Earlier quoted context omitted.
> There's absolutely no reason that Windows installs and Linux distros should offer unencrypted storage as anything but a hidden option for experts. People unfortunately have been coddled by consumerism, or are coddled by job titles like "director" and "officer", and expect to be able to get passwords reset and access recovered by someone if they forget. The correct way to do disk encryption is to not store the passw…
> subordinate-to-revenue-generation IT departments If your company is large enough to have an IT Department , even if it's just one person with a sufficient amount of clue, they should know how to set up FDE with a recovery key manually stored in a secure location (even printed on a piece of paper locked in a safe of the CEO, or something). https://docs.microsoft.com/en-us/windows/security/informatio...
Then a month later HQ relented because too many branches couldn't figure it out. These were financial advisors offices, in the days when client data was stored locally. Brokers being too lazy to enter the passphrase trumped information security I guess.