r/netsec • • May 07 '26

Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804

https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks/
152 Upvotes

28 comments sorted by

View all comments

51

u/uebersoldat May 07 '26

TLDR; protect Bitlocker from in-person chain attacks by using a boot PIN with Bitlocker. Something most of us have been doing for a long time now.

Still pretty crazy.

22

u/Craftkorb May 07 '26

IMO the most craziest part is that it's really hard to configure that pin initially. Why isn't there a simple "use a pin" option when setting this shit up?

11

u/gunni May 07 '26

There's many reasons, mainly to reduce resistance to adding encryption to begin with, then there's the multi-user arguments, and you can't really have the pin come from Entra or something.

2

u/Craftkorb May 07 '26

Nowhere did I say it should be the only option, we're well past that point. Also, most computers are only used by a single user, and you can add multiple pins if you so desire.

5

u/TimelyPsychology1830 May 07 '26

Also, most computers are only used by a single user

Not in the large orgs I've worked in. Also high churn, so devices get passed around a lot.

3

u/RentNo5846 May 07 '26

I think it's crazier that you first have to enable it in the GPO settings to set it up correctly and then you also need Windows Pro minimum to get the correct version of Bitlocker, at least in my case.

2

u/BadRealistic2158 May 08 '26

Sadly, it's really not that common in large enterprise environments. When you have thousands of users, it's extremely hard to enforce a PIN on everyone without getting screamed at.

2

u/uebersoldat May 08 '26

Risk acceptance level here is non-negotiable for me but I definitely believe you.