How is TPM more secure than USB?

Page 2 of 2 FirstFirst 12

  1. Posts : 1,746
    Windows 10 Pro x64 22H2
    Thread Starter
       #11

    I'll try to be more specific.

    disk partition layout in windows 10 is like this:

    How is TPM more secure than USB?-dep-win10-partitions-uefi.png

    Image from this site:
    UEFI/GPT-based hard drive partitions

    What I want to know is, which partitions (from the image above) gets encrypted when using TPM, and when using USB method, is there a difference?
      My Computer


  2. Posts : 1,064
    windows 10
       #12

    There is no difference in bitloker operation between a tpm or without tpm but with a usb disk. It's the security that changes, the tpm is much better than only with a usb hdd without tpm.


    The tpm protects the computer from tampering when the system is offline, with a tpm there is a system integrity check before booting.
    With a tpm there is multi-factor authentication, for example a pin code and/or a usb hdd.
      My Computer


  3. Posts : 5,048
    Windows 10/11 Pro x64, Various Linux Builds, Networking, Storage, Cybersecurity Specialty.
       #13

    zebal said:
    I'll try to be more specific.

    disk partition layout in windows 10 is like this:

    How is TPM more secure than USB?-dep-win10-partitions-uefi.png

    Image from this site:
    UEFI/GPT-based hard drive partitions

    What I want to know is, which partitions (from the image above) gets encrypted when using TPM, and when using USB method, is there a difference?
    BTW - it’s MBR (Master Boot Record.)

    What @itsme correctly pointed out above is the answer.

    HTH,

      My Computer


  4. Posts : 41,460
    windows 10 professional version 1607 build 14393.969 64 bit
       #14

    Code:
    BitLocker Drive Encryption Partitioning Requirements
    BitLocker must use a system partition that is separate from the Windows partition. 
    
    
    The system partition:
    
    Must be configured as the active partition.
    Must not be encrypted or used to store user files.
    Must have at least 250 MB of space.
    May be shared with a recovery partition.


    https://docs.microsoft.com/en-us/win...iew=windows-11



    Code:
    What is the recommended boot order for computers that are going to be BitLocker-protected?
    
    You should configure the startup options of your computer to have the hard disk drive first in the boot order, 
    before any other drives such as CD/DVD drives or USB drives. 
    
    If the hard disk is not first and you typically boot from hard disk, then a boot order change may be detected 
    or assumed when removable media is found during boot. 
    
    The boot order typically affects the system measurement that is verified by BitLocker and a change in boot 
    order will cause you to be prompted for your BitLocker recovery key. 
    
    For the same reason, if you have a laptop with a docking station, ensure that the hard disk drive is first in 
    the boot order both when docked and undocked.


    https://docs.microsoft.com/en-us/win...quirements-faq
      My Computer


  5. Posts : 1,746
    Windows 10 Pro x64 22H2
    Thread Starter
       #15

    thank you guys for helping, I get it now.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 08:17.
Find Us




Windows 10 Forums