Windows to enable Disk Encryption by Default. Say Goodbye to Files for Forgotten Passwords

19 Comments

  1. DoctorKomodo

    Wouldn’t be so bad if Bitlocker wasn’t so wonky. I’ve wanted at least an encrypted main partition for years to protect user data but several trials of Bitlocker have always ended with me having to either disable Bitlocker or outright reinstall Windows because Bitlocker crapped out in one way or another. 

    The usual problem being an outright refusal to boot if you so much as look at the boot loader or attempt something crazy like dual booting. 

    So very much think I’ll be disabling this.

  2. banacct421

    Why do you think we invented sticky notes so we could put our passwords on our monitors

  3. mhb-210-

    Windows 11 haters: “The sky is falling!”

    Meanwhile…

    > The caveat with Windows 11 Home is that BitLocker encryption is only applied through the device manufacturer, and only if the manufacturer enables the encryption flag in the UEFI. So, DIY PCs running Windows 11 Home probably won’t be affected.

    If you built your own PC and are running Windows 11 Home, you’re unlikely to have a problem.

  4. I’m always surprised at the disparity with some technologies between Windows and Apple, like this one.

    FileVault has been a standard for managed Macs for many years, and the Apple Silicon machines are all hardware encrypted by default from first user creation.

    Huh.

  5. Exodia101

    This is a good thing. Without encryption, anyone can bypass your password by popping in a live USB or taking out your drive and access all of your files, saved passwords, etc. Every Mac and smartphone has been encrypted for years.

  6. PunyParker826

    >This behavior applies to clean installs of Windows 11 24H2 and system upgrades to version 24H2. Systems that upgrade to Windows 11 24H2 automatically have the Device Encryption flag turned on, but it only takes effect (for some reason) once Windows 11 24H2 is reinstalled on the machine.

    This isn’t clicking for me. If I upgrade to 24H2, will it or will it not encrypt my drive? Or does it  only encrypt on a clean install?

  7. flareflo

    Disc encryption is good and necessary, too bad windows doesn’t do itself good with Bitlocker.

  8. neuromancer_21

    I’m a Geek Squad repair tech, I see a lot of computers come in for data recovery when they won’t boot or the client forgot a password. If bitlocker is enabled (which it is by default already in most Windows 11 machines) then they’re actually just shit out of luck and their data is gone. I’ve seen people lose their only backup of family photos or tax documents because their drive was encrypted and they didn’t know because it was enabled by Microsoft without their knowledge.

    This is a bad change.

  9. preventDefault

    I’d say this could be a good thing for laptops and mobile devices… but for desktop PC’s staying home I think this will do more harm than good.

    What problem is this trying to solve? Someone breaking into your home to steal your files?

    Meanwhile real problems like a forgotten password or borked system update will destroy family photos and all sorts of data, for no real upside. Lock your damn doors before you start throwing on FDE, lol.

  10. jferments

    You have two choices:

    (A) Make passwords a hollow psychological comfort, which any attacker with physical access can easily bypass. Everyone has an insecure system by default, but irresponsible people who forget their passwords can easily recover their data because they have zero security.

    (B) Make passwords actually work, so you literally can’t access the data without the password, no matter what. This means that people who remember their passwords have secure systems. People that forget their passwords are fucked, and hopefully learn their lesson.

    I’d much rather have option B. Rather than building systems around enabling irresponsible people to forget their passwords, have secure data be the default, and teach people not to forget passwords (90% of which is just teaching people to use long, easy to remember passphrases rather than complicated random sequences of symbols)

  11. SameRandomUsername

    Yeah bitlocker is shit, yet as with everything with Windows you can turn that shit off.

  12. BigBrownBear28

    I bought an ASUS ROG Ally and noticed it was on by default. It was a pain to get the code and enter it in; it’s going to cause so many people to lose their files. I can only imagine the less tech savy people.

  13. The_Pacific_gamer

    All I’m gonna say is back your stuff up.

  14. USSHammond

    And that’s gonna be the first thing I disable when 24h1 hits my systems. MY systems, MY rules. Not Microsofts’

  15. Good change, too many people assume a windows password is enough to keep their data safe, in reality after giving away or disposing their old computer they are potentially handing over everything once the easy bypass is performed. Those saying that people will loose their data in the event of a software fault, well that is the case with hardware faults too. There should always be a backup.

  16. foamingdogfever

    Fun fact: Each block of digits in a Bitlocker recovery key is divisible by 11. It’s how Windows checks to see if you have fucked up entering the key.

Write A Comment