Chaos Communication Congress

Chaos Communication Congress

Windows BitLocker: Screwed without a Screwdriver (38x104)


Air date: Dec 28, 2024

Ever wondered how Cellebrite and law enforcement gain access to encrypted devices without knowing the password? In this talk, we’ll demonstrate how to bypass BitLocker encryption on a fully up-to-date Windows 11 system using Secure Boot. We’ll leverage a little-known software vulnerability that Microsoft has been unable to patch since 2022: bitpixie (CVE-2023-21563). We'll live-demo the exploit, and will walk through the entire process—from the prerequisites and inner workings of the exploit to why Microsoft has struggled to address this flaw. We'll also discuss how to protect yourself from this and similar vulnerabilities.

  • Rank #
  • Premiered: Dec 2011
  • Episodes: 1474
  • Followers: 0
  • Ended
  • Unknown
  • Unknown