Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

what is the best way to have yubikey always work on this ssd (encryption needed?


  • Please log in to reply
3 replies to this topic

#1 helpingisfun

helpingisfun

  •  Avatar image
  • Members
  • 158 posts
  • OFFLINE
  •  
  • Local time:12:48 AM

Posted 23 October 2021 - 08:27 PM

hi

i read that if someone has not bitlocker the ssd can be started without the yubikey login for win10. it is a problem. 

i read that the ssd has to be encrypted to avoid the yubikey being by passed in safe mode.

 

i also read some use bitlocker and some say to rely on samsung encryption wich i have no clue what that means.

 

the ssd is Samsung 860 EVO 2.5 SATA III 500GB INTERNAL SSD MZ-76E500B/AM

 

what are the steps in order to acheive a win10 with yubikey always asked? tx



BC AdBot (Login to Remove)

 


#2 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,554 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:01:48 AM

Posted 01 May 2022 - 10:10 AM

I'm no expert in this subject, but I would think that by "Samsung" encryption,

they probably mean Samsung's own, built-in whole-drive encryption feature.


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 


#3 N0vajay05

N0vajay05

  •  Avatar image
  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:48 AM

Posted 13 May 2022 - 11:57 AM

Absolutely need the drive encrypted for yubikey login to be worth anything. If not, one can get to all of the data on any windows based machine in about 60 seconds, yubikey or not.

 

Use bitlocker and a TPM chip to avoid putting in the password each boot, or bitlocker with password if you don't have a TPM chip. Also know that unless you use a different remote program, RDP doesn't like to work using yubikey auth (from a different machine to the one with yubikey auth) because it doesnt see the key when you're logging in from remote.



#4 Shplad

Shplad

  •  Avatar image
  • Members
  • 6,554 posts
  • ONLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:01:48 AM

Posted 13 May 2022 - 01:54 PM

True, but rather than encrypt an entire drive, I think it's easier to just encrypt one folder.

Unless you need to encrypt the entire drive.

 

I doubt most home users need their Windows system files encrypted.


- Use this to collect and post information about your PC hardware, software and configuration (Whether or not you have crashing).

 

Blue Screen of Death (BSOD) Posting Instructions - Windows 10, 8.1, 8, 7 & Vista

https://www.bleepingcomputer.com/forums/t/576314/blue-screen-of-death-bsod-posting-instructions-windows-10-81-8-7-vista/

 

 





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users