Bitlocker, TPM modules and USB disks

Soldato
Joined
6 Sep 2008
Posts
3,974
Location
By the sea, West Sussex
Hi All,

Anyone have experience of the above?

I've got a file server (W2K8 R2) running RAID6 and I backup irreplaceable files on to 1 USB disk every night except Sunday where I run the same backup again to another disk which I store away from the house.

It dawned on me that the USB disks are unencrypted and anyone who could get hold of them could access my data - nothing major but you never can tell what can be useful to someone with little morals these days.

My server has a TPM module, and a quick read about Bitlocker suggests I can encrypt the USB disks almost invisibly (ie needs no passcode or other intervention) with those. But I need to be able to read those disks elsewhere should the server die / house burns or floods etc.

Can I have the disk work seemlessly in the server using tthe TPM module in the server and with a passcode in another machine or is a one or the other affair??


Thanks in advance


Pete
 
As I understand it, the TPM is used as a way of allowing seamless encryption [you are not prompted for the password etc] and to also check the hardware has not changed in anyway [adding/removing hardware will change the snapshot the TPM stores and will cause it to prompt the user for their password].

So, in the event the TPM is broken, missing or never been present [i.e. drive is on another machine] you can still access the data, you just have to enter the unlock keys manually.

All of the above is what I gleaned from a quick nosey through the Bitlocker stuff. You should probably dig a little deeper to be 100% sure I am not talking out of my arse before going ahead! :D
 
Ahhhh so the TPM module is effectively like a keyring that simply holds the passcode removing the need to enter it manually, but that process still takes place behind the scenes.

I might just give it a go. I used to have the time to just sit around and try stuff like this and time is very tight since a change of work location so I like to make sure I'm not wasting my time first!!
 
Back
Top Bottom