Comment Re: Surprised that automatic unlock is a risk? (Score 1) 67
The TPM is supposed to rely on a hardware signature match before unlocking. Booting from alternate media would fail that test and the TPM won't hand over the keys. And in fact, YellowKey does require you to boot from the internal drive into the recovery environment. Apparently the recovery environment unlocks the drive and relocks it.
Looking further, it uses some kind of pending file change tool in the System Volume Information folder to put a file on (I think) the mounted recovery system while the drive is unlocked so that it doesn't break the signature. Apparently Windows shipped the PE with an option to read an
This wouldn't be possible if you were modifying a binary because it wouldn't match the signing keys. But since they included an option to trivially set an