Diffuser missing from BitLocker Drive Encryption

I couldn't help but notice on my Windows Server 2012 Essentials installation that the Diffuser options are gone from BitLocker Drive Encryption. This was a shocker. Since Windows Vista/Server 2008, the following four options have always been available:
AES 256-bit with Diffuser
AES 128-bit with Diffuser
AES 256-bit
AES 128-bit
The default was AES 128-bit with Diffuser, but I always opted for the strongest, and changed it to AES 256-bit with Diffuser. I made this change after probing around Google and Bing to see if BitLocker with Diffuser provided stronger encryption than BitLocker
sans Diffuser.  What I found supported the use of Diffuser as being the strongest, thereby making AES 256-bit with Diffuser the strongest encryption of the four settings.
So to find Diffuser culled from BitLocker was a shocker, and made me lose a bit of respect for the technology. Why would you WEAKEN the product (BitLocker) by removing the stronger versions of the encryption?  This TechNet article is quite disappointing: http://technet.microsoft.com/en-us/library/hh831713.aspx
The article simply says, "The Diffuser option is no longer available to be added to the Advanced Encryption Standard (AES) encryption algorithm" under the heading "Removed
or deprecated functionality." There is ZERO explanation.
I'm hoping someone can answer this, please. WHY would you take out the stronger versions of encryption in favor of leaving the weaker ones? Wouldn't it be more appropriate
to deprecate the non-Diffuser variants and require the use of Diffuser?
BitLocker was, and still is, a great technology, but it was just made quite a bit weaker with the release of Windows 8 and Server 2012.

Hi Manoj,
If I understand your answer, are you saying that the BitLocker options with Diffuser are actually WEAKER than those without it?
It's always been my impression that FIPS aims for the highest possible security standards.  If FIPS-only environments allow BitLocker without Diffuser but disallow BitLocker when Diffuser is used, that would lead me to believe Diffuser actually weakens
BitLocker.  Is this correct?
I guess that as long as BitLocker with AES 256-bit encryption makes the FIPS federal government folks happy, then it's good enough encryption for me!
Also, you mention crypto-acceleration hardware.  Where would I find this?  I'm guessing this is something found in newer servers, laptops and desktops?  Or maybe even tablets?  Would the new Microsoft Surface come with such capabilities?
Matt

Similar Messages

  • BitLocker Drive Encryption Recovery Key

    I have a Dell Optiplex 7010 running Windows 7 Enterprise 64-bit. Intermittently when booting the computer the Windows BitLocker Drive Encryption Recovery Key Entry screen shows up. Most of the time I can power off the computer and then turn it back on and
    it loads Windows without that screen showing up. If powering it off and back on again doesn’t get me past the Windows BitLocker Drive Encryption Recovery Key screen, I will enter the recovery key.
    I have already reimaged the computer, replaced the hard drive, cleared Bitlocker Cache in the BIOS and have updated the BIOS to the latest version.
    Any ideas to keep the Windows BitLocker Drive Encryption Recovery Key Entry screen from showing up?

    Hi,
    I have already reimaged the computer, replaced the hard drive, cleared Bitlocker Cache in the BIOS and have updated the BIOS to the latest version.
    Did you mean you have re-install the OS? Did you use another clean image rather than capturing the old OS?
    Did you encrypt the OS partition?
    Please use below command to check the status:
    manage-bde -status
    If there is any volume is encrypted, use below command to turn it off:
    manage-bde -off C:
    Karen Hu
    TechNet Community Support

  • Critical BitLocker Drive Encryption system files are not available

    Hi all,
    We are running into some issues when attempting to configure BitLocker Drive Encryption through the BitLocker UI on Windows Server 2008SP2.
    On running the BitLocker configuration screen we are presented with a message stating that
    ‘Your system volume is not configured correctly to allow you to use BitLocker Drive Encryption. 
    Critical BitLocker Drive Encryption system files are not available’
    We believe this issue may have been caused during a recent hardware migration using the DoubleTake Move software as we encountered a similar issue with the Windows Backup utility not seeing any available HDDs.
    Has anyone else encountered a similar issue and aware of any potential fix?

    I think it should be supported on Windows Server 2008 as it is supported on Windows Vista.
    Can you check whether BdeHdCfg.exe is present in System32 folder. If not can you copy the BdeHdCfg.exe installer from higher version of OS and copy it to the system32 folder on Windows Server 2008 and then run the command with the administrative rights. 
    NOTE : Make sure to change the directory to %SystemDrive%\Windows\System32
    Before running the command.
    Regards, "Gaurav Ranjan" =========== NOTE: Mark as Answer and Vote as Helpful if it helps =======

  • Critical BitLocker Drive Encryption system files are not available- which was working earlier.

    Hello All,
    The E drive  (external USB drive) of server which was encrypted using bitlocker. earlier it was working perfectly fine. On running the BitLocker configuration screen we are getting with a message stating that ‘Your system
    volume is not configured correctly to allow you to use BitLocker Drive Encryption.  Critical BitLocker Drive Encryption system files are not available’
    now whenever we are clicking on E drive it is showing to format the disk.
    can anyone help me to understand which are the files required or repair for bitlocker?
    Thanks & Regards,
    MAsud Hussain

    Hi Masud,
    Do you have any progress at the moment?
    If there are any related error messages in Event Logs, please post them out for further analyzing.
    Best Regards,
    Amy
    Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Adobe files missing from network drive after editing...

    Problem started around June 1st.  PDF files are shared on the network drive.  After I edit one of the forms and resave it, the networked computers can no longer see the file listed on the network drive.  Only the hosting computer still sees them.  Also, if I resave one of the files as a new name, it will reappear on the network.  Any ideas?  Adobe Reader 11.0.03

    Yes, the problem is still continuing. However, after looking into as much of it as I can, I can confirm something that r.p.b_ started stumbling on. The files are deleted IF AND ONLY IF a user is using the built-in Windows 7 disc burning utility AND is dragging
    and dropping the files to the drive from a network share; this doesn't happen locally. If you watch what happens in the native folder, the files are literally scrubbed from the drive as they are processed and added to the image. However, if you Right Click
    on the files and copy them, then Right Click->Paste onto the drive, they remain. (The keyboard shortcuts also worked.) Also, 3rd party disc burning utilities function they way the should. (In other words, they don't delete the files.)
    My speculation is that there's a bug in the coding that sees the network share as a temporary buffer file while the image is being prepared. Then, as the files are processed in what ever way is needed, the "temporary buffer" is being deleted. The result:
    lost files on a network share. But, this is just speculation.

  • Files missing from external drive

    I have a 4 TB G-Tech RAID drive attached via FireWire 800. It was formerly a backup drive for photos/videos, moved up to a main drive when the old drive it was backing up failed. Problems got in the way of replacing it....
    Anyway, all of a sudden, my files were gone. Just gone. For some reason, the folder hierarchy is still there--every folder, as best I can tell is where it was, but any and all data is gone.
    Disk Utility found nothing wrong with the drive; DiskWarrior didn't, either. I booted from another external drive running 10.6.x, no change in what wa(sn't) there, and ran TechTool Pro 5 (I'm running 10.8.3 and don't have a newer version so it ran off the older OS); no help.
    I ran Data Rescue for a few days and it seems to have recovered a lot of files--but we're talking almost 3 TB of data, and I shudder at how many months it's going to take me to get it back into a semblence of order, as well as how much I've actually recovered.
    The part that makes me hit my forehead is that I ran the Deleted Files function, which scans free space only. I did so because, at the time I ran Data Rescue, there still was data on the drive, about 600 GB of photos/videos. But when it had finished, all THAT was gone, too, and I wonder if I should have done a Deep Scan and missed files as a result.
    But here's the thing: If I do a Get Info on the drive, it says that the capacity is 4TB. But, if I open a Finder window and show the top level (with all of the volumes shown) and use List view, it shows  the drive as being 2.99 TB in size. So... is that data is still there, somehow? I.e., is there anything recoverable in a *useful* form--in the original folders and with the original names, rather than hundreds of thousands of undifferentiated files that DR presumebly found?
    Side note, and perhaps a red herring. The drive had been running slowly for a while, though tests didn't show why; see here. The drive had seemed to recover itself, but then got slow again. I downloaded Drive Genius (demo) and tried to run the Benchmark function, only to find that it didn't run in eval mode. At some point, I found that my iMac was running slowly, and I opened Activity Monitor and found an odd process taking up a lot of CPU: dgse. Couldn't figure out what it was, and Googling didn't reveal anything. So, just in case I had a Trojan, I quit it. It was right after this that I found my data gone. I later tracked the process to Library>Application Support>Drive Genius
    Sure seems darned coincidental....

    Thanks. Ran it twice, but it didn't restore the files. Still, it gave me the following:
    The original directory is damaged and it was necessary to scavenge the directory to find file and folder data.!
    Some files that had been lost or thrown away may have been recovered.
    Comparison of the original and replacement directories indicates that there will be no changes to the number or contents of files and folders. All files and folders were compared and a total of 807,104 comparison tests were performed.
    • All errors in the directory structure such as tree depth, header node, map nodes, node size, node counts, node links, indexes and more have been repaired.
    • Volume Information had to be scavenged from the file system journal.

  • BitLocker Drive Encryption, Access Issues

    I encrypted my external hard drive and save the recovery key to a thumb drive. Now I cant access my external drive. I get an error message that says that the key I have entered does not match this drive. Can anyone help?

    Hi harvey,
    You should use password first.
    If you forgot your password for decryption, you could use your recovery key for recovery. If you mean the error message says that the recovery key you entered does not match this drive. Make sure you enter the right key and txt file has not
    been modified before because error shows that you entered the wrong key.
    If the recovery key doesn’t work,  I’m afraid that there is no other way to access it
    Regards
    D. Wu

  • Lightroom 5.2 - files are missing from hard drive after Import

    I am using Lightroom 5.2, Windows 7.
    I imported files into Lightroom from my hard drive and now those folders on my hard drive are empty and the photos are gone from Lightroom as well.
    Help!

    Not sure if move or add was selected; what is the default?  I did do a preliminary search of my hard drive but interrupted it because it was taking so long.  I will let it finish searching.  I must have moved them.  They're not in the recycle bin. 
    There is a catalog for both Lightroom 4 and 5.  I upgraded the Lightroom 4 catalog but that didn't help.

  • Hard Drive Encryption Issue

     
    This is in regard to hard drive encryption issues in my USB Hard drive. I have Windows 7. I was encrypting my USB hard drive and
    was able to enter a password. However, I did not receive any prompt to save the Bitlocker recovery key.  During encryption process, I received an error. The encryption process was unsuccessful. However, now when I plug-in the hard drive, I receive the
    following message on the status bar:
    Application and Device Control rule Block writing to removable media. Unencrypted drive found (No_Encrypted_Found) has blocked edpa.exe trying to access Volume
    {e3901a75-f1ff-11e1-817c-806e6f6e6963 alpha-numeric number appearing here}
    When I try to open the drive, it asks for a password. When I enter the password, I am receiving the following error message:
    Bitlocker Drive Encryption failed to recover from an abruptly terminated conversion. This could be due to either all conversion logs being corrupted or the media
    being write-protected.
    I have read that Bitlocker repair tool can help resolve this issue.
    However, I just have the password that I had set to encrypt the drive and Bitlocker recovery key identification. Can this help to get access to my hard drive data  using the Bitlocker tool.

    Checked this ? 
    http://answers.microsoft.com/en-us/windows/forum/windows_7-security/bitlocker-drive-encryption-failed-to-recover-from/232e812b-4f7a-e011-9b4b-68b599b31bf5
    Arnav Sharma | http://arnavsharma.net/ Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading
    the thread.

  • Bit locker drive encryption failed due to power failer and hard disk corrupted

    I ran Bitlocker drive ecryption drive D. My pc is windows 7 ultimate, while it was in progress of 1% due to power failer the encryption failed, when power resume the drive didn't showed the file format nor the size but it shows the size in disk management.
    It showed like this in My computer
    I do Have the recovery code password and back of recovery password so I ran the "manage-bde-_unlock D:-rp[my code ]
    and my pc got hang  no other option rather than to press the restart button. 
    then I used commang "repair-bde -force D:I:-rp[my rp] and following info showed but it stucked in 1% about 8 hours, and there was no increase in the pecentage
    I also connected the hardisk to mac but all othe partation showed but didn't showed the encrypted one.
    I had lots of memorable picture and other backups so any one kindly help me to get out of this problem. Thanks for help

    Hi,
    The BitLocker encryption and decryption processes can be interrupted by turning the computer off, and it will resume where it left off the next time Windows starts. This is true even if the power is suddenly unavailable.
    Bitlocker-repair (repair-bde)  tool
    can't repair a drive that failed during the encryption or decryption process.
    In addition, could you please explain a bit for what drive you are trying to deal with? external one?
    When you first restart your PC, have you seen any signs that indicate that the encryption is in process?
    Regarding your scenario, please take a look to see if the following articles could help here:
    Scenario 11: Recovering Data Protected by BitLocker Drive Encryption (Windows 7)
    Besides, when running manage-bde command, did we followed the steps mentioned in the below article?
    Scenario 14: Using a Data Recovery Agent to Recover BitLocker-Protected Drives (Windows 7)
    Best regards
    Michael Shao
    TechNet Community Support

  • "Rename" missing from Finder context menu

    The Rename feature on the Finder Context menu has been very useful to me.
    Got an error message while trying to rename several folders.
    Now the Rename feature is missing from the Finder context menu.
    OS 10.10 Yosemite, 27" iMac
    Just recently purchased at Thunderbolt hard drive enclosure (Akitio Thunder2 Quad enclosure) and the error happened while renaming files on the Thunderbolt drive. Now the rename feature is missing from all drives.
    I've tried:
    rebooting - no help
    ejecting the Thunder2 quad and rebooting - no help
    power down the Thunder2 and rebooting - no help

    Welcome to the world of Mac. Some ‘light’ reading to help the transition. I don’t recommend trying to get through all of this at once.
    
A guide for switching to a Mac
    Anatomy of a Mac
    
Mac Basics—Tutorials on using a Mac
    
Mac OS X keyboard shortcuts,
    Mac Basics – Switching From Windows
    Mac OS FAQ
    MacTips,
    Quick Assist
    Switch Basics
    Switching to Mac Superguide
    Switching to the Mac: The Missing Manual, Mountain Lion Edition
    
Take Control E-books
    
Welcome to the Switch To A Mac Guides

  • T510 - Bitlocker missing from Control Panel

    I just got my new T510 with Windows 7 Professional 32 bit and I was trying to use Bitlocker to encrypt the hard drive. But Bitlocker is nowhere to be found in Control panel.
    Used Search option in Start menu and the only result is refering to manage file encryption certificate.
    I looked in BIOS just in case I need to enable TPM chipset - nothing found. All my other DELL laptops in the office have Bitlocker present in Control Panel. Even on my old LENOVO T60P I was able to enable it.
    I don't know what's happening here, what I'm missing ?
    I cannot belive that the new T510 is missing the feature. Any help apreciated... 
    Solved!
    Go to Solution.

    Correct, BitLocker is only in Win 7 Ultimate (and Enterprise).  You can use the Windows Anytime Upgrade feature to upgrade your Pro to Ultimate-->hit windows-key + Pause to bring up the System properties, and there's a link at the bottom left of the window (I'm going by memory here) that allows you to do the anytime upgrade.  You don't have to re-install your OS or apps or anything, it happens in-place once you've paid the fee.
    ThinkPad T510 : i5-540M : 8GB PC-10600 : 500GB 7200rpm : 15.6" HD+ : Intel 6300 : Win7 Pro 64 : 9Cell
    Ordered 2/Feb/2010 : Shipped 22/Feb/2010 : Received 3/Mar/2010

  • Copy File From One Drive to Another & Missing Keyword Tags

    Hi,
    I use LR 2.7.  I want to copy one file from one drive to another drive with the same file name.  I thought you could drag the file, but it doesn't copy over the file in the other drive, can you explain what I have to do? 
    Also, I tried to import the folder into another drive, but it doesn't copy the keyword tags.  Is there a way to do this?
    Thanks
    Barb

    Hey Barb,
       Well, if you use the Year/Month/Day/pictures_here  format, none of the folders contains a massive amount of folders.  It's not the number of folders that generates problems, it's having them all in _one_ folder that creates slow-down issues.  Imagine if you had a deck of cards; look for one card... you have to go through all 52 cards to find it.  But, if you broke it down into the 4 groups, you only have to go through 13, which is lots faster.  Now imagine going through 15000 instead of 52...
    Look at the way lightroom can automatically import by date;  it has several preset formats.  If you pick one of those, then when you import new photos, it will automatically create any missing ones, and you have lots less to do.
    Depending on how much work you have already done, you might consider making a new catalog and just importing all of your photos again, and let it create everything quickly for you.
    You could save all of your "edit" changes by writing out all of the xmp files first.  But with 15000 files in one directory, this will double it to 30000 (one per image!), but will preserve all of your edits if you choose to make a new catalog approach.
    As for combing catalogs, once you have one catalog the way you want it, you can select "import from catalog" and it will suck it into a new one, thus combining the catalogs.  The only problem I can see is that it will import it in the format you already have it, so you have to organize it manually before you import it.  Otherwise, you'll get your old format and your new format in the one catalog (but can then move pictures around if you need to).
    Personally,  I'd go the 'write xmp files, create new catalog' approach.  Then just recreate my collections, etc.
    But either way you do it, it will take some time processing, as that's a lot of files to start with!
    Ciao!
    Jason

  • TS5376 For "The program can't start because MSVCR80.dll is missing from your computer", I followed the steps and there is no C:\Program Files\iTunes and look for .dll files..Also, after the update, I no longer show my disk drive when I load a CD.

    After downloading the new Itunes update, my compter now shows error: "The program can't start because MSVCR80.dll is missing from your computer". I follwed the Apple fix / steps but it did not correct it. Also, after the update my disk drive is not recognized on my computer. If I load a CD, I cannot even access it.

    See also Troubleshooting issues with iTunes for Windows updates.
    The steps in the second box are a guide to removing everything related to iTunes (similar to the advice above) and then rebuilding it which is often a good starting point unless the symptoms indicate a more specific approach. Review the other boxes and the list of support documents further down page in case one of them applies. E.g. TS2308: iTunes for Windows: Optical drive is no longer recognized, or "Disc burner or software not found" alert after install.
    Your library should be unaffected by these steps but there is backup and recovery advice elsewhere in the user tip.
    tt2

  • Drive encrypted using Bitlocker...encrypting backup on Server 2008

    I've seen this topic discussed a few times but with very little real explanation on how to do this. 
    I have several servers for several customers that now must be encrypted.  I've run a few tests with our own internal servers and one user server and the drive encryption goes off without a hitch.
    Encrypting their backups however is still an issue.  Usually they are setup with 2 drives, one on site, one off.  Obviously the one on site is a theft issue so it defeats the purpose of encrypting the server if there is an un-encrypted backup.
    Bit Locker to Go is an R2 feature, isn't it?  Plus when you setup a drive for Windows backup, it formats the drive so is Bitlocker even usable?
    The whole idea of encrypting their drives concerns me because of recovering the data/server after a crash.  We use encrypted online back up but the need to do a bare metal restore is the part that concerns me.  I even thought of adding a third drive to the mix just to be overly redundant(paranoid).
    What is the best way to handle this?  How does it work in the event of a server crash, how do you do a bare metal restore with a bit locker drive?
    Thanks

    You can bitlock a portable drive for Server 2012 R2 backup as follows:
    Using Essentials, the first time you use the drive
    1. Start the dashboard and go to the Storage Tab and select
    Disks
    2. Click on the new drive and add it to the backup. Give it a unique label. Backup will format it and remove the drive letter.
    3. Go to the start screen and start Administrative tools | Computer management
    4. Find Disk Management and scroll down to find your backup disk.
    5. Right click on the disk block and choose Change Drive Letter and Paths.
    Add a drive letter.
    6. Open This PC and right click on your drive. Choose
    Turn on Bitlocker.
    7. Give the disk a password and save or print the key. Choose to encrypt used space only.
    8. When Bitlock finishs encrypting the drive, click on the Manage Bitlocker link at the bottom of the progress screen. Find your disk and click the dropdown arrow. Click on
    Turn on Auto-unlock. (Auto-unlock greatly simplifies swapping disks. However, my experience has been it will not reliably unlock the disk after a restart or power failure. You may have to log in for the disk to be reconnected.)
    9. You can use Disk Manager  as you did before to
    Remove the drive letter. It can be handy for verifying the disk's status or distinguishing multiple disks, but you don't really need it.
    10. Close everything up. You are good to go. After this, the disk can be replaced using the normal procedures for swapping USB drives.

Maybe you are looking for

  • Help with dual booting...PLEASE

    so I just got a new laptop and ArchLinux is running great on it, I love everything about it.  I originally intended to run WinXP under KVM because there are some windows apps I need to use for my job.  It turns out my bios doesn't support KVM and I c

  • Vendor / Customer Master transfer from Feeder to GTS

    Hi All, When I transfer a Vendor / Customer / Bank Key from Feeder system to GTS, the Business partner is created with BP Role "000000 - BP General". But what I need is whenever I transfer a Vendor the BP should be created with BP Role "SLLCPS" & For

  • Application response too slow- How to resolve (webLogic)

    Hi All, Can you please let me know what are all the main areas that i need to concentrate in the weblogic application server if i get the complaint from the clients saying "application performance is too slow". Edited by: user11361691 on Apr 21, 2010

  • My iphone 4s shows 1% battery all day but wont die

    My battery shows fully charged when it is plugged in.  when I unplug it it quickly drops down until it is at 1% then it doesnt die and works fine all day.  Is this software? I have wiped my phone, I have rebooted it, i have hard started it..... tried

  • I can't install Creative Suite CS6

    Hi, I just bought new computer and tried to install Adobe Creative Suite CS6 with DVD. However, I couldn't proceed it after put serial number in. Just showing this message. What does it mean and what I supposed to do to install properly?