Live data from Hacker News

Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

windowslatest.com

31–37 of 37 posts

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#31
For everyone I know, their personal PCs don't store data that's valuable to criminals who might steal their PC, but do store personally important data like family photos, etc.

They all would much rather have the disk exposed to anyone with physical access and have their data recoverable in the much more likely case where the PC suffers physical damage or some other kind of software/hardware failiure.

Account passwords and session tokens can be reset, photos of loved ones can't can't be retaken

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#32

Am I understanding the article correctly that it's for new installs only? Also is "on by default" the right wording for something that needs a registry change to turn off? That just seems like it's forced with a workaround that they'll remove at some point. Last point, does that mean that windows is going to take a massive speed penalty going forward since they also default to their slow software encryption over hard…

Fresh installs and resets according to the article. Although I had to help a family member set up a new computer in January. I set it up with a local account and device encryption was "on" but checking with command prompt revealed that with local account it wasn't actually encrypted since a Microsoft Account hadn't been submitted, and there was no Bitlocker key.

There are so many problems with this that are stupid but that's par for the course when it comes to tech corps these days, they have all the leverage, so their fuckup is your problem, and what is this customer support you speak of.

Don't hold your breath on Microsoft actually improving any of its offerings.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#33

For everyone I know, their personal PCs don't store data that's valuable to criminals who might steal their PC, but do store personally important data like family photos, etc. They all would much rather have the disk exposed to anyone with physical access and have their data recoverable in the much more likely case where the PC suffers physical damage or some other kind of software/hardware failiure. Account password…

Very good point.

Account passwords and session tokens belong to secure local storage anyway. For personal PCs unencrypted personal data and encrypted secure local storage would make most sense as default configuration IMO.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#34
post #26
post #17

Earlier quoted context omitted.

Maybe not surprisingly, I've had a couple of tech-literate friends where they thought they were the only ones with a recovery key but it turned out (luckily, here) that MS had a copy after all.

If MS has a copy then the Russians who hacked MS might also have one. This is not actual security, but rather a security circus. Windows 11 comes bundled with spyware and now ransomware and people pay for it.

If you are worried about the Russians stealing your computer to decrypt the hard drive, you should be expected to have solid understanding of where all the potential decryption keys are kept.

I personally am happy for my Microsoft account to contain a copy. Yes it is an issue if I were to need security from a government, (either from subpoena or espionage). But it provides a very convenient backup of the recovery key, and security from random theft, which is my actual concern.

Also you can disable backing up the keys if you want to. People who need security from state level actors should be expected to take responsibility for proper configuration themselves.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#35

This could lead to more data being lost than from ransomware. The best part is Windows doesn't even notify you about it. It will show you numerous useless notifications and now even ads, but it won't notify you that it has encrypted all your data. As that would be too "intrusive". I already know of one case where all data was lost. Somehow recovery key was not stored in Microsoft account.

Windows had been data loss positive for a while. I've lost files on Desktop and under C:\ couple times from trying to disable OneDrive.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#36
post #26

Earlier quoted context omitted.

If MS has a copy then the Russians who hacked MS might also have one. This is not actual security, but rather a security circus. Windows 11 comes bundled with spyware and now ransomware and people pay for it.

If you are worried about the Russians stealing your computer to decrypt the hard drive, you should be expected to have solid understanding of where all the potential decryption keys are kept. I personally am happy for my Microsoft account to contain a copy. Yes it is an issue if I were to need security from a government, (either from subpoena or espionage). But it provides a very convenient backup of the recovery key…

I am personally not happy about that at all but my choice doesn't get any support. Not even registering Windows and turning off s-mode is possible without an account or with severe hacks that do involve deactivating secure boot anyway.

Microsoft is the security flaw here, they were even deemed a threat to national security in the US.

It is a complete circus and it lessens security compared to your average Windows 7 MBR installation while it was supported.

Microsoft forcing you to register to deactivate their presents pretty clearly line out their motivation here.

Re: Microsoft confirms Windows 11 24H2 turns on Device Encryption by default

#37
post #4

Earlier quoted context omitted.

I think it will lead to lots of lost data. Kind of like how your kid's old ipad loses its mind and your apple id password doesn't work and the data is lost. This kind of thing should be super-explicit when setting things up, and they should provide a way out.

No. That doesn’t help anyone other than computer nerds that have the background understanding to have usefully thought through the pros and cons. The reality is data is effectively “lost” all the time already when a laptop’s display fails, or some other problem that’s left the actual data completely in tact, because most people don’t know what to do about that and a sizeable portion of those people won’t bother to ‘t…

non-computer nerds cannot remember any account credentials and if they use any hardware key their chances of recovery are way worse than restoring any failed archaic system. This is to get people into the MS ecosystem. It isn't about growth or providing a service.
Post reply on HN