• Jeena@piefed.jeena.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    1 month ago

    Perfect, this will finally lock out all the old people of their devices because they forget their bitlocker password :D

    • Lucy :3@feddit.org
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 month ago

      I guess they’ll use TPM. I’m so excited to tell half of my “clients” (all seniors in the village) that they are fucked because their Laptop died.

      • wizardbeard@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Yeah, this makes sense for corporate environments with keys backed up to a centralized location like Active Directory. Not for consumers with no reasonable way to keep some key like this in a safe place as a “break glass in case of emergency” option.

        • Romkslrqusz@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 month ago

          It backs up to the Microsoft Account

          Still, some people create an @outlook.com email, set up no recovery options, forget the password, and find themselves locked out.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        You don’t need your hard drive if all your files have been secretly moved to OneDrive taps forehead.

      • dogslayeggs@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Unless you don’t have an MS account or only set up a dummy account just to get the stupid OS to activate and have never used once since.

        • stephen01king@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          1 month ago

          Wel then, either get a Microsoft account that you remember the password to or don’t use Windows since they are pushing hard for this type of security. Linux is completely free for people who don’t like the way Windows is heading towards.

  • Vahenir@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 month ago

    This one is especially fun on windows 11 home. At least it was some time ago on some machine i worked on. Since home doesn’t have the bitlocker settings fully you cannot disable bitlocker encryption. It would also auto enable sometimes even if you don’t have a microsoft account, which means it doesn’t back the key up anywhere. Not sure it does that anymore, i hope not, but i expect a lot of people to lose their data to this crap in the future.

    In either case at least i find that full disk encryption on most machines is just overkill as it only really protects in the scenario the device is stolen and someone tries to pull data off of it that way. But in the vast majority of cases when people get their data stolen its done with malware, which disk encryption does /nothing/ to prevent.

    • MoonlightFox@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      1 month ago

      In the scenario in which your computer is forgotten or stolen, it would offer some comfort knowing that the data on the computer is not accessible.

      We have a “policy” in our household that everything that has personal data should be encrypted. That is just for cases in which we lose the device or it gets stolen. That makes it a purely financial loss, and not as invasive / uncomfortable.

      But on the other hand my household are not average users. So it might not work well for other people.

  • zecg@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 month ago

    This will make people angry in waves as updates break bitlocker and cohorts don’t have their key, a new one each time

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      If you’re getting tickets, I assume you mean at work? What’s a business doing running Home and no Domain? This isn’t an issue on machines joined to a domain.

      • azuth@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Rofl.

        The vast majority of small business do run on Home have no clue wtf a domain is. Probably share files via google drive rather than a file server.

  • Hal-5700X@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    1
    ·
    1 month ago

    Do the average Windows user really need BitLocker device encryption? They don’t. The only users who need BitLocker are business’ and government workers.

    Also 99% of Windows users are going to get locked out of their computers.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      1 month ago

      Everyone needs drive encryption.

      And no, 99% of Windows users aren’t going to get locked out.

      99% of Windows boxes are business boxes, which already are encrypted (and if they aren’t, that’s some bad IT).

      This really only affects Home users, who don’t enable encryption because they don’t know any better. I have no doubt we’ll see quite a few people have issues because they lose their key and can’t recover their data. This is why MS should provide clear directions during setup about storing the key. Instead they’re going to keep it in people’s OneDrive/365 account. Such a bad idea. Now I’ve gotta write documentation for friends and family about what NOT to do during setup.

      • Hal-5700X@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        This is why MS should provide clear directions during setup about storing the key.

        Now I’ve gotta write documentation for friends and family about what NOT to do during setup.

        Okay. You need to write documentation for your friends and family, but Microsoft have clear directions.

    • LunchMoneyThief@links.hackliberty.org
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      the days of popping out a hard drive, and grabbing whatever the hell’s on there with a usb connection are over

      Independent repair shops are going to suffer big time from this.

        • LunchMoneyThief@links.hackliberty.org
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          I’ve supported bitlocker in corporate deployments. I have also spent some time in independent repair shops. I have little confidence in users to supply a bitlocker key, let alone even know what one is. I anticipate a lot of “what? I already gave you my password.”

      • db2@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Clearly you didn’t do any machine recovery during that fiasco or you wouldn’t ask. When the machines crashed the only fix was to get in and delete the offending file, but as Windows wouldn’t load up you had to unlock the drive to get in with a working OS.

  • Magister@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    1 month ago

    It’s good, for privacy and all of course, but I remember here a Dell BIOS upgrade that basically wiped the TPM2.0 and so windows was asking for the recovery bitlocker key at boot. I have them on a encrypted USB key and anyway I can access my MS account from another device to find the key and type it.

    But I’m sure a lot of people will basically say “well, fuck, I don’t have the key”, guaranteed.

    • lemmyvore@feddit.nl
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Which brings me to the question, how is Microsoft doing this, where will people’s keys be located? Do they force everybody to put in an USB stick?

      • stupidcasey@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        Don’t know don’t care, anyone with half a brain saw windows was a sinking ship around the time they started putting ads in a $150 software but if that wasn’t enough forcing you to decline ads every 2 weeks or whatever is just psychopathic behavior so is the degraded search, I unironically would choose chrome Os or Ios over windows theses days especially since the world has moved to browsers and os doesn’t matter but any way you look at it the steam deck has proven windows has about as necessary as AOL these days, if you’re still using windows that’s a you problem, backwards compatibility be dammed you should not be relying on this company for anything crucial it can’t be trusted.

        • wizardbeard@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          0
          ·
          1 month ago

          Good job being so smart, mama’s little smart man! You still have to eat your veggies before you can have any dessert though!

          More seriously, the overwhelming majority of businesses use Windows as their end user facing desktop OSes. You’re legitimately just being a myopic asshat if you think that Windows can’t be trusted for anything important. (Inb4 you bring up Crowdstrike, which wasn’t a Windows specific issue, but a “we have code running at kernel level” issue, and hit Linux roughly three months prior to the big clusterfuck)

          Also, your bit about $150 cost for the OS is dumb too. The average user is buying a prebuilt with the OS preinstalled. Technically they are paying for it, but it’s a wacky discounted OEM license fee baked into the full cost. Anyone not buying a rig with Windows preinstalled can use it unlicensed, can transfer license from pretty much any older Windows OS install from the last 20 years, can just use massgrave to activate it for free, or could go buy a discounted OEM license that they can only install to one machine. The full price license allows for install on multiple machines, which you don’t really need.

          My point is, very few people are paying full price for a Windows license.

          Full disclosure, I agree that Microsoft is a shit company. But this elitist shit is just stupid. Especially when it’s almost pure posturing.

          • stupidcasey@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            1 month ago

            Oh no the poor companies making money off a product might have to update a product made in 1992😱😱😱how will they ever recuperate an investment that is free every 32 years.

            Also a Monopoly is able to use monopolistic behavior to force companies to use their product and mask it as “FREE”*** then still charge the user with ads is not a good thing just look at the price delta between equivalent windows and chrome books if you don’t believe me.

            IM not saying you have to get the L word I would literally get a MacBook at this point.

            • wizardbeard@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              What? Huh? The fuck are you even trying to say with that first paragraph and what connection does it have with my comment?

              My point was that for someone calling people still willing to use Windows stupid, your lack of knowledge about the actual cost (and how almost no user is paying the full cost) makes you look incompetent at best.

              There was precisely zero there lamenting Microsoft missing out on money. Check my host lemmy instance, it’s the piracy one. There’s a reason I name dropped the best open source tool for tricking Windows into thinking you have a valid license. Steal your OS, I don’t give a fuck. The only “validly” licensed personal machine I have is my main desktop, and only because it was my first time doing a manual customized Win 10 install so I didn’t want to fuck around with faking the license to save myself $20 for an OEM license.

              Which brings me to my next point. For someone being so bull headedly elitist about how bad Windows is, and how smart they are, you’re completely unaware of how easy it is to make Windows work for you and disable all the user hostile shit like ads.

              It’s called install the Pro version of the OS and use Group Policy manager. 90% of the settings are clearly labeled in there too, like “Disable Cortana Internet Search”, “Disable OneDrive integration”.

            • BearOfaTime@lemm.ee
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              Made in 1992?

              Niw you’re really showing your ignorance.

              Yes, NT 3.5 was released in about 1992. But it was actually a ported DEC Alpha OS from a few years before…so perhaps 1988.

              And the OS today is very different from NT 3.5. So it’s not software that was “made in 1992”.

              Not that when it was first released has any relevance anyway. Hell, I’m more partial to software that’s been around for ages. It’s demonstrated itself over time.

              But I guess someone who’s still wet behind the ears doesn’t get that.

            • Blackmist@feddit.uk
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 month ago

              The Linux boys on this site actually make me want to try it less.

              They’re the Rick and Morty fans all over again.

    • isles@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Where’s your encrypted USB recovery key stored?! Is it encrypted USBs all the way down?

  • Romkslrqusz@lemm.ee
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    […] device encryption will be enabled by default when you first sign in or set up a device with a Microsoft account or work / school account.

    For devices with a TPM, this has literally been the case since Windows 10 1803 back in 2018.

    • bandwidthcrisis@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      But that’s not the case for Windows Home, is it? The FDE setting just takes me to a page to upgrade to Pro. My laptop does have TPM.

  • Shadywack@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    Cool, let all the dumb fuck time vampires suffer. I won’t be helping anyone with shit. “Shoulda bought a Mac”

  • robber@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    I think this is a step in the right direction. Everyone can lose a portable device or it can get stolen, so protecting the potentially sensitive data is important.

    I think what people are complaining about is not full-disk encryption itself, but the fact that people are not used to being responsible for their cryptographic keys.

    I think we should educate people regarding this responsibility. We did it with regular keys we use to unlock our homes.

    • Appoxo@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 month ago

      Are they even saved by default in an MS account? Because if I’d link one, I would expect them to at least prompt me

      • stephen01king@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        1 month ago

        I believe you can find them in the first Microsoft account that you registered to that windows install.

        • gwen@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 month ago

          happened to my ma’s computer, her microsoft account+key was not saved in there so she just. lost all her important work documents. also, what of the people who don’t have another device to look up the website where the key is stored?

          • stephen01king@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            arrow-down
            1
            ·
            1 month ago

            Well, most people do have a secondary device, and of those that don’t, in most cases they can just use someone else’s.

  • Brkdncr@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    1 month ago

    The anti-MS here is annoying. They set up online accounts by default to improve usability and its complaints about privacy. They set up full disk encryption at rest by default to improve privacy and its complaints about usability.

    • BearOfaTime@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      1 month ago

      They set up online accounts by default to improve usability

      Hahahahaha, you’re kidding, right? Or do you genuinely believe this?

      Unless you mean usability for MS tracking and telemetry of home users who lack the expertise of enterprise IT (which uses Windows Pro, and disables/blocks the MS tracking via Group Policy, which isn’t available on Windows Home).

      The reason for defaulting to an MS account, and making it practically required (they even hide creating a local account during setup if it has a network connection), is to capture even more user data and telemetry.

      Now, defaulting to encryption is a good thing. But, the way to do it is to explain during setup (and have a process for) saving the key to another device immediately after setup - such as a thumb drive. Or even printing it, saving it to a text file, etc, etc.

      It should also explain how critical it is, and not to trust saving it to a single device/location.

      • RubberDuck@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        1 month ago

        From powerusers yes, and taking away their options is nonsense. But for the general populace it is arguably a good thing.

    • IHawkMike@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      1 month ago

      Agreed. The immature iamsosmart user base is making me strongly consider leaving Lemmy for good. There just aren’t enough actual professionals here for any serious discussion in a technical community. It’s just a bunch of 20-year-olds who think they have the world figured out. And they all downvote based on emotion rather than facts (which I am quite prepared for).

      Microsoft accounts, OneDrive, and BitLocker are absolutely great features for the average user providing SSO, cloud storage with ransomware-proof backups, and seamless full-disk encryption.

      I love Linux too, but there seems to be no room for nuance on Lemmy. These children are insufferable.

      • dogslayeggs@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 month ago

        I lost all of my data on a tablet that had Bitlocker installed without my knowledge. Not one time was I ever told that my drive was encrypted or that there was even something called Bitlocker or that I should write down some password or code. Bitlocker activated because of an OS update, and I had no way to unlock it so I had to wipe the drive. I don’t have an MS account, because I have no need to give MS all of my data, so I couldn’t unlock it that way either. And no, I’m not a 20 year old; I’m someone who has used computers since before the internet and have no interest in setting up a corporate account for every watch, shoe, phone, video game, car, etc. I have no interest in giving MS all of my pictures, documents, emails, and browsing history.

        • IHawkMike@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          1 month ago

          Bitlocker activated because of an OS update

          This did not happen. You did something to enable it.

          I don’t have an MS account, because I have no need to give MS all of my data

          If you had one, all of your data would have been safe in OneDrive and easily recoverable. But I’m sure the irony is completely lost on all the anti-MS people here. Nah, it must be Microsoft’s fault you didn’t have backups when you broke your tablet.

          • dogslayeggs@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            1 month ago

            Bitlocker activates when you enter an incorrect OS password too many times. I had my tablet set to unlock without a password or pass code, so I never used whatever pass code I set up a year and a half earlier. After one of the OS updates it forced me to log in with a pass code. I tried some pass codes I thought I might have used, thinking that worst case I would have to do a time delay before trying again… because again, MS never told me Bitlocker was installed and never told me it had a password and never told me I should write down whatever password Bitlocker set for itself and never told me that Bitlocker would lock my entire harddrive if I entered an incorrect password too many times.

            But go ahead and keep telling me it’s my fault MS added something so intrusive without telling me.

  • MystikIncarnate@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    2
    ·
    1 month ago

    This has been happening for a lot longer than just Windows 11.

    Several people I’ve spoken to, who have purchased OEM computers from the likes of Dell, HP, Lenovo and others, did not know that bitlocker FDE was enabled, and they were not aware that they needed to back up their recovery key.

    On at least one occasion, this caused someone to lose the contents of their laptop when Windows failed to finish booting into the OS. The drive was fine as far as I could tell, but the content on the drive would not complete the boot up sequence and would bsod/boot loop the system, so data retrieval was not possible without the recovery key, which they did not have. That was a Windows 10 Dell system from 2020 or so.

    My opinion is that FDE is a good thing.

    My advice is if you have FDE enabled, backup your recovery keys. It’s easy, but it won’t directly save to a file on the filesystem that’s locked by the key to which the recovery key applies. The easiest workaround is to “print” it, then use the built in Microsoft print to PDF, then dump it wherever you want. Afterwards, put it somewhere safe. Doesn’t matter where, but anywhere that isn’t the encrypted drive. Maybe Google drive, maybe a USB flash drive, maybe email it to yourself. I dunno, just somewhere you can retrieve if that system isn’t working.

    When you’re done doing that, go check the same on your parents computers, friends, brothers and sisters… If they’re someone you care about, and they have a windows computer, check. Get those recovery keys backed up somewhere.