4 ms·
From reading the article, it seems the author assumed that disk encryption is on by default, which is not the case in Windows. You have to, for example, open th
by vdaea 3y ago
From reading the article, it seems the author assumed that disk encryption is on by default, which is not the case in Windows. You have to, for example, open the "Manage BitLocker" control panel applet to set up disk encryption.
- g1a55er 3y agoIt is on by default in Windows 11 Home if you go through the normal setup experience completely according to the Microsoft documentation. As part of the setup, you sign in to a Microsoft account, which then creates a TPM protector. "Unlike a standard BitLocker implementation, device encryption is enabled automatically so that the device is always protected... When the administrator uses a Microsoft account to sign in, the clear key is removed, a recovery key is uploaded to the online Microsoft account, and a TPM protector is created. Should a device require the recovery key, the user is guided to use an alternate device and navigate to a recovery key access URL to retrieve the recovery key by using their Microsoft account credentials." From https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/ https://learn.microsoft.com/en-us/windows/security/operating... This is also how it's reported in the press: "In fact, the mechanisms to do exactly that are already in place. Windows 11 Home and Windows 11 Pro both support automatic device encryption, with the Home version a more streamlined experience. You just have to sign into the machine with a Microsoft account, which nearly all people do during setup." From https://www.pcworld.com/article/624593/is-your-windows-11-pc-encrypted-the-answer-is-surprisingly-complex.html https://www.pcworld.com/article/624593/is-your-windows-11-pc... My main point is just that if you skip this, like a lot of privacy conscious people do, you might end up inadvertently not having encryption fully enabled.
- vdaea 3y agoYou left out the part where it says "If a device uses only local accounts, then it remains unprotected even though the data is encrypted" I think you are confusing "device encryption" with "disk encryption" (BitLocker)
- g1a55er 3y agoI quote that exact part of the documentation in the post. I also talk about the difference between "Device encryption" and "BitLocker Device Encryption" My argument isn't that this isn't documented. It's that it is a bit counterintuitive. My points are: 1) It would be best if Microsoft just asked if you wanted encryption if you create a local account. This is what Apple does in this situation. I imagine a large portion of the people who are creating local accounts on Windows 11 Home are the sort that want to manage their own keys. 2) If you are in that set of people, you should double check your setting if you never thought about it before, because it's easy to miss.
- hakfoo 3y agoI would think the other side of this is "if you try to boot another OS one day, surprise, you didn't know the disc was encrypted and can't access any of your files." That screams anti-competitive behaviour to me-- how many people would stop their "let's try Linux" experiment if you can't mount your existing drive to access previous data?
- gruez 3y ago>That screams anti-competitive behaviour to me ...or they're trying to increase security against physical attacks. The year of the Linux desktop has been a running joke for decades. Microsoft doesn't need disk encryption to keep Linux from gaining traction. Linux is already doing a pretty good job for them.
- hakfoo 3y agoWell, I could see plenty of other use cases (i. e. "My machine is kaput, can you tether the hard disc and grab my data") but this one has a legitimate business edge if they intercept it.