§ Guide, full text

BitLocker FileVault And Full Disk Encryption

Full disk encryption, such as BitLocker and FileVault, is often recoverable, particularly in managed environments where recovery keys are typically escrowed. This guide details how these systems work, where keys reside, and how to lawfully obtain and image decrypted volumes for litigation or investigation. It also addresses scenarios where keys are genuinely absent.

17 pages · 27 min read

Loading the PDF reader

Page 1

FULL - DISKENCRYPTION · A GUIDE FOR UK LAWYERS Bit Locker, File Vault and Full-Disk Encryption Recovery Keys, Escrow and What the Encrypted Drive Really Does and Does Not Protect COMPUTER FORENSICS LAB

§ ABOUT THE AUTHOR PREPARED BY COMPUTER FORENSICS LAB E-DISCOVERY TEAM ESTABLISHED 2007 · LONDON ISO 17025-ALIGNED PROCEDURES ENCRYPTED-DRIVE EXAM IN AT I ON RECOVERY-KEY & ESCROW ANALYSIS CPR PART 35 EXPERT REPORT S FULL CHAIN-OF-CUSTODY DOCUMENTATION

§ CONTENTS In this guide 01 Executive summary 02 The problem in plain English: encryption built to be recovered 03 How Bit Locker, File Vault and LUKS actually work 04 Where the recovery keys live: directory, console, cloud and escrow 05 Obtaining the key law full y and imaging the decrypted volume 06 When there is no key: the genuinely inaccessible drive 07 Deployment: the recovery position, disclosure and honest limits 08 Source architecture: where else the evidence lives 09 Worked examples 10 Common mistakes and technical limitations 11 Questions to ask · Suggested wording 12 Checklist and red flags · When to involve a digital forensic expert 13 Frequently asked questions 14 Glossary · References · Disclaimer · How a specialist laboratory can assist

§ 01 · ORIENTATION Executive summary THE HEADLINE POINT: FULL - DISKENCRYPTIONISDESIGNEDTOBERECOVERABLE, AND INAMANAGEDENVIRONMENTTHERECOVERYKEYALMOSTALWAYSEXISTSSOMEWHERE THEORGANISATIONCONTROLS: THE EXAMINER ' SFIRSTTASKISTOFINDTHATKEY, NOTTOATTACKTHEENCRYPTION, ANDONLYWHERENOESCROWEDKEYEXISTSISTHE DRIVEGENUINELYBEYONDREACH

§ 02 · FIRST PRINCIPLES The problem in plain English: encryption built to be recovered

§ 03 · HOW IT WORK S How Bit Locker, File Vault and LUKS actually work

Page 2

§ 04 · WHERETHERECOVERYKEYSLIVE Where the recovery keys live: directory, console, cloud and escrow

§ 05 · OBTAININGANDIMAGING Obtaining the key law full y and imaging the decrypted volume

§ 06 · WHEN THERE IS NO KEY When there is no key: the genuinely inaccessible drive

§ 07 · DEPLOYMENT Deployment: the recovery position, disclosure and honest limits

§ 08 · THEWIDERMAP Source architecture: where else the evidence lives QUESTION COUNTERPART LOCAL- ENCRYPTED RECOVERY- CLOUD SERVER-SIDE DRIVE KEY STORES BACKUP PLATFORMS SYNCED / DELETED / COPIES ONLY

§ 09 · IN THE WILD Worked examples EXAMPLE1 · THEBITLOCKERLAPTOPTHATWASOPENALLALONG EXAMPLE2 · THESUPPRESSEDESCROWTHATTOLDITSOWNSTORY EXAMPLE3 · THEPERSONALMACBOOKANDTHEHONESTLIMIT

Page 3

§ 10 · WHEREITGOESWRONG Common mistakes and technical limitations Common mistakes Technical limitations

§ 11 · INTERROGATORIES & DRAFTING AIDS Questions to ask · Suggested wording Ask your client Ask your opponent (or the reluctant party) Ask your e Discovery / forensic provider SUGGESTED WORDING · INSTRUCTION FOR AN ENCRYPTED - DRIVEEXAMIN AT ION

§ 12 · QUICK CONTROL Checklist and red flags · When to involve a digital forensic expert The encrypted-drive checklist Red flags When to involve a digital forensic expert

§ 13 · COMMON QUESTIONS Frequently asked questions The laptop is Bit Locker encrypted. Is the data lost? Where exactly do we find a recovery key? Can you break Bit Locker or File Vault if there is no key? A managed device's recovery key is missing from the console. What does that mean? The device is personal and the person will not give the key. Now what? Is a decrypted image as good as evidence as an unencrypted one?

§ 14 · REFERENCE Glossary LUKS TPM Sources and authoritative references DISCLAIMER

§ HOW A SPECIALIST LABORATORY CAN ASSIST Working with Computer Forensics Lab Speak to a forensic examiner, not a salesperson. INSTRUCTTHELAB NEWENQUIRIESEMAILE - DISCOVERY

Cite as: Joseph Naghdi, BitLocker FileVault And Full Disk Encryption, Computer Forensics Lab, https://e-discovery.uk/library/bitlocker-filevault-and-full-disk-encryption/pdf.

Instruct the practice

Bring us in early. Defensibility is built, not retrofitted.

Whether you are responding to a regulator, preparing for disclosure, or scoping an internal investigation, start the chain of custody with a short, confidential conversation.

WhatsApp