This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Using USB containing BEK key to access HDD from a different machine

Hello,

I have a USB containing a startup key (.BEK file)  for a computer that has the boot partition encrypted with Bitlocker. I was wondering if I was to take out the encrypted hard drive from that machine and then connect it to a machine using a different OS like Kali linux,  could that startup key that was created with the original computer be used to decrypt the HDD on the machine it is now attached to and access the files or would the HDD require the bit locker recovery key instead of that startup key? If anyone could provide me with more information, it would be greatly appreciated.



This thread was automatically locked due to age.
Parents
  • Hi Yohan,

    Using BEK file for decrypting a Bit locker encrypted drive is absolutely possible by slaving the drives to a machine that also has BitLocker installed in it, thereby making other Operating Systems not effective in this process natively.

    After slaving the encrypted data volume on a Windows machine with Bitlocker in it, you will be prompted for a password. The drive will normally be unlocked with a password, but if this doesn’t work, select ‘I forgot my password’. Enter your recovery key and ‘Voila' all the data on the encrypted data volume will be recovered.

    Hope this helps!

    Regards,

    Adithyan Thangaraj
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

Reply
  • Hi Yohan,

    Using BEK file for decrypting a Bit locker encrypted drive is absolutely possible by slaving the drives to a machine that also has BitLocker installed in it, thereby making other Operating Systems not effective in this process natively.

    After slaving the encrypted data volume on a Windows machine with Bitlocker in it, you will be prompted for a password. The drive will normally be unlocked with a password, but if this doesn’t work, select ‘I forgot my password’. Enter your recovery key and ‘Voila' all the data on the encrypted data volume will be recovered.

    Hope this helps!

    Regards,

    Adithyan Thangaraj
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

Children
  • Hi Adithyan,

     

    Thank you for your response. The question is more related to a security concern with the BEK file on a USB. When installing sophos we added the option to use a startup key and as a result the BEK file was generated onto the USB. My question is that if someone had this BEK file could they use it to access files of the HDD drive if the HDD was attached to another computer? I know that kali linux has a program called dislocker that allows you to decrypt a drive if you have a BEK key file or a bit locker recovery key. I was wondering if that BEK file created by the sophos application is specific to the particular machine where the usb key was generated from? I hope this make sense.

     

  • Hi Yohan,

    Thank you for your response! Ah! Understood your question perfectly. I would say that the BEK file is not machine specific and is meant to be used for the encrypted drive. This BEK file generated is merely a copy of the recovery key that Bitlocker makes and is hence usable on any other machine where the drive can be slaved. In short - anyone with access to the BEK file (or the token with the file in it) and the corresponding encrypted drive 'can' access the drive's data.

    Regards,

    Adithyan Thangaraj
    Community Support Engineer | Sophos Technical Support

    Knowledge Base  |  @SophosSupport  | Sign up for SMS Alerts
    If a post solves your question use the 'This helped me' link.

  • Hi Adithyan,

     

    Thank you for your response. That answer's my question.