Earlier quoted context omitted.
> Not what happened here (I reserve my judgment wrt the promised TPM+PIN exploit). Yes this is the one I'm referring to. I have noticed it myself, it has happened to me that my system rebooted to install updates and it did not pass through the blue TPM pin entry screen at that point. That was a big red flag for me. A normal reboot always does that, even a 'hot' reboot.
Bitlocker can be suspended, and will be unprotected until the next reboot. Then it will resume (and presumably re-lock to the current state) A good or corporate BIOS/etc. updater will do this to avoid requiring a recovery at the next boot
But the files on the disk must still be decrypted somehow. The key must be stored somewhere.
According to this: https://windowsforum.com/threads/pause-bitlocker-before-bios...
> BitLocker is now suspended, which means the drive remains encrypted, but Windows temporarily stores the unlock information so firmware changes won’t immediately trigger recovery.