Why isn't Microsoft modernizing Bitlocker?

Thorakson 10 Reputation points
2025-02-24T18:57:58.38+00:00

Many Windows users, both commercial and private users, rely on Bitlocker. Although it works fine, it is quite outdated and lacks up-to-date security measures. The two biggest ones are:

  1. Bitlocker still does not support TPM command and parameter encryption, so sniffing attacks are still possible if the TPM is not protected by a PIN.
  2. For passphrase-protected volumes, Bitlocker performs weak key stretching in this day and age. In fact, Bitlocker's key stretching is weaker than PBKDF2 (which should not be used anymore either) for the same number of iterations. Nowadays, a memory-intensive KDF like scrypt or Argon2 should be used.

Are there any plans to bring Bitlocker up to date?

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
10,877 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Welf Alberts 1 Reputation point
    2025-02-27T13:18:54.0333333+00:00

    Hi.

    1 Classic TPM sniffing is impossible if you use a firmware based TPM ("fTPM"). Most devices manufactured after the release of Win10 (2015) are equipped with an fTPM, so the point is moot for, say, >90% of modern machines unless you have other reasons not to use an fTPM. There are still attack vectors left, see https://ieeexplore.ieee.org/document/10190531

    2 In my opinion: "who uses a passphrase!?". If you want highest security, you use a certificate or the TPM or a usb-based .bek file ("startup key protector") as protector, never a passphrase. If we are talking about a non-OS partition, you could also use the auto-unlock protector so d: "piggy-backs" on the strong protector that you set for c: and no additional entry is needed.

    0 comments No comments

  2. Molly Lu-MSFT 1,101 Reputation points Microsoft Vendor
    2025-02-28T06:14:54.91+00:00

    Hello,

    Thank you for posting in Microsoft Q&A.

    Based on the description, I understand your question is related to Bitlocker.

    BitLocker currently does not support TPM command and parameter encryption. BitLocker uses PBKDF2 with SHA-256. Try monitor Microsoft's official channels and security blogs might provide the latest updates on this front.

    It is recommended to report this issue to Microsoft, use the Feedback Hub app. To learn more, see Send feedback to Microsoft with the Feedback Hub app:

    Send feedback to Microsoft with the Feedback Hub app - Microsoft Support

    Have a nice day.

    Best Regards,

    Molly

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.