When BitLocker Is Not Enough: HP TPM Guard Protects Against Physical Attacks
BitLocker is no longer sufficient. This is the conclusion reached by HP, which recently announced TPM Guard as a feature included in its devices to prevent a new type of very sophisticated attacks that render Windows functionality effectively useless.
HP TPM Guard Resolves a Vulnerability of BitLocker
BitLocker was created as a solution to protect data from physical attacks: the entire partition is encrypted, making the data completely inaccessible, even if the disk is removed and inserted into another computer to bypass the need for the Windows password.
Gaining access to devices and the data contained within them is of particular interest to criminals, as it often allows access to confidential information or internal applications, with the possibility of entering and establishing themselves within corporate networks. Stealing a laptop is therefore a (relatively) easy solution to access a device without having to penetrate cybersecurity defenses, and BitLocker is designed to stop this kind of attack.
The problem is, as HP points out, that the architecture itself has vulnerabilities. A technique known as "TPM bus snooping" allows interception of communications between the CPU and the TPM, the security module that manages cryptographic keys, including the BitLocker key. The communication between the CPU and TPM is not actually encrypted, allowing criminals with the right equipment (which costs as little as 20 dollars) to insert themselves between the two to intercept the BitLocker keys, granting unlimited access to the data. Since this is a hardware problem, merely updating the software is not sufficient.
This type of attack completely changes the game, as companies that need to protect locally stored data on devices can no longer rely on BitLocker as a protective measure. This is not a novelty: throughout history, we have seen a constant chase between defenses and weapons, moving from wooden palisades to castles and from arrows to cannons. To make a comparison, it’s as if BitLocker were a medieval castle where one can reach the gate undisturbed. TPM Guard is therefore the equivalent of a drawbridge.
TPM Guard encrypts the data that passes between the CPU and the TPM, thus preventing snooping attacks. Not only that: the TPM itself is encrypted and tied to the specific device, meaning it cannot be extracted and read on another device.
HP presented TPM Guard at Imagine 2026 and intends to include it on all PCs presented from this year onwards to ensure data security. At least until a new attack is discovered that renders current defenses ineffective.