? I am really having a hard time finding that exact info and that's something I'd like to know beforehand :p
    Now free from the incompetence of vodafail
  • John_Gray
    John_Gray Posts: 5,845 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Photogenic
    Does this writeup, about Macrium Reflect and Bitlocker, assist in any way?
  • Yolina
    Yolina Posts: 2,262 Forumite
    edited 13 May 2013 at 2:46PM
    Possibly :) will do some more digging. You'd think that kind of fairly essential info (IMHO!) would be readily available, but for some reason isn't. Could well be that it is fairly straightforward (i.e along the lines of "do Windows recovery as normal and input BitLocker password/recovery key when prompted") but...
    Now free from the incompetence of vodafail
  • S0litaire
    S0litaire Posts: 3,535 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    I think you can't do a "bare metal" restore with BitLocker (i'e blank drive and an encrypted backup!)

    *NOTE*
    I've never used Bitlocker, I'd rather go with a trusted 3rd party program who have recovery options well worked out and documented.

    From what I've read, you need to use the recovery disk, install the Base OS and then use that to open the bitlocked backup using the 48 digit key that was created when you first used bitlocker either by hand or as a file on a USB stick.

    Then you can access the encrypted drive to restore the system.

    Then recovery can read the drive and decrypt the backup.

    http://social.microsoft.com/Forums/en-US/whssoftware/thread/01532e7a-9d27-425e-b183-20c533cb9196/
    Laters

    Sol

    "Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"
  • Yolina
    Yolina Posts: 2,262 Forumite
    The backup wouldn't be bitlockered... let's try again, and I hope I can make things clear this time :rotfl:

    - SSD which I partitioned into C: & D:
    - there are 3 other included partitions: OEM recovery partition, Recovery partition, EFI system partition
    - I also have put recovery on physical media - one done via the Windows utility and the other via the manufacturer (Sony) utility;
    - C: & D: would be bitlockered with password (+ obviously recovery key stashed away somewhere safe!)
    - what happens if for any reason the laptop throws a tantrum and I have to boot into recovery and then either need to repair or reinstall the OS without being able to unlock the drives first?

    I went for a nosey in the MS tech library and couldn't find an answer there...
    Now free from the incompetence of vodafail
  • S0litaire
    S0litaire Posts: 3,535 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    OK think i posted the wrong link >_<
    Try this:

    http://answers.microsoft.com/en-us/windows/forum/windows_vista-system/how-do-i-restore-my-bitlocker-encrypted-computer/85c3e924-5cb3-42ec-b215-fa8776b12597

    Recovery has the ability to decrypt drives if you have the passkey handy.

    Recovery password and recovery key

    "When you set up BitLocker, you must create a recovery password. In the event that your computer enters a recovery state, you need this recovery information (either a recovery password or recovery key) to unlock the encrypted data on the volume. You can save the recovery password in one of these formats:
    • As a numerical password consisting of 48 digits divided into 8 groups. During recovery, you need to type this password into the BitLocker recovery console by using the function keys on your keyboard.
    • As a recovery key stored as a file on a USB flash drive, in a format that can be read directly by the BitLocker recovery console. During recovery, you need to insert this USB device."
    Laters

    Sol

    "Have you found the secrets of the universe? Asked Zebade "I'm sure I left them here somewhere"
  • Yolina
    Yolina Posts: 2,262 Forumite
    edited 13 May 2013 at 6:19PM
    I saw something similar in the Win 8 BitLocker tech library, but the "recovery state" was referring to BitLocker recovery mode, rather than the "normal" computer recovery - that why I'm finding it all so damned confusing...
    And the standard (consumer) MS help pages only refer to turning BL on/off and that kind of things, but no "what to do when the SHTF and your drive is bitlockered". Obviously a non-issue if I am still able to access settings and decrypt *before* booting into recovery, but still not sure of how it all works if I can't. Hopefully I never have to find out :rotfl: but it would have been nice to hear if anyone had any experience of it.
    Now free from the incompetence of vodafail
  • Yolina
    Yolina Posts: 2,262 Forumite
    edited 13 May 2013 at 9:18PM
    The solution offered to people who have forgotten their pw and lost recovery key (!) is to delete partition, format & reinstall - so that puts my mind at rest as to any potential issues :) as I have backups galore anyway.

    So the way it *should* work is that booting into system recovery with drives still locked would call for BL password or recovery key to be entered and then proceed as normal. And if for whatever reasons there's issues, then just wipe the lot :p
    Now free from the incompetence of vodafail
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.2K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.