Wednesday, May 20, 2015

Windows 10 Includes a Linux-Style Package Manager Named “OneGet”

Forget the Windows Store. Microsoft is working on a Linux-style package management framework for Windows, and it’s included with Windows 10. It’s being tested with Chocolatey’s existing packages, and allows you to easily install desktop applications and other software.
This is huge news. If you’ve ever used Linux, you’ve probably wanted a package management system for the Windows desktop ever since. Now it’s finally arriving!

OneGet, a Package Management Framework for Windows

This package manager is called OneGet, and is shipping as part of PowerShell. In a blog post titled “My little secret : Windows PowerShell OneGet” over at Technet, Microsoft’s Garret Serack explains:
“OneGet is a unified interface to package management systems and aims to make Software Discovery, Installation and Inventory (SDII) work via a common set of cmdlets (and eventually a set of APIs). Regardless of the installation technology underneath, users can use these common cmdlets to install/uninstall packages, add/remove/query package repositories, and query a system for the software installed. Included in this CTP is a prototype implementation of a Chocolatey-compatible package manager that can install existing Chocolatey packages.”
As OneGet is part of the latest version of PowerShell, it’s included by default in the Windwos 10 Technical Preview. It’s also available as part of the Windows Management Framework 5.0 Preview for Windows 8.1.
Just look at the image at the top of this article to see how it will all work. Yes, you can install VLC or another piece of Windows software that easily! After you run the command, OneGet will locate the package in your configured package sources, download it to your computer, and install it — all automatically. And there should be graphical user interfaces for this, too, so it’ll just take a few clicks.

How OneGet Works

Let’s dig in a bit deeper. Here’s how Microsoft describes OneGet:
“OneGet is a new way to discover and install software packages from around the web. With OneGet, you can:
  • Manage a list of software repositories in which packages can be searched, acquired, and installed
  • Search and filter your repositories to find the packages you need
  • Seamlessly install and uninstall packages from one or more repositories with a single PowerShell command”
The Get-PackageSource cmdlet lets you view a list of installed package sources, or repositories. OneGet now includes two Microsoft-provided sources. Chocolatey was previously the default package source during development and can easily be added.
Anyone can create and operate a repository of packages. Microsoft could potentially create their own one-stop-shop for Windows desktop programs. A company could manage its own repository with the programs they use so they can be easily installed and managed. A software developer could set up a repository containing only the software they create so their users can easily install and update it. You can add more repositories with the Add-PackageSource cmdlet or remove them with Remove-PackageSource.
The Find-Package cmdlet lets you search the package sources you’ve configured for available packages. Find software to install without searching the web!
The Install-Package cmdlet then lets you install a package of your choice, just by specifying its name. The package is automatically downloaded and installed from the software repository of your choice without any searching for .exe files, downloading them, and clicking through wizards that try to install junk on your computer. Better yet, you can specify multiple package names here — imagine installing the fifty Windows programs you use with a single command and leaving your computer to get a coffee while doing so.
The Get-Package cmdlet then lets you see what packages you have installed. Packages can later be uninstalled with Uninstall-Package. There’s currently no Update-Package command that will automatically install the latest versions of these software package from the available repositories, something that will be sorely needed — hopefully it’s on its way.

What’s a Package Manager? And What’s Chocolatey?

If you’ve gotten this far, you should understand the basics of what a package manager is. Basically, it’s a software tool that makes installation, updating, and locating of software to install much easier. Package managers are used on Linux, and they let you install packages from trusted software repositories in just a few clicks or keystrokes. The package manager can automatically update your packages whenever updated versions are added to the repositories, so every program doesn’t need its own built-in updater. It’s easy to use, and also very easy to automate.
Chocolatey is a package manager that brings this style of easy software installation to Windows. Currently, it primarily uses text commands so it hasn’t found much of a home beyond geeks — but geeks love it! Chocolatey allows you to install Windows software like Firefox, VLC, and 7-Zip with just a few keystrokes instead of the usual downloading and clicking process, just like you’d install software on Linux. Chocolatey is currently running a Kickstarter, seeking money to “take Chocolatey to the next level.” They’re also working on a graphical user interface for their package manager so average Windows users can more easily use it. With the package manager framework in Windows 10, Chocolatey can easily piggy-back off whatever work Microsoft is doing — work that seems originally inspired by Chocolatey. Rather than being a bolted-on package management system, Chocolatey will work hand-in-hand with the package management framework included with Windows.

It’s impossible to say exactly how far Microsoft will go here. One thing’s for sure: For Windows system administrators and geeks, installing software and automating software deployments is about to get a lot easier. This is currently a geek tool, as it’s only available via PowerShell commands. But, as Microsoft says, this will eventually be exposed as a set of APIs.

Tuesday, February 3, 2015

How to Check Your Motherboard Model Number on Your Windows PC

Whether you need to update drivers, want to check hardware compatibility, or you’re just curious, it’s way easier to check your motherboard model number with these simple tricks than it is to crack open your computer case to check the board itself. Read on as we show you how to check your motherboard model number from the comfort of your keyboard.

Why Do I Want To Do This?

There are a variety of situations where knowing your motherboard’s model number is important: upgrading your drivers, buying new hardware (you’ll need the proper expansion slots for card-based upgrades and the right memory DIMMS for memory upgrades, etc.), and checking the capabilities of your board if you’re considering upgrading the entire thing.
If you kept the paperwork that came with your computer (or the individual components if you built it yourself) you can often times reference that. Even then, it’s best to check to make sure the documentation is correct. Rather than open the case and search for the model number, it’s easy to use tools within Windows to check things out.

Checking Your Model Number via CMD.exe

If you’re comfortable using the command line, you can easily check a variety of motherboard and hardware stats using the handy Windows Management Instrumentation Command-line (WMIC) a command-line interface for Microsoft’s powerful WMI tool.
With the WMIC we can entry the query baseboard to check motherboard stats and then additional specific query modifiers like get Manufacturer, Model, Name, PartNumber, slotlayout, serialnumber, poweredon to get more detailed information about the motherboard. Let’s check our motherboard’s manufacturer, model number, and serial number using WMIC.
Open up the command prompt in Windows via either the run dialog (WIN+R) or via the search in the start menu; enter cmd.exe into either, no need to run it as an administrator. Enter the following text at the command line.
wmic baseboard get product,Manufacturer,version,serialnumber
This will return the following data.
The above information checks out for our system: the manufacturer is MSI, the board is the Z87-G45 (MS-7821), and while the WMIC tool attempted to check the serial number apparently, alas, MSI left that particular bit unfilled for whatever reason. None the less, the WMIC tool functioned just as it should, and without opening the case or using any third party tools we have the basic information we’re looking for.

Checking Your Model Number via Speccy

If you’d prefer a GUI-based way to check your motherboard’s model number (as well as a method that yields more information at a glance than the WMIC tool), the free tool Speccy by Piriform (the folks that brought us CCleaner) is a handy app to have around.
Grab a free download here and then fire it up.
Not only will it tell your model number, as seen above, but if you click on the Motherboard entry in the left hand navigation column, you can check even more information about the motherboard like the chipset and voltage settings.

Have a pressing tech question, hardware releated or otherwise? Shoot us an email at ask@howtogeek.com and we’ll do our best to answer it.

Saturday, November 29, 2014

How to Create Encrypted Zip or 7z Archives on Any Operating System

Protected Folder.
Zip files can be password-protected, but the standard Zip encryption scheme is extremely weak. If your operating system has a built-in way to encrypt zip files, you probably shouldn’t use it.
To gain the actual benefits of encryption, you should use AES-256 encryption. 7z archives support this natively, but you can also encrypt Zip files with AES-256 encryption.

Zip 2.0 Legacy Encryption vs. AES Encryption

There are actually two types of Zip file encryption. The older Zip 2.0 encryption is extremely insecure, while the newer AES encryption is fairly secure.
Unfortunately, many pieces of software — particularly operating systems with built-in support for Zip files — don’t support the newer AES encryption standard. This means that using the Zip password-protection features found in Windows XP, current versions of Mac OS X, and even typical Linux desktops won’t give you securely encrypted Zip files. Even some third-party utilities are reluctant to switch to AES for their Zip encryption as it means those AES-encrypted zip files will then be incompatible with the built-in Zip features in Windows, Mac OS X, and other software.
It’s still possible to get AES encryption with Zip files — but such files will require third-party software to view, anyway. You may just want to use a different archive format, such as 7z. The 7z archive format requires strong AES-256 encryption. Whenever you create a password-protected 7z file, you know that it’s securely encrypted. Really, 7z is great — it came out on top in our file-compression benchmarks. It’s generally on the top of other file compression benchmarks we’ve seen, too.

Windows – 7-Zip

Windows offers a built-in way to create Zip files. Windows XP even offered a way to password-protect and encrypt these Zip files. However, Windows XP used the extremely insecure “standard” zip file encryption algorithm. Even if you’re still using Windows XP, you shouldn’t use this feature. Later versions of Windows dropped the password-protection option entirely.
Nearly every popular encryption utility offers this features. We like 7-Zip, which is completely free and open-source, so it won’t try to nag you for any money.
With 7-Zip installed, you can select some files in a File Explorer or Windows Explorer window, right-click them, and select 7-Zip > Add to archive. Be sure to select the “Add to archive” option, as it gives you the ability to set a password. If you don’t see the menu option here, you can also open the 7-Zip application directly and use it to create an archive.
7-Zip will create a 7z archive by default, but you can also choose Zip. If you do opt to go with Zip, be sure to select the AES-256 encryption method instead of the weaker ZipCrypto method. Enter your password into the provided boxes and click OK to create your encrypted archive file.

Mac – Keka

Mac OS X also provides an easy way to create Zip files from a Finder window, but there’s no way to encrypt a zip file with the graphical user interface. The zip command included with Mac OS X does offer a way to encrypt zip files without using any third-party software. However, like the password-protection feature built into Windows XP, it uses the old and insecure standard zip encryption scheme. If you really wanted, you could use the “zip -e” command in a Terminal on a Mac. However, we strongly recommend against this.
As on Windows, you’ll once again need a third-party file compression app for secure compression. Keka seems to be one of the most well-loved file compression and decompression apps for Mac, and we can recommend it. However, even Keka doesn’t use AES for encrypting Zip files by default. You can get the currently-in-beta version of Keka and enable a hidden option to do this, or just use the standard version of Keka and create encrypted 7z files instead.
Launch Keka, select 7z, and enter a password for your archive. (If you select Zip, be sure you have the correct version of Keka and that you’ve enabled the hidden option above to get the secure encryption.)
Drag and drop one or more files you want to compress onto the Keka window and they’ll be compressed into a 7z file encrypted with the password you provided. You’ll need the password to access the file’s contents in the future.

Linux – File Roller with p7zip-full

The standard Archive Manager (File Roller) application included with Ubuntu and other GNOME-based desktop environments does have an option to create password-protected zip files. However, the underlying zip command used still uses the old, weak encryption instead of strong AES encryption. Thankfully, File Roller can be used to create encrypted 7z archives.
To enable this option, you’ll first need to install the p7zip-full package. (On some Linux distributions, it may just be called p7zip instead.) For example, on Ubuntu, you can either open the Ubuntu Software Center, search for p7zip-full and install it, or open a Terminal window and run the sudo apt-get install p7zip-full command.
Once you have, you can create encrypted 7z files directly from the File Roller window. Select some files in a file manager window, right-click them, and select Compress — or open the Archive Manager application directly and use it to create a new archive.
In the Compress window, be sure to select the 7z archive format. Click the Other Options header and provide a password. The password will be used to unlock your archive later.

There are many different software programs for creating password-protected archives, but — whatever you use — be sure it’s using secure encryption. The problem with Zip encryption isn’t purely theoretical. The web is full of tools that can “recover” a password-protected zip file that was created using the old encryption scheme. “Recover” is a less-scary word for breaking and removing the encryption.

Friday, September 26, 2014

How to Check Your BIOS Version and Update it

bios-update

You probably shouldn’t update your BIOS, but sometimes you need to. Here’s how to check what BIOS version your computer is using and flash that new BIOS version onto your motherboard as quickly and safely as possible.
Be very careful when updating your BIOS! If your computer freezes, crashes, or loses power during the process, the BIOS or UEFI firmware may be corrupted. This will render your computer unbootable — it’ll be “bricked.”

How to Check Your BIOS Version in Windows

Your computer’s BIOS version is displayed in the BIOS setup menu itself, but you don’t have to reboot to check this version number. There are several ways to see your BIOS version from within Windows, and they work the same on PCs with a traditional BIOS or a newer UEFI firmware.
To use a command, open a Command Prompt window — press Windows Key + R, type cmd into the Run dialog, and press Enter. Run the following command:
wmic bios get smbiosbiosversion
You’ll see the version number of the BIOS or UEFI firmware in your current PC.
find-bios-version-from-command-prompt
You can also find your BIOS’s version number in the System Information window. On Windows 7, you can search the Start menu for System Information to find it. On Windows 8, it’s more hidden — but you can still launch the System Information panel on Windows 8.
The BIOS version number is displayed on the System Summary pane. Look at the BIOS Version/Date field.
find-bios-or-uefi-version-in-windows-system-information

How to Update Your BIOS

Different motherboards use different utilities and procedures, so there’s no one-size-fits-all set of instructions here. However, you’ll perform the same basic process on all motherboards.
First, head to the motherboard manufacturer’s website and find the Downloads or Support page for your specific model of motherboard. You should see a list of available BIOS versions, along with any changes/bug fixes in each and the dates they were released. Download the one you want to update to. You’ll probably want the newest BIOS version unless you want an older one for a specific reason.
If you purchased a pre-built computer, head to the computer manufacturer’s website, look up the computer model, and look at its downloads page. You’ll find any available BIOS updates there.
download-updated-bios
Your BIOS download probably came in an archive — usually a .zip file. Extract the contents of that file. You’ll find some sort of BIOS file — in the screenshot below, it’s the E7887IMS.140 file.
The archive should also contain a README file that will walk you through updating to the new BIOS. You should check out this file for instructions that apply specifically to your hardware, but we’ll try to cover the basics that work across all hardware here.
bios-archive

You’ll need to choose one of several different types of BIOS-flashing tools depending on your motherboard and what it supports. The BIOS update’s included README file should recommend the ideal option for your hardware.
Some manufacturers offer a BIOS-flashing option in their BIOS, or as a special key-press option when you boot the computer. You copy the BIOS file to a USB drive, reboot your computer, and enter the BIOS or UEFI screen. From there, you choose the BIOS-updating option, select the BIOS file you placed on the USB drive, and the BIOS updates to the new version.
You generally access the BIOS screen by pressing the appropriate key while your computer boots — it’s often displayed on the screen during the boot process and will be noted in your motherboard or PC’s manual. Common BIOS keys include Delete and F2. The process forentering a UEFI setup screen on a Windows 8 PC is a bit different.
bios-menu
There are also more traditional DOS-based BIOS-flashing tools. You’d create a DOS live USB drive and copy the BIOS-flashing utility and BIOS file to that USB drive. You’d then reboot your computer and boot from the USB drive. In the minimal DOS environment, you’d run the appropriate command — often something like flash.bat BIOS3245.bin — and the tool would flash the new version of the BIOS.
The DOS-based flashing tool is often provided in the BIOS archive you download from the manufacturer’s website, although you may have to download it separately. Look for a file with the .bat or .exe file extension.
In the past, this process was performed with bootable floppy disks and CDs. We recommend a USB drive because it would probably be the easiest method on modern hardware.
run-dos-program-from-a-bootable-usb-drive
Some manufacturers provide Windows-based flashing tools, which you run on the Windows desktop to flash your BIOS and then reboot. We don’t recommend using these, and even many manufacturers who provide these tools usually caution against using them. For example, MSI “strongly recommends” using their BIOS-based menu option instead of their Windows-based utility in the README file of the sample BIOS update we downloaded.
Flashing your BIOS from within Windows can result in more problems. All that software running in the background — including security programs that may interfere with writing to the computer’s BIOS — could cause the process to fail and corrupt your BIOS. Any system crashes or freezes could also result in a corrupted BIOS. It’s better to be safe than sorry, so you should use a BIOS-based flashing tool or boot to a minimal DOS environment to flash your BIOS.
windows-bios-flashing-utility

That’s it — after you run the BIOS-flashing utility, you’ll reboot your computer and immediately begin using the new BIOS or UEFI firmware version. If there’s a problem with the new BIOS version, you may be able to downgrade it by downloading an older version from the manufacturer’s website and repeating the flashing process.

Thursday, September 11, 2014

How to Create and Run Virtual Machines With Hyper-V

run-linux-in-hyper-v-on-windows-8.1

Hyper-V is a virtual machine feature built into Windows. It was originally part of Windows Server 2008, but made the leap the to desktop with Windows 8. Hyper-V allows you to create virtual machines without any additional software.
This feature isn’t available on Windows 7, and it requires the Professional or Enterprise editions of Windows 8 or 8.1. It also requires a CPU with hardware virtualization support like Intel VT or AMD-V, features found in most modern CPUs.

Install Hyper-V

Hyper-V isn’t installed by default on Windows 8 Professional and Enterprise systems, so you’ll have to install it before you can use it. Thankfully, you don’t need a Windows disc to install it — you just need to click a few checkboxes.
Tap the Windows key, type “Windows features” to perform a search, and then click the “Turn Windows features on or off” shortcut. Check the Hyper-V checkbox in the list and click OK to install it. Restart your computer when prompted.
install-hyper-v-on-windows-8-or-8.1

Open Hyper-V Manager

To actually use Hyper-V, you’ll need to launch the Hyper-V Manager application. You’ll find it in your list of installed programs, and you can also launch it by searching for Hyper-V.
The Hyper-V Manager application refers to a “virtualization server,” which gives away its heritage as a tool for servers. It can be used to run virtual machines on your own computer — in that case, your local computer functions as a local virtualization server.
launch-hyper-v-manager

Set Up Networking

Click the name of your local computer in Hyper-V Manager to find the options for your current computer.
You’ll probably want to give the virtual machine access to the Internet and local network, so you’ll need to create a virtual switch. Click the Virtual Switch Manager link first.
virtual-switch-manager
Select External in the list to give virtual machines access to the external network, and click Create Virtual Switch.
virtual-switch-manager-create-external-switch
Give the virtual switch a name afterward and click OK. The default options should be fine here, although you should ensure the External network connection is correct. Be sure to select the network adapter that’s actually connected to the Internet, whether it’s Wi-Fi or wired Ethernet.
give-virtual-machine-networking-in-hyper-v

Create a Virtual Machine

Click New > Virtual Machine in the Actions pane to create a new virtual machine.
create-new-virtual-machine-in-hyper-v-manager
RELATED ARTICLE
Beginner Geek: How to Create and Use Virtual Machines
Virtual machines allow you to run an operating system in a window on your desktop. Use them to run software... [Read Article]
The New Virtual Machine Wizard window will appear. Use the options to name your virtual machine and configure its basic hardware. This should all be fairly self-explanatory if you’ve ever used another virtual machine program before. When you reach the Configure Networking pane, you’ll need to select the virtual switch you configured earlier — if you didn’t configure one, the only option you’ll see here is “Not Connected,” which means your virtual machine won’t be connected to the network unless you add a network adapter to its virtual hardware later.
hyper-v-new-virtual-machine-wizard
If you have an ISO file containing your guest operating system’s installation files, you can select it at the end of the process. Hyper-V will insert the ISO file into the virtual machine’s virtual disc drive so you can boot it afterwards and immediately start installing your guest operating system of choice.
install-operating-system-from-iso-file

Boot the Virtual Machine

Your new virtual machine will appear in the Hyper-V Manager list. Select it and “Start” it — click Start in the sidebar, click Action > Start, or right-click it and select Start. The virtual machine will boot up.
hyper-v-manager-start-virtual-machine
Next, right-click the virtual machine and click Connect to connect to it. Your virtual machine will then open in a window on your desktop — if you don’t connect to it, it just runs in the background with no visible interface. Again, it’s easy to see how this management interface was designed for servers.
After you connect, you’ll see a standard virtual machine window with options you can use to control the virtual machine. It should look familiar if you’ve ever used VirtualBox or VMware Player. Go through the normal installation process to install the guest operating system in the virtual machine.
When you’re done installing the operating system, click Action > Insert Integration Services Setup Disk. Open the Windows file manager and install the integration services from the virtual disc. This is Hyper-V’s counterpart to VirtualBox Guest Additions and VMware Tools
hyper-v-connected-window

Using Hyper-V

When you’re done with the virtual machine, make sure you’ve shut it down or turned it off in the Hyper-V Manager window — just closing the window won’t actually close the virtual machine, so it will stay running in the background. The virtual machine’s state should be “Off” if you don’t want it running.
turn-off-virtual-machine-in-hyper-v
Each virtual machine has a settings window you can use to configure its virtual hardware and other settings. Right-click a virtual machine and select Settings to adjust these options. Many of these settings can only be modified while the virtual machine is turned off.
virtual-machine's-settings-in-hyper-v
This tool was created by Microsoft, but that doesn’t mean it only works with Windows. Hyper-V can also be used to run Linux-based virtual machines. We were able to run Ubuntu 14.04 with Hyper-V on Windows 8.1 — no special configuration required.
install-ubuntu-14.04-in-hyper-v-on-windows-8.1

Hyper-V has other useful features, too. For example, checkpoints work like snapshots in VirtualBoxor VMware. You can create a checkpoint and then revert your guest operating system’s state to that state later. It’s a useful feature for experimenting with software or tweaks that may cause problems in your guest operating system

Sunday, July 13, 2014

How to Set Up BitLocker Encryption on Windows

bitlocker-locked-drive-icon

Windows can encrypt entire operating system drives and removable devices with its built-in BitLocker encryption. When TrueCrypt controversially closed up shop, they recommended their users transition away from TrueCrypt to BitLocker.
BitLocker Drive Encryption and BitLocker To Go require a Professional or Enterprise edition of Windows 7, 8, or 8.1. However, the “core” version of Windows 8.1 includes a “Device Encryption” feature that works similarly.

Enable BitLocker For a Drive


To enable BitLocker, open the Control Panel and navigate to System and Security > BitLocker Drive Encryption. You can also open Windows Explorer or File Explorer, right-click a drive, and select Turn On BitLocker. If you don’t see this option, you don’t have the right edition of Windows.
Click the Turn on BitLocker option next to an operating system drive, internal drive (“fixed data drive”), or removable drive to enable BitLocker for the drive.
There are two types of BitLocker encryption you can enable here:
  • BitLocker Drive Encryption:  Sometimes referred to just as BitLocker, this is a “full-disk encryption” feature that will encrypt an entire drive. When the computer boots, the Windows boot loader loads from the System Reserved partition, and the boot loader will prompt you for your unlock method — for example, a password. BitLocker will then decrypt the drive and load Windows. The encryption is otherwise transparent — your files will appear like they normally would on an unencrypted system, but they’re stored on the disk in an encrypted form. You can also encrypt other drives in a computer, not just the operating system drive.
  • BitLocker To Go: External drives, such as USB flash drives and external hard drives, can be encrypted with BitLocker To Go. You’ll be prompted for your unlock method — for example, a password — when you connect the drive to your computer. If someone doesn’t have the unlock method, they can’t access the files on the drive.
bitlocker-drive-encryption[4]

Use BitLocker Without a TPM


BitLocker Drive Encryption normally requires requires a computer with a TPM to secure an operating system drive. This is a microchip built into the computer, installed on the motherboard. BitLocker can store the encryption keys here, which is more secure than simply storing them on the computer’s data drive. The TPM will only provide the encryption keys after verifying the state of the computer. An attacker can’t just rip out your computer’s hard disk or create an image of an encrypted disk and decrypt it on another computer.If the PC you’re enabling BitLocker on doesn’t have a Trusted Platform Module (TPM), you’ll see a message saying your administrator must set the “Allow BitLocker without a compatible TPM” option.
bitlocker-can't-use-a-trusted-platform-module
If you’re doing this on your own computer, you’re the computer’s administrator. You’ll just need to open the Local Group Policy Editor application and change this setting.
Press Windows Key + R to open the Run dialog, type gpedit.msc into it, and press Enter. Navigate to Computer Configuration \ Administrative Templates \ Windows Components \ BitLocker Drive Encryption \ Operating System Drives. Double-click the “Require additional authentication at startup” setting, select Enabled, and check the “Allow BitLocker without a compatible TPM” option. Click OK to save the new setting.
use-bitlocker-to-encrypt-system-drive-withotu-tpm

Choose an Unlock Method

Next, you’ll see the “Choose how to unlock your drive at startup” screen. You can select several different ways of unlocking the drive. If your computer doesn’t have a TPM, you can unlock the drive with a password or by inserting a special USB flash drive that functions as a key.
If your computer does have a TPM, you’ll have additional options. For example, you can configure automatic unlocking at startup — your computer will grab the encryption keys from the TPM and automatically decrypt the drive. You could also secure it in other ways — for example, you could provide a PIN at startup. That PIN would unlock the strong decryption key stored in the TPM and unlock the drive.
Choose your preferred unlock option and follow the instructions in the next screen to set it up.
bitlocker-drive-encryption-choose-how-to-unlock-your-drive-at-startup

Back Up Your Recovery Key

BitLocker will provide you with a recovery key. This key can be used to access your encrypted files if you ever lose your main key — for example, if you forget your password or if the computer with the TPM dies and you have to remove the drive.
You can save the key to a file, print it, store it on a USB flash drive, or save it to your Microsoft account on Windows 8 and 8.1. If you back up the recovery key to your Microsoft account, you can access the key later at https://onedrive.live.com/recoverykey . Be sure to keep this key safe — if someone gains access to your key, they could decrypt your drive and bypass the encryption. You may want to back it up in multiple locations — if you lose this recovery key and your main unlock method, your encrypted files will be lost forever.
bitlocker-drive-encryption-how-do-you-want-to-back-up-your-recovery-key

Encrypt and Unlock the Drive

BitLocker will automatically encrypt new files as you add them, but you’ll need to choose what happens with the files currently on your drive. You can encrypt the entire drive — including the free space — or just encrypt the used disk files to speed up the process.
If you’re setting up BitLocker on a new PC, encrypt the used disk space only — it’s faster. If you’re setting BitLocker up on a PC you’ve been using for a while, you should encrypt the entire drive to ensure no one can recover deleted files. Encrypting only the used disk space is faster, while encrypting the entire drive takes longer.
You’ll be prompted to run a BitLocker system check and reboot your computer. After the computer boots back up for the first time, the drive will be encrypted. Check the BitLocker Drive Encryption icon in the system tray to see its progress. You can continue using your computer while it’s being encrypted, but it perform more slowly.
bitlocker-choose-how-much-of-your-drive-to-encrypt
When your computer boots, you’ll see a BitLocker prompt if you need to enter a password, PIN, or plug in a USB flash drive.
Press Escape here if you lose your unlock method. You’ll be able to enter your recovery key.
bitlocker-unlock-prompt-at-boot
If you choose to encrypt a removable drive with BitLocker To Go, you’ll see a similar wizard but your drive will be encrypted without any rebooting required. Don’t remove the drive while it’s being encrypted.
bitlocker-to-go
When you connect the drive to a computer, you’ll be prompted to provide the password or smart card you chose to unlock the removable device. Drives protected with BitLocker are identified with a lock icon in Windows Explorer or File Explorer.
bitlocker-to-go-enter-password-to-unlock-drive
You can manage a locked drive — change the password, turn off BitLocker, back up your recovery key, or perform other actions — from the BitLocker control panel window. Right-click an encrypted drive and select Manage BitLocker to go directly to it.
manage-bitlocker-in-control-panel

Like all encryption, BitLocker does add some overhead. Microsoft’s official BitLocker FAQ says that “Generally it imposes a single-digit percentage performance overhead.” If encryption is important to you because you have sensitive data — for example, a laptop full of business documents — it’s worth the performance trade-off.

Friday, July 11, 2014

How to Bypass and Reset the Password on Every Operating System

reset-or-bypass-operating-system-or-device-password
Passwords can be reset or bypassed on every operating system. On Windows, Linux, and Mac OS X, you can gain access to a computer’s unencrypted files after resetting the password — the password doesn’t actually prevent access to your files.
On other devices where you can’t gain access to the files, you can still reset the device and gain access to it without knowing a password. These tricks all require physical access to the device.

Windows


Resetting a password without an official tool is fairly simple. For example, the Offline NT Password & Registry Editor works well for this. First, you’ll need to boot from a special disc or USB drive — either a live Linux system or a specialized Offline NT Password & Registry Editor boot disc. The tool can edit the Windows registry, allowing you to clear the password associated with the user account. You can then boot into Windows and log into the account without a password.There are many ways to reset a Windows password. Windows allows you to create a password reset disk that can reset your password in an approved way — create a disk first and you can use it if you ever need it.
Even if you’re using Windows 8 with a Microsoft account, you can always reset the password of the built-in Administrator account to gain access.
To protect against this, you could password-protect your BIOS and restrict booting from external devices. Someone with physical access to the PC could reset the BIOS password to bypass this.Encrypting your Windows system drive with something like BitLocker would prevent the registry from being accessed and modified with this tool — encryption is the only good protection.
image

Linux

We’ll use Ubuntu as a concrete example here. Ubuntu offers a recovery mode in its default Grub boot menu — select Advanced options for Ubuntu and select Recovery mode. You’ll see the boot menu while booting your computer — if you don’t, you can hold the Shift key as you boot and the menu will appear.  You can easily boot directly to a root shell prompt from here.
This option isn’t necessary, as you can just press the e button to edit Ubuntu’s boot options and boot directly to a root shell prompt from within the main Grub menu. You’ll then be able to use the root shell to reset and change passwords on the system. If the Grub boot menu is locked and password-protected, you can still boot to Linux live media and change your password from there.
Once again, encryption would prevent your system from being accessed and modified without your encryption passphrase. We used Ubuntu as an example, but almost every Linux distribution uses Grub and few people set a Grub password.
ubuntu-recovery-menu-drop-to-root-shell-prompt

Mac OS X

Macs have a built-in password reset tool, and it’s very easy to access. This option is available in recovery mode. You’ll need to restart your Mac by clicking the Apple menu and selecting Restart. Press and hold the Command + R keys as the computer boots and it will boot into recovery mode.
Click the Utilities menu in recovery mode, select Terminal, type resetpassword into the terminal, and press Enter. You’ll see the Reset Password utility, which allows you to reset the password of a any user account on the Mac. You can also access this tool from a Mac OS X installation disc.
To prevent your Mac’s password from being reset, you could enable FileVault disk encryption on your Mac, set a firmware password inside recovery mode, or both.
reset-mac-os-x-password-from-recovery

Chrome OS

Your Chromebook’s user account password is your Google account password. You could reset your Google account password on the web to regain access.
Let’s say you have a Chromebook you want to use, but you can’t sign in. Perhaps you’ve forgotten the Google password associated with the device. Perhaps an old Google account is considered the device’s owner account. In this scenario, you can boot the Chromebook to the sign-in screen and press Ctrl + Shift + Alt + R at the same time. You’ll be prompted to factory reset your Chromebook with Powerwash. After you reset it, you can log in with another Google account and that Google account will be considered the owner account. This will erase all data on the device, but most Chromebook data is synced online.
There’s no way to gain access to a user’s files without their password on a Chromebook — those files are encrypted by default.
powerwash-or-reset-chrome-os-from-login-screen

Android


If you don’t have this information either, you may be able to bypass the lock screen in other ways. This should be easy on a device with USB debugging enabled, as you can connect it to a computer and manipulate it over USB with adb — that’s why USB debugging is disabled by default.If you forget your Android’s lock screen code, you can reset it. Try an incorrect password, PIN, or pattern a few times and you’ll eventually see a “Forgot password,” “Forgot PIN,” or “Forgot pattern” option. You can then regain access to your device by entering the username and password of the Google account associated with your device.
You can’t bypass the lock screen without your Google account password unless there’s a hole open in the device — for example, USB debugging. If you want to use the device, you can stillperform a factory reset from recovery mode — this will set the device back to its factory state, wiping the data on it . You can then log in and set up the device with another Google account.
android-wipe-data-factory-reset

iOS

RELATED ARTICLE
iPhones, iPads, and iPod Touches are also built without a way to reset the password. Unlike on Android, you can’t just reset the device’s password with your Apple ID information. If you forget your iOS device’s password, you’ll have to perform a factory reset. However, if you’re syncing the device to an Apple ID and you still remember your Apple ID password, all your device’s data can be restored afterward thanks toiCloud backups.
You can do this in several ways. If you’ve set up Find My iPhone, you can visit the iCloud websiteand erase your device from there. If you’ve backed up your device to iTunes on a computer, you can connect the device to your computer and restore your device from an iTunes backup.
If you don’t have access to Find My iPhone and you’ve never backed up the device to iTunes, you can still reset the device using recovery mode. Turn off the device, press and hold the Home button, and then connect the device’s USB cable to your computer. If it doesn’t turn on automatically, turn it on. iTunes will tell you it’s detected a device in recovery mode and allow you to restore it to factory default settings.
restore-ipad-or-iphone-from-recovery-mode

Passwords keep honest people honest, and they ensure people can’t gain access to your device without knowing the tricks or looking them up. But, if someone has physical access to your device and wants to bypass the password, there’s nothing you can do to stop them. Even encrypting your files will only protect your personal data — they can always wipe the encrypted data and start over fresh.