Data Recovery Case File · Case 1650 · The Key and the Right to Use It
Encryption Binds Data to a Person, and a Person Is Not Always Available
This enquiry is from a brother acting for his sister. Her personal laptop is encrypted with the full-disk encryption built into its operating system, and "my sister is recovering from a stroke with no memory of anything from the last five years. I brought it to a shop which attempted, however had no experience dealing with" it. He adds that the contents must remain intact — including the credentials stored in her browser, which are the keys to everything else in her life.
| Media | Personal laptop with full-disk encryption enabled — passphrase not available; owner unable to supply it following illness; recovery credential location undetermined |
| Reported situation | Personal laptop belonging to the enquirer's sister · full-disk encryption enabled · passphrase not recoverable from the owner following a stroke affecting memory of recent years · prior attempt by a provider without relevant experience · contents required intact including stored browser credentials · owner recovering |
| Fault class | No device fault — access governed by a credential that is not held; recovery credential escrow the only technical route, with authority to act a separate and prior question |
| Equipment used | Authority to act established before any technical work · recovery credential escrow locations enumerated across account, organisational and physical possibilities · drive imaged write-blocked so the encrypted volume is preserved unaltered pending a credential · stored credential material treated as restorable to the owner rather than readable · position stated honestly before any charge |
The decode: what encryption is doing, and the failure nobody plans for
What full-disk encryption promises: that the contents are available to one person and to nobody else. Not difficult for others — unavailable, in a way that no amount of skill, equipment or persistence changes. That is the entire design, and it works.
What it cannot distinguish: between somebody who should not have access and somebody who should. The device does not know who is asking — it knows only whether the correct credential has been supplied, which is precisely what makes it worth having.
So the failure mode, stated plainly: it protects the data against her as well. Her laptop is doing exactly what she configured it to do, and the thing standing between her and her own photographs is the thing she chose to protect them with.
Now the observation this archive has been circling for sixteen hundred cases. Everything here is about copies — two drives, two locations, a backup that has been verified, a second machine that still holds the originals. And a passphrase held in one human memory is a single point of failure that nobody thinks of as storage at all.
It has no redundancy, no monitoring and no warning. There is no notification when it becomes unreadable. Nobody audits it. And the circumstances in which you most need it — illness, injury, distress, time — are exactly the circumstances in which a memory is least reliable. This case is not a hypothetical version of that; it is the actual version.
The route that exists: find the recovery credential
Why there is genuine hope here rather than a polite hedge: systems of this kind generate a separate recovery credential when encryption is switched on. They do it precisely because passphrases are forgotten, and it is designed to be stored somewhere other than in the user's head.
Where to look, and this is a search rather than a technical problem. The account she was signed into when encryption was enabled — recovery keys are commonly escrowed there automatically and are visible from any browser once signed in. A work or educational account, if the machine was ever enrolled with one, in which case an administrator holds it. A printed copy or a saved file, if that option was chosen at setup. And the possibility that the device was supplied by an employer or an institution that retains it.
Why that is where the effort belongs: because the alternative does not exist. The encryption itself will not yield — its strength lies in the number of possible keys rather than in a mechanism that better equipment eventually opens, and waiting for technology to improve does not change that.
What to do with the device meanwhile: image it and preserve it. An encrypted volume kept as an unaltered image can be opened the moment a credential surfaces, and it removes the risk of the hardware failing while the search continues — which on a laptop that will now sit in a cupboard for months is a real risk rather than a remote one.
The doctrine of case 1650: you need the key and the right to use it
Almost every case in this archive asks one question — can this be read? This one asks two, and the second is easy to miss because it is not technical.
The laptop belongs to his sister. She is recovering, and at the moment she cannot say what she wants done with it. Which means somebody is going to make decisions about her private life on her behalf — and doing that properly is a question about authority, not about equipment.
Why it matters more here than in most cases: because of what he has correctly identified as important. The stored browser credentials are not merely files. They are access to her email, her banking, her accounts and her correspondence — the keys to everything else she owns. A laptop like this is not a container of documents; it is the master key to a life.
What follows from that: the material should be treated as hers throughout. Restored to her, not read. Where she can consent, her consent is what makes this straightforward. Where she cannot yet, the frameworks that exist for acting on behalf of somebody who lacks capacity exist to protect her — and using them is not bureaucracy, it is the difference between helping her and simply having access to her.
Why saying this is not a reproach: he is plainly acting for her, he has kept the device safe, and he asked before doing anything irreversible. Everything about the enquiry is careful. The point is that the care should extend to the question of standing, because that is the part nobody thinks to ask about.
On the bench
Authority to act was established before any technical work — access to a device belonging to somebody who cannot presently consent raising a question of standing prior to any question of method, particularly where stored credential material constitutes access to the owner's wider accounts. Recovery credential escrow locations were enumerated across account, organisational and physical possibilities, such credentials being generated at encryption specifically against passphrase loss. The drive was imaged write-blocked so the encrypted volume is preserved unaltered pending a credential, and stored credential material treated as restorable to the owner rather than readable.
The outcome
Authority established before any technical work, escrow locations enumerated, and the encrypted volume preserved as an unaltered image pending a credential. Free assessment, one fixed written figure including VAT — and no charge where no credential can be located. The decode, and the doctrine of case 1650: encryption binds data to a person, and a person is not always available — including to themselves. A passphrase held in one memory has no redundancy, no monitoring and no warning, and the circumstances in which you need it most are the ones in which memory is least reliable. The route that exists is the recovery credential, generated for exactly this reason and escrowed somewhere outside her head. And more than that: opening a device takes two things, the key and the right to use it. This archive is almost entirely about the first. The second matters most precisely when the person it belongs to cannot speak for themselves.
Encrypted device belonging to somebody who cannot supply the passphrase
Look for the recovery credential rather than for a way past the encryption — there isn't one, and waiting for technology to improve won't produce one, because the strength is the number of possible keys rather than a lock that better tools eventually open. Systems that encrypt a whole disk generate a separate recovery credential when it's switched on, precisely because passphrases get forgotten. Check the account that was signed in at the time, where it's commonly escrowed and visible from any browser. Check whether the machine was ever enrolled with a work or educational account, in which case an administrator holds it. Check for a printed copy or a saved file among their papers. Have the device imaged and preserved meanwhile, so a credential surfacing months later still opens something. And settle the question of authority before the question of method: where the owner cannot yet consent, the frameworks for acting on behalf of somebody who lacks capacity exist to protect them, and a personal laptop usually holds the stored credentials to their email, banking and accounts — which is to say the keys to everything else. Treat it as theirs throughout: restored to them, not read. Then, for yourself: if you encrypt a device, put the recovery credential somewhere outside your own head and outside the device. Printed with your important papers, or held by somebody you trust, or in an account you can reach from another machine. The situations where you need it are the situations where you cannot remember it.
Call Oxford Data Recovery on 01865 593000; authority established before any technical work, escrow locations enumerated across account and organisational possibilities, encrypted volume preserved unaltered pending a credential — and no charge where none can be found.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.