• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

TPM with hardware encryption

gregster

n00b
Joined
Dec 16, 2009
Messages
24
I'm looking to get a new SSD for my laptop, which unfortunately doesn't have a TPM chip. Some of the newer drives are compatible with MS' Edrive spec (Windows 8 feature) which is supposed to allow hardware encryption at the drive level.

What I'm unclear about, is whether there is any way to use Bitlocker without a TPM chip and without a USB key? All the docs I've read indicate you need to plug in the USB key everytime you boot, with no alternatives should you not have TPM. There doesn't seem to be any info out there as to whether this has changed with the new feature set (enabled by setting HDD password in the BIOS).
 
As an addition to the above post: the TPM is not involved in the encryption process itself, it just stores the key. So using a drive with built-in encryption that works with bitlocker just means that the drive does the encryption and not the processor. The role of the TPM stays the same: to store the key.
 
Right...I am wondering if there are any options other than a USB key with the new Windows 8 encryption features. I may need to go with something like Truecrypt instead.
 
Yes, there is, it is described in Zedicus' link. You then have to enter a passphrase every boot. I know it works, because I used it for some time.
 
Yes, there is, it is described in Zedicus' link. You then have to enter a passphrase every boot. I know it works, because I used it for some time.

I did perform the local policy modification via gpedit on my laptop, but as shown in the article, it still requires a startup key (USB) on each boot. Unless I am really missing something, it appears you can't go with just a PIN entered via keyboard unless you have TPM?

I see this same screen that they do in the article: http://cdn.howtogeek.com/wp-content/uploads/2009/11/sshot20091104185856.png
 
The first link I made up there is a gallery of images of the steps to do Bitlocker with the m500, and on the third image, if you don't have a TPM, there's an option which you apparently must select that says "Allow Bitlocker without a compatible TPM (requires a password or startup key on a USB flash drive)". In the more detailed info to the right, it is further clarified that "In this mode either a password or a USB drive is required for start-up."

Are the first three images in the gallery not what you are seeing?
 
You know what, the password option might be a Windows 8 feature. I am trying this on Win7 Pro and only see the USB key option. One reason to upgrade then.
 
Yes, it works only with Windows 8. I assumed you use Windows 8 since you mentioned it in the initial post.
 
Back
Top