Bench log · Where the limit falls · HUL-2025-0330
The Reader Stopped Knowing My Thumb.
Her thumb had unlocked that ProBook since the day it arrived. An update ended that — the fingerprint box has gone off the login screen
— and left her with a PIN set on the first afternoon and never used since: I typed it the once, then the reader took over
. Four wrong tries and the machine shut her out. It was payroll week. Four clients over in Skegness were waiting. On the drive sat eight years of other people's accounts
.
Sounds like yours? Ring us.
0800 6890668
What causes it.
Two locks are possible here and they have nothing to do with one another. Take the module out, put it on bench hardware, and you can see within minutes which one applies. A Windows password guards an account and stops there. The sectors below it are unaffected. That login has held her off for a week; read the flash directly and it is not in the picture at all. BitLocker works differently. It encrypts the volume end to end. Lacking the key — a recovery password will do instead — anything we lift off the flash reads as noise. Our bench is no exception to that. The first case is a few hours of work. The second is closed to us and to everyone else. Establishing which one you have is free, so we do it first.
The tools this one needed.
The steps we follow →| The gear | What this one did | Why we have it |
|---|---|---|
| Atola Insight Forensic | Copied the NVMe behind a write blocker, before keys were even discussed | Clones more than one drive at a time, write-blocked, with a log of every step |
| PC-3000 SSD | Showed the module itself was healthy, so nothing behind the lock was faulty | Talks to the flash controller direct, underneath anything the operating system reports |
| UFS Explorer Professional Recovery | Mounted the unencrypted volume at once; the other one waited for its key | Opens the volume formats most tools cannot: APFS, ReFS, XFS, ZFS, Btrfs |
The stages.
Copy it before the lock is even discussed
The copy came before everything else. Module out of the chassis, onto a hardware write blocker, image taken there. On a job of this sort the habit pays for itself twice. If a question is ever raised about who owns the laptop, or about what we did to it, the module can be shown in the condition it reached us. If no question comes, the caution cost nobody anything.
Read the headers before quoting anything
A minute reading headers settled where we stood. Volume one was plain NTFS with the system on it; taken directly, the login that had blocked her all week counted for nothing. Volume two carried the ledgers, and a BitLocker signature with them. She had turned it on years earlier, prompted by a checklist her professional body put out, and had then forgotten about it. The written quote covered both.
Look for the printed key before giving up
BitLocker states which key it wants. We gave her that identifier on the phone. She was adamant no such thing had ever come to her. Then she recalled Windows pressing her to print something she had made no sense of then. It was filed in a ring binder, one page behind her practising certificate. The volume opened on the first try. Without that page it would have stayed locked, and we would have told her that.
How it finished.
She got both volumes back. On the system side there was no sign a lock had ever existed; the ledgers gave way to a page printed years ago and ignored ever since. Payroll went out forty-eight hours late, on fresh media. The recovery key is kept in three spots now. The laptop is not one of them.
What people read after this.
Cases with a hard limit.
Is yours doing the same?
Turn it off. Send it to us. The diagnosis comes first. It says which files are still readable and which are not.