|
|
|
|
|
by gck1
164 days ago
|
|
> Windows cheats here Slightly off-topic: it also cheats in how TPM works for Bitlocker when you do TPM + PIN. One would assume PIN becomes part of the encryption key, but in reality, it's just used as the auth for TPM to release the key. So while it sounds like a two-factor solution, in reality it's just single factor. So the Bitlocker without TPM is actually a better idea and Windows makes it very painful to do if TPM is on. |
|
I’m not sure how the typical “two factor” best practices would interpret one of the factors basically self destructing after 10 guesses, but IMO it’s a pretty decent system if done right.