BitLocker key change question

Posted: 04-24-2006, 11:48 PM
When you change the bitlocker key, the drive does get re-encrypted?
Sector by sector. What happens if the computer re-boots/ loses power during
this process. Are there TWO keys active at that point?
Reply With Quote

Responses to "BitLocker key change question"

Zack Whittaker
Guest
Posts: n/a
 
Re: BitLocker key change question
Posted: 04-25-2006, 01:09 AM
Not entirely 100% sure on this one, but I do hope to be of some help )

When you change the key, the drive does become re-encrypted inline with the
new key. From what I imagine, if you try and understand that the way the
drive encrypts depends on the key you first type, so if you type in the same
key on another machine, in theory it could be encrypted the same way (I
think...)

If the computer reboots, not necessarily in beta builds (so might apply to
the public release), the encryption will either kick off from where it left
off, or decrypt it and ask for the key again - whether it's the same key you
used before the encryption or whether it starts the whole process off again,
still not sure.

I do think it'll vary on the software/hardware types of encryption though -
you can get hardware chips with encryption stuff on it, so this may change
how things encrypt and whether the answers I gave still apply or not. It's
sketchy... but I hope that sheds *some* light on it ) We'll definately
know when the public release comes out, as will a whole load of
documentation comes with it.

--
Zack Whittaker
» ZackNET Enterprises: www.zacknet.co.uk
» MSBlog on ResDev: www.msblog.org
» Vista Knowledge Base: www.vistabase.co.uk
» This mailing is provided "as is" with no warranties, and confers no
rights. All opinions expressed are those of myself unless stated so, and not
of my employer, best friend, Ghandi, my mother or my cat. Glad we cleared
that up!

--: Original message follows :--
"Dominik" <Dominik@discussions.microsoft.com> wrote in message
news:03D924D8-0385-4CA9-9030-9F7044AED726@microsoft.com...
> When you change the bitlocker key, the drive does get re-encrypted?
> Sector by sector. What happens if the computer re-boots/ loses power
> during
> this process. Are there TWO keys active at that point?

Reply With Quote
Dominik
Guest
Posts: n/a
 
Re: BitLocker key change question
Posted: 04-25-2006, 01:45 AM
Thanks.
It probably keeps a sector pointer; any sector before it is encrypted the
NEW FVE key and any sector after it will be ecrypted with the OLD FVE key.
This pointer will be moved forward.

Dominik

"Zack Whittaker" wrote:
> Not entirely 100% sure on this one, but I do hope to be of some help )
>
> When you change the key, the drive does become re-encrypted inline with the
> new key. From what I imagine, if you try and understand that the way the
> drive encrypts depends on the key you first type, so if you type in the same
> key on another machine, in theory it could be encrypted the same way (I
> think...)
>
> If the computer reboots, not necessarily in beta builds (so might apply to
> the public release), the encryption will either kick off from where it left
> off, or decrypt it and ask for the key again - whether it's the same key you
> used before the encryption or whether it starts the whole process off again,
> still not sure.
Reply With Quote
Josh
Guest
Posts: n/a
 
Re: BitLocker key change question
Posted: 05-09-2006, 07:05 PM
This isn't accurate.

Dominik,

the info you want is here.

http://www.microsoft.com/technet/win...y/bittech.mspx

They use two keys so that they don't have to decrypt/reencrypt the drive on
a rekey.

josh
http://windowsconnected.com


"Zack Whittaker" <admin@zacknet.co.uk> wrote in message
news:OMz03x$ZGHA.5088@TK2MSFTNGP03.phx.gbl...
> Not entirely 100% sure on this one, but I do hope to be of some help )
>
> When you change the key, the drive does become re-encrypted inline with
> the new key. From what I imagine, if you try and understand that the way
> the drive encrypts depends on the key you first type, so if you type in
> the same key on another machine, in theory it could be encrypted the same
> way (I think...)
>
> If the computer reboots, not necessarily in beta builds (so might apply to
> the public release), the encryption will either kick off from where it
> left off, or decrypt it and ask for the key again - whether it's the same
> key you used before the encryption or whether it starts the whole process
> off again, still not sure.
>
> I do think it'll vary on the software/hardware types of encryption
> though - you can get hardware chips with encryption stuff on it, so this
> may change how things encrypt and whether the answers I gave still apply
> or not. It's sketchy... but I hope that sheds *some* light on it ) We'll
> definately know when the public release comes out, as will a whole load of
> documentation comes with it.
>
> --
> Zack Whittaker
> » ZackNET Enterprises: www.zacknet.co.uk
> » MSBlog on ResDev: www.msblog.org
> » Vista Knowledge Base: www.vistabase.co.uk
> » This mailing is provided "as is" with no warranties, and confers no
> rights. All opinions expressed are those of myself unless stated so, and
> not
> of my employer, best friend, Ghandi, my mother or my cat. Glad we cleared
> that up!
>
> --: Original message follows :--
> "Dominik" <Dominik@discussions.microsoft.com> wrote in message
> news:03D924D8-0385-4CA9-9030-9F7044AED726@microsoft.com...
>> When you change the bitlocker key, the drive does get re-encrypted?
>> Sector by sector. What happens if the computer re-boots/ loses power
>> during
>> this process. Are there TWO keys active at that point?
>
>

Reply With Quote
Dominik
Guest
Posts: n/a
 
Re: BitLocker key change question
Posted: 05-09-2006, 09:58 PM
Thank you very much! That good article describes it well.

Dominik

"Josh" wrote:
> This isn't accurate.
>
> Dominik,
>
> the info you want is here.
>
> http://www.microsoft.com/technet/win...y/bittech.mspx
>
> They use two keys so that they don't have to decrypt/reencrypt the drive on
> a rekey.
>
> josh
> http://windowsconnected.com
>
>
> "Zack Whittaker" <admin@zacknet.co.uk> wrote in message
> news:OMz03x$ZGHA.5088@TK2MSFTNGP03.phx.gbl...
> > Not entirely 100% sure on this one, but I do hope to be of some help )
> >
> > When you change the key, the drive does become re-encrypted inline with
> > the new key. From what I imagine, if you try and understand that the way
> > the drive encrypts depends on the key you first type, so if you type in
> > the same key on another machine, in theory it could be encrypted the same
> > way (I think...)
> >
> > If the computer reboots, not necessarily in beta builds (so might apply to
> > the public release), the encryption will either kick off from where it
> > left off, or decrypt it and ask for the key again - whether it's the same
> > key you used before the encryption or whether it starts the whole process
> > off again, still not sure.
> >
> > I do think it'll vary on the software/hardware types of encryption
> > though - you can get hardware chips with encryption stuff on it, so this
> > may change how things encrypt and whether the answers I gave still apply
> > or not. It's sketchy... but I hope that sheds *some* light on it ) We'll
> > definately know when the public release comes out, as will a whole load of
> > documentation comes with it.
> >
> > --
> > Zack Whittaker
> > » ZackNET Enterprises: www.zacknet.co.uk
> > » MSBlog on ResDev: www.msblog.org
> > » Vista Knowledge Base: www.vistabase.co.uk
> > » This mailing is provided "as is" with no warranties, and confers no
> > rights. All opinions expressed are those of myself unless stated so, and
> > not
> > of my employer, best friend, Ghandi, my mother or my cat. Glad we cleared
> > that up!
> >
> > --: Original message follows :--
> > "Dominik" <Dominik@discussions.microsoft.com> wrote in message
> > news:03D924D8-0385-4CA9-9030-9F7044AED726@microsoft.com...
> >> When you change the bitlocker key, the drive does get re-encrypted?
> >> Sector by sector. What happens if the computer re-boots/ loses power
> >> during
> >> this process. Are there TWO keys active at that point?
> >
> >
>
>
>
Reply With Quote
Jamie Hunter [MS]
Guest
Posts: n/a
 
Re: BitLocker key change question
Posted: 06-12-2006, 11:00 PM
Glad that article helped!
-
Jamie Hunter [MS]

"Dominik" <Dominik@discussions.microsoft.com> wrote in message
news:9C1B34CA-C20D-4F5F-A993-CEF885BACD16@microsoft.com...
> Thank you very much! That good article describes it well.
>
> Dominik
>
> "Josh" wrote:
>
>> This isn't accurate.
>>
>> Dominik,
>>
>> the info you want is here.
>>
>> http://www.microsoft.com/technet/win...y/bittech.mspx
>>
>> They use two keys so that they don't have to decrypt/reencrypt the drive
>> on
>> a rekey.
>>
>> josh
>> http://windowsconnected.com
>>
>>
>> "Zack Whittaker" <admin@zacknet.co.uk> wrote in message
>> news:OMz03x$ZGHA.5088@TK2MSFTNGP03.phx.gbl...
>> > Not entirely 100% sure on this one, but I do hope to be of some help
>> > )
>> >
>> > When you change the key, the drive does become re-encrypted inline with
>> > the new key. From what I imagine, if you try and understand that the
>> > way
>> > the drive encrypts depends on the key you first type, so if you type in
>> > the same key on another machine, in theory it could be encrypted the
>> > same
>> > way (I think...)
>> >
>> > If the computer reboots, not necessarily in beta builds (so might apply
>> > to
>> > the public release), the encryption will either kick off from where it
>> > left off, or decrypt it and ask for the key again - whether it's the
>> > same
>> > key you used before the encryption or whether it starts the whole
>> > process
>> > off again, still not sure.
>> >
>> > I do think it'll vary on the software/hardware types of encryption
>> > though - you can get hardware chips with encryption stuff on it, so
>> > this
>> > may change how things encrypt and whether the answers I gave still
>> > apply
>> > or not. It's sketchy... but I hope that sheds *some* light on it )
>> > We'll
>> > definately know when the public release comes out, as will a whole load
>> > of
>> > documentation comes with it.
>> >
>> > --
>> > Zack Whittaker
>> > » ZackNET Enterprises: www.zacknet.co.uk
>> > » MSBlog on ResDev: www.msblog.org
>> > » Vista Knowledge Base: www.vistabase.co.uk
>> > » This mailing is provided "as is" with no warranties, and confers no
>> > rights. All opinions expressed are those of myself unless stated so,
>> > and
>> > not
>> > of my employer, best friend, Ghandi, my mother or my cat. Glad we
>> > cleared
>> > that up!
>> >
>> > --: Original message follows :--
>> > "Dominik" <Dominik@discussions.microsoft.com> wrote in message
>> > news:03D924D8-0385-4CA9-9030-9F7044AED726@microsoft.com...
>> >> When you change the bitlocker key, the drive does get re-encrypted?
>> >> Sector by sector. What happens if the computer re-boots/ loses power
>> >> during
>> >> this process. Are there TWO keys active at that point?
>> >
>> >
>>
>>
>>
Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


Similar Threads
Thread Thread Starter Forum Replies Last Post
question Aidan Windows Vista Install & Setup 16 10-12-2007 01:40 AM
How do I change my WEP key? Brian Windows Vista Networking & Sharing 3 07-20-2006 11:00 AM
How do I change WEP key? Brian Windows Vista Networking & Sharing 1 06-02-2006 02:50 PM
BitLocker Lost Password Stefan Windows Vista Security 6 03-24-2006 03:05 PM
Bitlocker Drive Encryption on 5308? news.microsoft.com Windows Vista 3 03-08-2006 09:24 AM