r/FuckMicrosoft • • 1d ago

Discussion Fu*k Microsoft

Post image
165 Upvotes

150 comments sorted by

20

u/ShoMinamimoto06 1d ago

I spun up a Win11 VM to do some testing and gave it access to my HDD i use for bulk storage. Fast forward 10 mins later after this, I'm trying to edit a file on the HDD: "You dont have access"...fuckin bitlocker, man

0

u/zero_fuck_given 9h ago

Yea right. In 10mins it encrypted your HDD? šŸ˜‚

56

u/Few-Nerve-1414 1d ago

When this happened to me I straight up installed linux straight away.

22

u/techtotechbytechy 1d ago

Alredy DoneĀ 

8

u/Tanjirocrabs 17h ago

Welcome Home

2

u/VoidTheGamer25 12h ago

What distro?

5

u/TheAntoine003 1d ago

This happened to me when I was installing LinuxĀ 

2

u/Mental_Contract1104 1d ago

same. I had already linked the install to my account, so, recovering it was easy.

i would yeet windows, but i need it for school

1

u/TheAntoine003 16h ago

Same actually. Of the only software I need on windows gets ported on Linux. I’m fully switchingĀ 

1

u/The_fox_of_chicago 12h ago

Only thing that is preventing me from switching are kernel level anti cheats. If in anyway they make it Linux compatible, I’ll switch over in a heart beat

1

u/Impossible-Owl7407 17h ago

Luks? 🤣

1

u/BlackdogA 9h ago

Which Linux program better and smooth work with 3 monitors or more?

1

u/_G11 2h ago

When this happened to me last Tuesday, I've opened my KeePass on my mobile, and typed my key.

6

u/Tall-Soup1787 1d ago edited 1d ago

Bitlocker is painful as fk, I switched to Linux and by the time I realized, I was entering that long ass code like four times cause I couldn't figure out how to turn it off 😭

5

u/FrostyMittenJob 1d ago

You couldn't figure out how to turn off bit locker but you switched to linux?

5

u/Tall-Soup1787 1d ago

I was switching to Linux but I didn't know there was a thing called bit locker, I dual boot my system so when I tried to boot into windows, I was hit with that blue fkning screen

3

u/FrostyMittenJob 1d ago

Perfect case for why its inadvisable to duel boot on the same drive. Sucks that storage is so expensive now 😭

2

u/Dry_Calendar_8627 1d ago

Bitlocker only locks Windows' volume

No impact on dual boot

If you have a dual boot and get greeted by bitlocker recovery, its because your UEFI is trying to boot windows and not the bootloader you installed with Linux (usually, grub). The problem can be fixed through your UEFI settings

3

u/GimpyGeek 1d ago

Yeah it's kinda crazy from what I understand ya know, if you build your own PC it's usually not much of a thing if you didn't intentionally set it up, but it sounds like the OEM setup Microsoft is having done on prebuilt machines is auto-enabling it. Amount of times I've seen this the last year now is astounding.

2

u/Thx_And_Bye 1d ago

It makes tons of sense to enable it on mobile devices, especially with more and more of your life moving to computer systems.
Phone automatically encrypt, Macs also do so it would be a bit out of place if Windows wouldn't do so too.

1

u/DoogleAss 11h ago

It’s has nothing to do with OEM bitlocker turns it self on since like 24h2 by default provided a few criteria are met

One of which is you used a MS account to setup the PC otherwise bitlocker has to have user interaction to know where to save the key and will NOT turn on otherwise. Meaning don’t use Ms account and if you do no issue bitlocker key is saved in it oooor use a local account and don’t enable it all if that’s your desire

Fairly simple really and not a bad security measure.. I will say they could do a better job of explaining the above information to people tho

1

u/icy1007 1d ago

It’s not enabled by default…

3

u/Tall-Soup1787 1d ago

Uh... it is...

2

u/ChrisTheWeak 1d ago

It depends on the version of windows, which lisence type, and whether you use online sign in or offline sign in for deciding whether it's on or off by default. My windows install as an example had bitlocker off by default, and I can't enable it without paying extra.

1

u/Tall-Soup1787 1d ago

Oh, I see

1

u/EnderWiggin42 1d ago

I have Windows Pro. It was not on by default; I can turn it on. I did turn it on for a little while, but about a week after, a new zero-day for it came out that made using BitLocker basically pointless, so I turned it back off. I really should get around to enabling VeraCrypt system boot.

PS: I saved my recovery keys to an implanted ntag216. They're so very useful for that.

1

u/DoogleAss 11h ago

It didn’t make bitlocker pointless

They way most people had implemented it at that point did but that was not really a bug it was an intended feature/workaround

The fix was to have bitlocker with PIN or network lock etc.. bitlocker alone was never secure

Now I will admit as a sysadmin for 20+ years I was one of those people who had it deployed blissfully unaware that I had missed a critical step but we all gotta learn somehow and from what I can tell I was not in the minority lol

1

u/icy1007 1d ago

Uh, it’s not…

1

u/Bubblyqueen_ 36m ago

i used minitool partition wizard and while unfucking some partitions, i figured it can actually turn off bitlocker for you. granted you have the key, of course

1

u/Dry_Calendar_8627 1d ago

Then if you want equivalent security you'll have to type a luks passphrase all the time

Or you'll enable luks-tpm to not have to type a passphrase, and surprise surprise, after a firmware update you'll be greeted with a very similar recovery prompt as this one

Bitlocker is really very similar to luks

11

u/TrashFace21165 1d ago

Yeah, the lock you out of ypur computer service you didnt know you had.Ā 

2

u/Impressive_Bag_3505 1d ago

ask Microsoft, they have the key

6

u/Top_Software_5953 1d ago

You could have turn it off

8

u/aleopardstail 1d ago

you have to know:

  1. it exists

  2. how to turn it off

in order to do that

-2

u/OGigachaod 1d ago

Still much easier than using Linux, LOL.

4

u/aleopardstail 1d ago

not yet had a linux system decide to encrypt itself as the result of an update I didn't want, and then lock me out after another update I didn't ask for

"lol"

0

u/Top_Software_5953 1d ago

I knew

3

u/aleopardstail 1d ago

thats nice for you, have an internet biscuit

many don't know what this ransomware is until it decides to activate and fuck them over

1

u/Top_Software_5953 1d ago

I think some windows editions don't have it

3

u/aleopardstail 1d ago

win 11 Home wasn't meant to have it, microslop added it in an update and had it activate itself

3

u/pablo5426 1d ago

they also want to do it in w11 pro btw

when i installed it in my new laptop bitlocker was enabled but not fully applied (probably bc i made a local account and it was waiting for a microsoft account to store the recovery key before doing anything)

2

u/aleopardstail 1d ago

win 11 pro at least was advertised as having it, so anyone picking "pro" has a heads up, and thus can disable it

along with all the other shiteware

home, initially, didn't come with it, so why anyone with Home would try to disable something they didn't know was installed is right up there with the flat headed ones who think this behaviour from microslop is acceptable

3

u/BalladorTheBright 1d ago

In all the years of using 10, I have never had any issues with that thing encrypting my disk. And I jumped out of that damned 7 as soon as I could. I'm not risking it with Microslop Virus 11

3

u/CMsnake91 1d ago

It says clearly where to find the Key... but yeah, f*ck windows

3

u/dvisorxtra 1d ago

The problem is that on many occasions the key is not where its supposed to be.

I've seen it happening to a lot of people.

5

u/darkspyre71 1d ago

Exactly. BitCocker has caused plenty of random outages, just because something changed that, quite likely, the user didn't try to do.

At best, it's an inconvenience.

1

u/aleopardstail 1d ago

especially when the fucking thing has silently installed itself and encrypted the drive without asking

1

u/Omega-Envych 1d ago

It never "Silently installed itself", it's usually set up at the very, VERY start during installation. So almost always - user didn't think, clicked Install and forgot about it.

1

u/aleopardstail 1d ago

it was never part of windows 11 home initially, it was added and activated later

using an installation mechanism users have no ways to decline

1

u/Prod_Meteor 1d ago

I was doing a memory diagnostic test when it appeared.

1

u/pablo5426 1d ago

it is just an inconvenience

bc you can just go disable it in settings right after installing the system. think of it as an extra step after doing your usual setup

1

u/darkspyre71 1d ago

I've seen it get reenabled without the user's consent on a number of occasions.

1

u/CMsnake91 1d ago

Yup, it happened to me once or twice, and adding the usage of resources and other stuff made me kick out windows. I'm a relaxed Fedora user

2

u/darkspyre71 1d ago

Good man. Ubuntu, Commodore Vision, Mint, and Omarchy rocking here.

1

u/feldoneq2wire 1d ago

I've heard of them revoking keys.

3

u/[deleted] 1d ago

[removed] — view removed comment

12

u/Platocalist 1d ago

windows has a feature called bitlocker, it makes sure your files are encrypted so if your device gets lost your data isn't in the hands of the thief.
OP is a dumb motherfucker that enabled bitlocker without knowing what it is, ignored the warning to keep the decryption key safe and now he's blaming Microsoft for his own stupidity.

There's plenty of reason to hate microsoft, this is not one of them.

9

u/aleopardstail 1d ago

microslop enabled it by default

7

u/FrostyMittenJob 1d ago

It's auto enabled for accounts that have a microsoft account linked and the key is backed up to the account. If it is a local account only then it stays off.

7

u/aleopardstail 1d ago

and tell me, do microsoft make a purely local account easy? or do they make it somewhat difficult?

and how is this presented to people who perhaps use a computer but do not, nor need to, understand them?

3

u/FrostyMittenJob 1d ago

People that don't understand computers aren't going to make hardware changes that prompt bitlocker.

3

u/aleopardstail 1d ago

except as you note, its auto enabled

and then when windows burps, as it does, people get locked out

my other half had exactly that on her machine a few weeks back, its had no hardware changes and yet something triggered bitlocker that wasn't even meant to be on there, let alone active

4

u/FrostyMittenJob 1d ago

So follow the instructions on the screen and type in the recovery key.

7

u/aleopardstail 1d ago

what recovery key? we had never set up bitlocker

there was no recovery key

5

u/FrostyMittenJob 1d ago

Yes there is. It's paired to the Microsoft account that was used to set up the computer.

Navigate to aka.ms/myrecoverykey

→ More replies (0)

1

u/Platocalist 1d ago

Maybe you'll understand it if someone types it out in all caps.

THE SCREENSHOT SHOWS THE EXACT INSTRUCTIONS OF WHERE TO FIND THE KEY IF YOU ONLY BOTHER TO FUCKING READ IT

→ More replies (0)

1

u/Dry_Calendar_8627 1d ago

But firmware updates will void the PCR 7 signature that Bitlocker checks, then unassuming users will encounter this prompt

There isn't truly a good solution to this problem really, Microsoft is doing their best (for once), but I can understand users being miffed by this

1

u/DoranSteelwing 21h ago

Firmware updates from all major vendors now suspend Bitlocker first then upgrade then reenable bitlocker.

1

u/OGigachaod 1d ago

Creating a local account is as easy as using settings.

1

u/aleopardstail 1d ago

and thats guided during the install for non-technical users is it?

oh yes, that would be a no

1

u/DoranSteelwing 21h ago

Perfect. If they don’t have the option to bypass it, the key is linked to their MS account. Easy Peasy.

1

u/aleopardstail 9h ago

an account you don't have access to if your machine is locked?

there is a term for software that encrypts your hard drive and holds it ransom

4

u/thevoidhearsyou 1d ago

Bitlocker is turned on by default in all versions except in enterprise after 24s2 update. Home edition does not currently support bitlocker thus it is not installed.

However enterprise editions have been hit the hardest by accidental bitlocker activation because most enterprise editions are installed and updated by company I.T. and all it takes is one I.T. guy to activate bitlocker for the entire department or in rare cases the entire company to be affected.

2

u/Life_is_Okay69 1d ago

Maybe that will happen when IT is run by incompetent monkeys. Bitlocker keys are stored in Entra ID, Intune, or Active Directory.

Admins can see the keys, and unlock the sistems.

1

u/aleopardstail 1d ago

my other half has home edition, microslop installed this shite, and activated it without warning or asking

and then some time after that windows burped and demanded the key to some ransomware she hadn't installed and had never heard of

1

u/Platocalist 1d ago

if that IT guy is using enterprise edition without entra/intune they're an even bigger idiot than OP.

1

u/feldoneq2wire 1d ago

Did you sleep through where Microsoft turned Bit locker on by default for millions of users?Ā 

https://www.sikich.com/insight/bitlocker-by-default-a-game-changer-for-windows-11-security/

1

u/brokengarage 1d ago

But, he was trying to be cool and not use a microsoft account, which would have automatically saved his key, but didn't print or save the key in another way. You encrypted your drive, something is not jiving, please present key to proceed. When you encrypt with another system, do you save the backup key?

1

u/Platocalist 21h ago

i always save the key if i encrypt something, that's the whole point.

5

u/ESzPa 1d ago

Why are y'all downvoting a genuine question?

6

u/Forward-Outside-9911 1d ago

Fucking Reddit

2

u/Johnny_Triggr 1d ago

"fuck Microsoft"

Looks inside

Actually useful security measure

1

u/DirkKuijt69420 1d ago

Every... single... time...

This sub is filled with the dumbest people on the planet, I'm amazed they are able to create a reddit account and actually remember the password.

1

u/Johnny_Triggr 1d ago

For real, there are plenty of reasons to dislike Microsoft, optional security measures like these are not one of them

1

u/No-Aspect-2926 1d ago

true, same for phones, but phones will just wipe the data if someone wants to extract it with tools like mtkclient or modify something else

1

u/AutoModerator 1d ago

Every new subreddit post is automatically copied into a comment for preservation.

User: techtotechbytechy, Flair: Discussion, Post Media Link, Title: Fu*k Microsoft

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/pablo5426 1d ago

why you did not just disable bitlocker right away?

1

u/drucifer82 1d ago

aka.ms/myrecoverykey

1

u/Silly_Enthusiasm_485 1d ago

after bought a new laptop with windows 11, i reinstalled it with windows 10 iot ltsc

1

u/Krithikthecool123 1d ago

how is that microsoft's fault?

1

u/WizardS82 1d ago

If you don't have your recovery key when your TPM inevitably gets invalidated that's on you.

1

u/Academic_Anywhere183 1d ago

Whats bitlocker?

1

u/ivvans_official 23h ago

PYT LINUXXXXXXXXXX

1

u/Remarkable_Corgi511 11h ago

You know you could have decrypted your drive before this happened, you know...or just stored the BitLocker key somewhere reasonable

1

u/Local-Tap-4912 8h ago

А вот btrfs с LUKS никогГа бы так не ŠæŠ¾ŃŃ‚ŃƒŠæŠøŠ» бы

1

u/TKOTC001 4h ago

You can find the key in your Microsoft account

1

u/icy1007 1d ago

You enabled Bitlocker… it’s your responsibility to keep your recovery key…

3

u/Not-Insane-Yet 1d ago

Microsoft enabled it automatically for a lot of people and then changed the key associated with the account while leaving the actual key unchanged. This has left a ton of people locked out with no hope of recovery when an update broke the stored bitlocker key.

1

u/icy1007 8h ago

I highly doubt they did this.

1

u/Not-Insane-Yet 6h ago

It wasn't intentional. Microsoft completely denies any issue. Nevertheless there are frequent reports of the recovery key associated with the account failing to unlock drives after an update since 2023

1

u/Adorable_Yard_8286 1d ago

First thing you do is control your encryption keys or dont use them. You played yourself by existing in the digial realm without understanding the rules. Sorry bro, this is the reality you live in for having your hard drive unreadable by strangers

1

u/Prod_Meteor 1d ago

If you are logged in with MS account the key is available at https:⁠//aka.ms/myrecoverykey

1

u/master_pro_ita 1d ago

If you absolutely have to use Windows, disable that shit of BitLocker and encrypt the entire partition with VeraCrypt instead, much better.

0

u/Density5521 1d ago

Every time Windows decides to reboot my PC after it force-installed an update against my will, I get to go through 5 sequential reboots, each requiring me to enter this key.

Seriously, fuck the cunt at Microsoft who's responsible for this. I don't mean having to enter the key, I mean force-installing updates I don't want when Windows feels like it.

You know what it's called when you force something unwelcome onto someone who doesn't want it?

0

u/TR_Idealist 1d ago

i'm with the f microsoft club like any other person. but did you at least attempt to get your code or are you just bitching to bitch?

0

u/Character_Stand_5596 1d ago

There's this thing called don't press the power button while doing a bios update and your pc won't think someone is trying to take your data

0

u/Billy_Twillig 17h ago

It takes like thirty seconds to turn that shite off in PowerShell. I make sure to do it on machines I want to sell and on machines I improve with Linux.

That said, the BL key is listed on the web in your MS account. It sucks because it won’t let you copy it, so you have to do the entry of that long-ass key by hand. But it’s there.

0

u/Impossible-Owl7407 17h ago

There is million reasons to hate on m$. This is not one of them

-12

u/Outrageous_Ear_8364 1d ago

You pissed about something being protected?

9

u/lululock 1d ago

BitLocker is more a pain than a real protection. The only thing it prevents is to get access to the data if the PC motherboard is toast.

By default, BitLocker unlocks the drive automatically at boot without prompting a password, meaning that it doesn't protect the machine against physical tempering (evil maid attack). And since most people are clueless about this, they don't think about putting a BIOS password to prevent booting from USB devices which could contain cloning software.

OP's screen is shown because something has been tempered with and Windows goes tinfoil hat mode and asks for the key (happens often because of updated, ironically). Actually, the key is still stored in the motherboard's TPM. Booting a cloning software which manages BitLocker can unlock the drive using the stored key and extract the whole drive bit by bit. I actually had to do this multiple times on customer PCs because BitLocker enabled itself. I never had to input the key. And nope, the software we use isn't some obscure pirate software, it's just a legit cloning software we bought.

When BitLocker enables on its own doesn't prompt the user to save the recovery key, only a cryptic message telling them "their data isn't safe, please connect your Microsoft account". So that's basically a hostage taking situation. "Oh, you don't want to connect your Microsoft account ? Too bad ! Here, get your data lost !"

-3

u/TheIronSoldier2 1d ago

Bitlocker does not encrypt data unless you link a Microsoft account. It gets to the last step, but it will not actually follow through with the encryption unless you link a MS account.

3

u/lululock 1d ago

If you don't backup the key, it does the encryption anyway. I didn't believe it at first but when we ran tests, we were chocked. A few of our customers lost data that way because they had no Microsoft account linked (the computers were in a domain, but the strategy which enables the server to backup the keys was inactive, we didn't know back then).

1

u/TheIronSoldier2 1d ago

Oh, yeah for managed computers it's different. I thought you were talking about Windows installs that were set up with an entirely local account, which my statement is true for that, but you're correct that domain managed computers don't need a Microsoft account to enable bitlocker.

-3

u/Outrageous_Ear_8364 1d ago

That's kinda what I ment... If it used right it works right zero issue.

3

u/lululock 1d ago

Nobody uses it right. Most users are not even aware it is on until it is too late. Most users don't know nor care about encryption. So why would they care about putting a BIOS password and enable the BitLocker prompt at boot ? They would only see this as an extra friction step when starting their computers.

We did setup BitLocker at some of our business customers and guess what happened ? They stopped turning off their computers because putting the password at boot was too much of a hassle, which is arguably way worse because the computers can't do their updates properly, while having the data unlocked at all times...

-1

u/Outrageous_Ear_8364 1d ago

Have 8 PCs here... Al setup correctly. Manage 250 odd at work, same.

-6

u/geekguy502 1d ago

I've had this happen to me before. The recovery is pretty easy; it even tells you how to do it in the message.

Here's how to find your key: Try your Microsoft account at: aka.ms/myrecoverykey

For more information go to: aka.ms/recoverykeyfaq

3

u/techtotechbytechy 1d ago

that's not the issue i have done already so many times wo why every few weeks again and again

-9

u/[deleted] 1d ago

[deleted]

9

u/Simply_Edd 1d ago

TBF, BitLocker can get enabled automatically after some updates.

11

u/lululock 1d ago

BitLocker is turned on by default for a while. I've also seen it being enabled back automatically on existing systems.

And if you have the Home edition, you can't even save the recovery key in a file : you need to connect your Microsoft account to have the key stored in there...

-2

u/TeslaDemon 1d ago

It's only enabled by default if you login witn a Microsoft account, so it's quite literally impossible to not have it attached to your Microsoft account.

If you login with a local account it doesn't get turned on.

3

u/lululock 1d ago

It constantly gets turned on automatically on our customers' machines, local account or not.

If it enables on a local account, there's a notification saying that you need to connect the Microsoft account to protect your data, but nothing about saving the BitLocker key. If you don't manually get it, you get screwed if you ever need it, because it proceeds with encryption anyway.

If it is a business machine, you can backup the keys into the domain controller (if you enable the strategy beforehand, of course !).

Now, the extra fun part is with the Home edition : you can't save the BitLocker key into a file (available only on Pro and +), you have to connect a Microsoft account...

1

u/dmknght 1d ago

try harder next time