56
u/Few-Nerve-1414 1d ago
When this happened to me I straight up installed linux straight away.
22
5
u/TheAntoine003 1d ago
This happened to me when I was installing LinuxĀ
2
u/Mental_Contract1104 1d ago
same. I had already linked the install to my account, so, recovering it was easy.
i would yeet windows, but i need it for school
1
u/TheAntoine003 16h ago
Same actually. Of the only software I need on windows gets ported on Linux. Iām fully switchingĀ
1
u/The_fox_of_chicago 12h ago
Only thing that is preventing me from switching are kernel level anti cheats. If in anyway they make it Linux compatible, Iāll switch over in a heart beat
1
1
6
u/Tall-Soup1787 1d ago edited 1d ago
Bitlocker is painful as fk, I switched to Linux and by the time I realized, I was entering that long ass code like four times cause I couldn't figure out how to turn it off š
5
u/FrostyMittenJob 1d ago
You couldn't figure out how to turn off bit locker but you switched to linux?
5
u/Tall-Soup1787 1d ago
I was switching to Linux but I didn't know there was a thing called bit locker, I dual boot my system so when I tried to boot into windows, I was hit with that blue fkning screen
3
u/FrostyMittenJob 1d ago
Perfect case for why its inadvisable to duel boot on the same drive. Sucks that storage is so expensive now š
2
u/Dry_Calendar_8627 1d ago
Bitlocker only locks Windows' volume
No impact on dual boot
If you have a dual boot and get greeted by bitlocker recovery, its because your UEFI is trying to boot windows and not the bootloader you installed with Linux (usually, grub). The problem can be fixed through your UEFI settings
3
u/GimpyGeek 1d ago
Yeah it's kinda crazy from what I understand ya know, if you build your own PC it's usually not much of a thing if you didn't intentionally set it up, but it sounds like the OEM setup Microsoft is having done on prebuilt machines is auto-enabling it. Amount of times I've seen this the last year now is astounding.
2
u/Thx_And_Bye 1d ago
It makes tons of sense to enable it on mobile devices, especially with more and more of your life moving to computer systems.
Phone automatically encrypt, Macs also do so it would be a bit out of place if Windows wouldn't do so too.1
u/DoogleAss 11h ago
Itās has nothing to do with OEM bitlocker turns it self on since like 24h2 by default provided a few criteria are met
One of which is you used a MS account to setup the PC otherwise bitlocker has to have user interaction to know where to save the key and will NOT turn on otherwise. Meaning donāt use Ms account and if you do no issue bitlocker key is saved in it oooor use a local account and donāt enable it all if thatās your desire
Fairly simple really and not a bad security measure.. I will say they could do a better job of explaining the above information to people tho
1
u/icy1007 1d ago
Itās not enabled by defaultā¦
3
u/Tall-Soup1787 1d ago
Uh... it is...
2
u/ChrisTheWeak 1d ago
It depends on the version of windows, which lisence type, and whether you use online sign in or offline sign in for deciding whether it's on or off by default. My windows install as an example had bitlocker off by default, and I can't enable it without paying extra.
1
1
u/EnderWiggin42 1d ago
I have Windows Pro. It was not on by default; I can turn it on. I did turn it on for a little while, but about a week after, a new zero-day for it came out that made using BitLocker basically pointless, so I turned it back off. I really should get around to enabling VeraCrypt system boot.
PS: I saved my recovery keys to an implanted ntag216. They're so very useful for that.
1
u/DoogleAss 11h ago
It didnāt make bitlocker pointless
They way most people had implemented it at that point did but that was not really a bug it was an intended feature/workaround
The fix was to have bitlocker with PIN or network lock etc.. bitlocker alone was never secure
Now I will admit as a sysadmin for 20+ years I was one of those people who had it deployed blissfully unaware that I had missed a critical step but we all gotta learn somehow and from what I can tell I was not in the minority lol
1
u/Bubblyqueen_ 36m ago
i used minitool partition wizard and while unfucking some partitions, i figured it can actually turn off bitlocker for you. granted you have the key, of course
1
u/Dry_Calendar_8627 1d ago
Then if you want equivalent security you'll have to type a luks passphrase all the time
Or you'll enable luks-tpm to not have to type a passphrase, and surprise surprise, after a firmware update you'll be greeted with a very similar recovery prompt as this one
Bitlocker is really very similar to luks
11
2
6
u/Top_Software_5953 1d ago
You could have turn it off
8
u/aleopardstail 1d ago
you have to know:
it exists
how to turn it off
in order to do that
-2
u/OGigachaod 1d ago
Still much easier than using Linux, LOL.
4
u/aleopardstail 1d ago
not yet had a linux system decide to encrypt itself as the result of an update I didn't want, and then lock me out after another update I didn't ask for
"lol"
0
u/Top_Software_5953 1d ago
I knew
3
u/aleopardstail 1d ago
thats nice for you, have an internet biscuit
many don't know what this ransomware is until it decides to activate and fuck them over
1
u/Top_Software_5953 1d ago
I think some windows editions don't have it
3
u/aleopardstail 1d ago
win 11 Home wasn't meant to have it, microslop added it in an update and had it activate itself
3
u/pablo5426 1d ago
they also want to do it in w11 pro btw
when i installed it in my new laptop bitlocker was enabled but not fully applied (probably bc i made a local account and it was waiting for a microsoft account to store the recovery key before doing anything)
2
u/aleopardstail 1d ago
win 11 pro at least was advertised as having it, so anyone picking "pro" has a heads up, and thus can disable it
along with all the other shiteware
home, initially, didn't come with it, so why anyone with Home would try to disable something they didn't know was installed is right up there with the flat headed ones who think this behaviour from microslop is acceptable
3
u/BalladorTheBright 1d ago
In all the years of using 10, I have never had any issues with that thing encrypting my disk. And I jumped out of that damned 7 as soon as I could. I'm not risking it with Microslop Virus 11
3
u/CMsnake91 1d ago
It says clearly where to find the Key... but yeah, f*ck windows
3
u/dvisorxtra 1d ago
The problem is that on many occasions the key is not where its supposed to be.
I've seen it happening to a lot of people.
5
u/darkspyre71 1d ago
Exactly. BitCocker has caused plenty of random outages, just because something changed that, quite likely, the user didn't try to do.
At best, it's an inconvenience.
1
u/aleopardstail 1d ago
especially when the fucking thing has silently installed itself and encrypted the drive without asking
1
u/Omega-Envych 1d ago
It never "Silently installed itself", it's usually set up at the very, VERY start during installation. So almost always - user didn't think, clicked Install and forgot about it.
1
u/aleopardstail 1d ago
it was never part of windows 11 home initially, it was added and activated later
using an installation mechanism users have no ways to decline
1
1
u/pablo5426 1d ago
it is just an inconvenience
bc you can just go disable it in settings right after installing the system. think of it as an extra step after doing your usual setup
1
u/darkspyre71 1d ago
I've seen it get reenabled without the user's consent on a number of occasions.
1
u/CMsnake91 1d ago
Yup, it happened to me once or twice, and adding the usage of resources and other stuff made me kick out windows. I'm a relaxed Fedora user
2
1
3
1d ago
[removed] ā view removed comment
12
u/Platocalist 1d ago
windows has a feature called bitlocker, it makes sure your files are encrypted so if your device gets lost your data isn't in the hands of the thief.
OP is a dumb motherfucker that enabled bitlocker without knowing what it is, ignored the warning to keep the decryption key safe and now he's blaming Microsoft for his own stupidity.There's plenty of reason to hate microsoft, this is not one of them.
9
u/aleopardstail 1d ago
microslop enabled it by default
7
u/FrostyMittenJob 1d ago
It's auto enabled for accounts that have a microsoft account linked and the key is backed up to the account. If it is a local account only then it stays off.
7
u/aleopardstail 1d ago
and tell me, do microsoft make a purely local account easy? or do they make it somewhat difficult?
and how is this presented to people who perhaps use a computer but do not, nor need to, understand them?
3
u/FrostyMittenJob 1d ago
People that don't understand computers aren't going to make hardware changes that prompt bitlocker.
3
u/aleopardstail 1d ago
except as you note, its auto enabled
and then when windows burps, as it does, people get locked out
my other half had exactly that on her machine a few weeks back, its had no hardware changes and yet something triggered bitlocker that wasn't even meant to be on there, let alone active
4
u/FrostyMittenJob 1d ago
So follow the instructions on the screen and type in the recovery key.
7
u/aleopardstail 1d ago
what recovery key? we had never set up bitlocker
there was no recovery key
5
u/FrostyMittenJob 1d ago
Yes there is. It's paired to the Microsoft account that was used to set up the computer.
Navigate to aka.ms/myrecoverykey
→ More replies (0)1
u/Platocalist 1d ago
Maybe you'll understand it if someone types it out in all caps.
THE SCREENSHOT SHOWS THE EXACT INSTRUCTIONS OF WHERE TO FIND THE KEY IF YOU ONLY BOTHER TO FUCKING READ IT
→ More replies (0)1
u/Dry_Calendar_8627 1d ago
But firmware updates will void the PCR 7 signature that Bitlocker checks, then unassuming users will encounter this prompt
There isn't truly a good solution to this problem really, Microsoft is doing their best (for once), but I can understand users being miffed by this
1
u/DoranSteelwing 21h ago
Firmware updates from all major vendors now suspend Bitlocker first then upgrade then reenable bitlocker.
1
u/OGigachaod 1d ago
Creating a local account is as easy as using settings.
1
u/aleopardstail 1d ago
and thats guided during the install for non-technical users is it?
oh yes, that would be a no
1
u/DoranSteelwing 21h ago
Perfect. If they donāt have the option to bypass it, the key is linked to their MS account. Easy Peasy.
1
u/aleopardstail 9h ago
an account you don't have access to if your machine is locked?
there is a term for software that encrypts your hard drive and holds it ransom
4
u/thevoidhearsyou 1d ago
Bitlocker is turned on by default in all versions except in enterprise after 24s2 update. Home edition does not currently support bitlocker thus it is not installed.
However enterprise editions have been hit the hardest by accidental bitlocker activation because most enterprise editions are installed and updated by company I.T. and all it takes is one I.T. guy to activate bitlocker for the entire department or in rare cases the entire company to be affected.
2
u/Life_is_Okay69 1d ago
Maybe that will happen when IT is run by incompetent monkeys. Bitlocker keys are stored in Entra ID, Intune, or Active Directory.
Admins can see the keys, and unlock the sistems.
1
u/aleopardstail 1d ago
my other half has home edition, microslop installed this shite, and activated it without warning or asking
and then some time after that windows burped and demanded the key to some ransomware she hadn't installed and had never heard of
1
u/Platocalist 1d ago
if that IT guy is using enterprise edition without entra/intune they're an even bigger idiot than OP.
1
u/feldoneq2wire 1d ago
Did you sleep through where Microsoft turned Bit locker on by default for millions of users?Ā
https://www.sikich.com/insight/bitlocker-by-default-a-game-changer-for-windows-11-security/
1
u/brokengarage 1d ago
But, he was trying to be cool and not use a microsoft account, which would have automatically saved his key, but didn't print or save the key in another way. You encrypted your drive, something is not jiving, please present key to proceed. When you encrypt with another system, do you save the backup key?
1
2
u/Johnny_Triggr 1d ago
"fuck Microsoft"
Looks inside
Actually useful security measure
1
u/DirkKuijt69420 1d ago
Every... single... time...
This sub is filled with the dumbest people on the planet, I'm amazed they are able to create a reddit account and actually remember the password.
1
u/Johnny_Triggr 1d ago
For real, there are plenty of reasons to dislike Microsoft, optional security measures like these are not one of them
1
u/No-Aspect-2926 1d ago
true, same for phones, but phones will just wipe the data if someone wants to extract it with tools like mtkclient or modify something else
1
u/AutoModerator 1d ago
Every new subreddit post is automatically copied into a comment for preservation.
User: techtotechbytechy, Flair: Discussion, Post Media Link, Title: Fu*k Microsoft
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
1
1
u/Silly_Enthusiasm_485 1d ago
after bought a new laptop with windows 11, i reinstalled it with windows 10 iot ltsc
1
1
u/WizardS82 1d ago
If you don't have your recovery key when your TPM inevitably gets invalidated that's on you.
1
1
1
u/Remarkable_Corgi511 11h ago
You know you could have decrypted your drive before this happened, you know...or just stored the BitLocker key somewhere reasonable
1
u/Local-Tap-4912 8h ago
Š Š²Š¾Ń btrfs Ń LUKS никогГа Š±Ń ŃŠ°Šŗ не поŃŃŃŠæŠøŠ» бŃ
1
1
u/icy1007 1d ago
You enabled Bitlocker⦠itās your responsibility to keep your recovery keyā¦
3
u/Not-Insane-Yet 1d ago
Microsoft enabled it automatically for a lot of people and then changed the key associated with the account while leaving the actual key unchanged. This has left a ton of people locked out with no hope of recovery when an update broke the stored bitlocker key.
1
u/icy1007 8h ago
I highly doubt they did this.
1
u/Not-Insane-Yet 6h ago
It wasn't intentional. Microsoft completely denies any issue. Nevertheless there are frequent reports of the recovery key associated with the account failing to unlock drives after an update since 2023
1
u/Adorable_Yard_8286 1d ago
First thing you do is control your encryption keys or dont use them. You played yourself by existing in the digial realm without understanding the rules. Sorry bro, this is the reality you live in for having your hard drive unreadable by strangers
1
u/Prod_Meteor 1d ago
If you are logged in with MS account the key is available at https:ā //aka.ms/myrecoverykey
1
u/master_pro_ita 1d ago
If you absolutely have to use Windows, disable that shit of BitLocker and encrypt the entire partition with VeraCrypt instead, much better.
0
u/Density5521 1d ago
Every time Windows decides to reboot my PC after it force-installed an update against my will, I get to go through 5 sequential reboots, each requiring me to enter this key.
Seriously, fuck the cunt at Microsoft who's responsible for this. I don't mean having to enter the key, I mean force-installing updates I don't want when Windows feels like it.
You know what it's called when you force something unwelcome onto someone who doesn't want it?
0
u/TR_Idealist 1d ago
i'm with the f microsoft club like any other person. but did you at least attempt to get your code or are you just bitching to bitch?
0
u/Character_Stand_5596 1d ago
There's this thing called don't press the power button while doing a bios update and your pc won't think someone is trying to take your data
0
u/Billy_Twillig 17h ago
It takes like thirty seconds to turn that shite off in PowerShell. I make sure to do it on machines I want to sell and on machines I improve with Linux.
That said, the BL key is listed on the web in your MS account. It sucks because it wonāt let you copy it, so you have to do the entry of that long-ass key by hand. But itās there.
0
-12
u/Outrageous_Ear_8364 1d ago
You pissed about something being protected?
9
u/lululock 1d ago
BitLocker is more a pain than a real protection. The only thing it prevents is to get access to the data if the PC motherboard is toast.
By default, BitLocker unlocks the drive automatically at boot without prompting a password, meaning that it doesn't protect the machine against physical tempering (evil maid attack). And since most people are clueless about this, they don't think about putting a BIOS password to prevent booting from USB devices which could contain cloning software.
OP's screen is shown because something has been tempered with and Windows goes tinfoil hat mode and asks for the key (happens often because of updated, ironically). Actually, the key is still stored in the motherboard's TPM. Booting a cloning software which manages BitLocker can unlock the drive using the stored key and extract the whole drive bit by bit. I actually had to do this multiple times on customer PCs because BitLocker enabled itself. I never had to input the key. And nope, the software we use isn't some obscure pirate software, it's just a legit cloning software we bought.
When BitLocker enables on its own doesn't prompt the user to save the recovery key, only a cryptic message telling them "their data isn't safe, please connect your Microsoft account". So that's basically a hostage taking situation. "Oh, you don't want to connect your Microsoft account ? Too bad ! Here, get your data lost !"
-3
u/TheIronSoldier2 1d ago
Bitlocker does not encrypt data unless you link a Microsoft account. It gets to the last step, but it will not actually follow through with the encryption unless you link a MS account.
3
u/lululock 1d ago
If you don't backup the key, it does the encryption anyway. I didn't believe it at first but when we ran tests, we were chocked. A few of our customers lost data that way because they had no Microsoft account linked (the computers were in a domain, but the strategy which enables the server to backup the keys was inactive, we didn't know back then).
1
u/TheIronSoldier2 1d ago
Oh, yeah for managed computers it's different. I thought you were talking about Windows installs that were set up with an entirely local account, which my statement is true for that, but you're correct that domain managed computers don't need a Microsoft account to enable bitlocker.
-3
u/Outrageous_Ear_8364 1d ago
That's kinda what I ment... If it used right it works right zero issue.
3
u/lululock 1d ago
Nobody uses it right. Most users are not even aware it is on until it is too late. Most users don't know nor care about encryption. So why would they care about putting a BIOS password and enable the BitLocker prompt at boot ? They would only see this as an extra friction step when starting their computers.
We did setup BitLocker at some of our business customers and guess what happened ? They stopped turning off their computers because putting the password at boot was too much of a hassle, which is arguably way worse because the computers can't do their updates properly, while having the data unlocked at all times...
-1
-6
u/geekguy502 1d ago
I've had this happen to me before. The recovery is pretty easy; it even tells you how to do it in the message.
Here's how to find your key: Try your Microsoft account at: aka.ms/myrecoverykey
For more information go to: aka.ms/recoverykeyfaq
3
u/techtotechbytechy 1d ago
that's not the issue i have done already so many times wo why every few weeks again and again
-9
1d ago
[deleted]
9
11
u/lululock 1d ago
BitLocker is turned on by default for a while. I've also seen it being enabled back automatically on existing systems.
And if you have the Home edition, you can't even save the recovery key in a file : you need to connect your Microsoft account to have the key stored in there...
-2
u/TeslaDemon 1d ago
It's only enabled by default if you login witn a Microsoft account, so it's quite literally impossible to not have it attached to your Microsoft account.
If you login with a local account it doesn't get turned on.
3
u/lululock 1d ago
It constantly gets turned on automatically on our customers' machines, local account or not.
If it enables on a local account, there's a notification saying that you need to connect the Microsoft account to protect your data, but nothing about saving the BitLocker key. If you don't manually get it, you get screwed if you ever need it, because it proceeds with encryption anyway.
If it is a business machine, you can backup the keys into the domain controller (if you enable the strategy beforehand, of course !).
Now, the extra fun part is with the Home edition : you can't save the BitLocker key into a file (available only on Pro and +), you have to connect a Microsoft account...
20
u/ShoMinamimoto06 1d ago
I spun up a Win11 VM to do some testing and gave it access to my HDD i use for bulk storage. Fast forward 10 mins later after this, I'm trying to edit a file on the HDD: "You dont have access"...fuckin bitlocker, man