Hacker News new | ask | show | jobs
by hedora 705 days ago
Are there VM platforms that can encrypt disks without giving the host access to the disk? Sure, they could use TPM or something, but that doesn't solve the problem.

Worst case, I imagine you could boot to the bootloader menu, then scrape the unwrapped bitlocker key from RAM.

(I agree that the org that mandated cloudstrike would collectively lay an egg if they realized this was possible.)