Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Trust, Practice & Honest Limits · The Key, Not the Cipher

Encryption Does Not Get Weaker, So the Hope Is Elsewhere

Her enquiry has been waiting eight years for an answer that is not coming in the form she hopes. A computer encrypted by a workplace product, where her father changed the password and "ultimately forgot it days later. We are hoping that as technology becomes more advanced there could be a way to decrypt" it, to reach childhood photographs and video. Waiting will not help — but there is a genuine route, and it has nothing to do with defeating the encryption.

MediaLaptop encrypted with a workplace full-disk encryption product — user password not known; deploying organisation no longer trading; personal photographic and video content held
Reported situationComputer encrypted with an enterprise full-disk encryption product · user password changed and subsequently forgotten · numerous password attempts unsuccessful over several years · machine linked to both personal and workplace use · deploying organisation since ceased trading · personal content required
Fault classAccess controlled by a key that is not held — no device fault present; recovery credential the only route, with no technical alternative
Equipment usedPosition stated honestly before any assessment · recovery credential routes identified as the only viable approach · drive imaged write-blocked so the encrypted volume is preserved unaltered · password recall avenues discussed · no charge where no credential can be located

The decode: why waiting does not work, and what does

Why the hope is understandable: most technical obstacles do yield to time. Things that were impossible become routine, which is a reasonable expectation formed from watching computing improve for decades.

Why encryption is the exception: its strength does not sit in a mechanism that better tools can pick. It sits in the number of possible keys, which is chosen to be beyond exhaustive searching by any conceivable amount of computing. Faster machines do not shorten that meaningfully, because the quantity is not the kind of large that faster helps with.

So the honest statement, which she deserves plainly: nobody is going to be able to decrypt this without the key. Not now, and not through waiting — and eight years of hoping on that basis is eight years better spent on the route that might work.

Why it is important that this is true: the same property protecting her father's disk is what protects everybody's banking, medical records and messages. An encryption that could be defeated by a determined specialist would be worthless, so the thing standing in her way is the thing doing its job.

Now the route that exists. Products of this kind, deployed by an organisation across staff machines, do not rely on the user's password alone. They generate a separate recovery credential at deployment — held by whoever administered the installation — precisely because employees forget passwords and leave.

Why the organisation ceasing to trade may not end it: records survive company closures. Administration and liquidation processes retain business records, IT contractors keep documentation, and the people who ran the systems are findable. That is a paperwork exercise rather than a technical one, and it is where the effort belongs.

What is also worth pursuing, and costs nothing: the password was changed days before being forgotten. People do not invent new schemes when they change a password — they vary the previous one, so anything remembered about earlier passwords is a starting point. Anywhere he wrote things down is worth looking too.

What can be done with the machine meanwhile: the drive imaged and preserved. An encrypted volume kept as an unaltered image can be opened the moment a credential surfaces, and it removes any risk of the hardware failing while the search continues.

On the bench

The position was stated honestly before any assessment — encryption strength residing in the size of the key space rather than in any mechanism that improved tooling addresses, so elapsed time and faster computing do not alter it. Recovery credential routes were identified as the only viable approach, enterprise deployments generating an administrative recovery credential precisely against user password loss. The drive was imaged write-blocked so the encrypted volume is preserved unaltered pending a credential.

The outcome

The position stated honestly before any assessment, credential routes identified, and the encrypted volume preserved as an unaltered image. Free assessment, and no charge where no credential can be located. The decode: waiting will not help, because encryption strength is the number of possible keys rather than a mechanism that better tools open. The route that exists is the recovery credential the deploying organisation generated — and company records survive closures.

Encrypted machine with a forgotten password

Pursue the recovery credential rather than waiting for technology, because encryption doesn't get weaker with time — its strength is the sheer number of possible keys, not a mechanism that better tools eventually pick. If the machine was encrypted by an employer, the product will have generated a separate administrative recovery credential at deployment, precisely because staff forget passwords and leave. A company ceasing to trade doesn't necessarily end that: business records survive closures, IT contractors keep documentation, and the people who ran the systems can be found. Meanwhile, a password changed days before being forgotten is usually a variation on the previous one.

Encrypted device and no password?
The credential is the route — call Oxford Data Recovery on 01865 593000; honest position before any assessment, volume preserved as an unaltered image pending a credential, and no charge where none can be found.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.