Live data from Hacker News

Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

windowslatest.com

21–30 of 37 posts

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#21

Seems like this would be double encrypting OPAL self encrypting drives in the places that use those, potentially adding a further failure point.

Didn't Microsoft stop using those in BitLocker years ago because they were often borked? [1] It's a new failure point, but it's sensible.

[1] https://www.tomshardware.com/news/bitlocker-encrypts-self-en...

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#22
post #2

Definitely save those recovery keys, because BitLocker loves freaking out after BIOS updates or minor hardware changes. I think I had to enter mine after a GPU firmware update.

I think they're saved to your Microsoft account by default now. And, since Microsoft likes to pretend an account is required to even install Windows now, most people will likely have a linked account.

I don't use a windows account.

Of course that means I'm constantly bugged about using one.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#23
post #21

Seems like this would be double encrypting OPAL self encrypting drives in the places that use those, potentially adding a further failure point.

Didn't Microsoft stop using those in BitLocker years ago because they were often borked? [1] It's a new failure point, but it's sensible. [1] https://www.tomshardware.com/news/bitlocker-encrypts-self-en...

Thanks, that's good info. :)

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#26
post #17

This could lead to more data being lost than from ransomware. The best part is Windows doesn't even notify you about it. It will show you numerous useless notifications and now even ads, but it won't notify you that it has encrypted all your data. As that would be too "intrusive". I already know of one case where all data was lost. Somehow recovery key was not stored in Microsoft account.

Maybe not surprisingly, I've had a couple of tech-literate friends where they thought they were the only ones with a recovery key but it turned out (luckily, here) that MS had a copy after all.

If MS has a copy then the Russians who hacked MS might also have one. This is not actual security, but rather a security circus. Windows 11 comes bundled with spyware and now ransomware and people pay for it.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#27
The issue is lots of folks create Microsoft Accounts then promptly forget the password, then set up the auto-login they know and love. I bet there are millions of forgotten / zombie Microsoft Accounts.

A lot of people are about to have nasty surprises the next time they reinstall Windows because their kid downloaded some malware and realize their data is all gone.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#29

I mean between bitlocker and T2 I’d rather have T2. At least with bitlocker the key is in my Microsoft account so if something happened to my pc and the drive was still intact I can easily access the data again. On a T2 secured Mac, if something happened then I’m screwed.

I'm certain I've read that with T2 enabled mac still offer to print recovery keys.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#30

This could lead to more data being lost than from ransomware. The best part is Windows doesn't even notify you about it. It will show you numerous useless notifications and now even ads, but it won't notify you that it has encrypted all your data. As that would be too "intrusive". I already know of one case where all data was lost. Somehow recovery key was not stored in Microsoft account.

I tried to help someone who had a Windows update freeze for several _days_, and after force rebooting the PC it bluescreened and went to a BitLocker recovery screen, and he had no recovery keys in any of his accounts, and all data was lost.

I think it's absurd this kind of thing would be enabled by default without very explicit warnings about the possible reprucussions of not backing up your recovery keys

Post reply on HN