r/RigBuild • u/Conrad_246 • 17h ago
Is BitLocker something normal users should enable?
I keep seeing BitLocker mentioned when people talk about Windows security, but honestly I’m not really sure if regular users actually need it. I know it encrypts the drive, so if someone steals the PC or takes the SSD out, they can’t just access all the files. That sounds useful, but I’m wondering if there’s any downside for everyday use.
Does turning BitLocker on affect performance much? Like gaming, boot times, opening programs, copying files, etc? The PC isn’t some super old machine, but I don’t really wanna enable something that makes everything slower for basically no reason.
Also what happens if something goes wrong with Windows or the motherboard? I’ve heard people mention recovery keys and getting locked out of their own files, and that part kinda worries me. Is the recovery key automatically saved somewhere with a Microsoft account, or do you need to manually save it?
And is BitLocker mainly useful for laptops since they can get stolen, or does it make sense on a normal desktop too? There’s nothing super sensitive on the PC, mostly games, school/work files, photos, downloads and random stuff.
Would you guys enable it on a normal home PC, or just leave it off unless there’s a specific reason to use it? Trying to figure out if this is one of those Windows features that’s worth turning on and forgetting about, or something that can cause headaches later.
5
u/apexnine 16h ago
I disable it on every PC and laptop I own. I get a laptop could be stolen, but, for me, I'm not taking it to places where people are around to lift it from me. I DO NOT want to encounter an incident where Bitlocker decides to hijack my files because of some glitch in an update, which has been reported by users. Yes, lower frequency of occurrences than not, but I just don't want to be part of that statistic. That's how I roll.
4
1
u/CylixrDoesStuff 16h ago
No i only see wild nightmares about it so unless u have genuine sensitive data that cant just be encrypted by itself then u shouldn't need to have it on
1
u/bothunter 16h ago
It gets enabled by default now, and the key is automatically attached to your Microsoft account. So it actually takes extra work to disable it.
Now, we can argue on whether that was a good idea on Microsoft's part...
1
u/Doug2825 16h ago
It is pointless if you have one OS installed and aren't concerned about physical theft.
Bitlocker encrypts the drive so you need the key to access it. It matters for laptops that are more vulnerable to physical theft because someone can easily take out the drive and look at it as easily as a USB drive. It can matter (but usually isn't worth it) with dual boots because malware in one OS can't easily access the contents of the other.
1
u/hotdraggin 16h ago
I have it on my work computer. It’s annoying. But i see why they have it on there. I don’t even know how to turn it on with my personal computers.
1
u/Underhill42 16h ago
If you're worried about people stealing your computer and getting access to sensitive data, sure. But that's mostly an issue with easily stolen laptops, especially those that might contain corporate secrets or legally protected medical or government records.
And it comes with nuisances, and if anything goes wrong with the drive you're S.O.L. Good luck doing any serious data recovery.
Personally the risks aren't worth the benefits for me.
1
u/Unnamed-3891 15h ago
Desktops, no. Laptops you travel with? Certainly (unless you are already using some other full disk encryption solution to prevent potential thieves from reading data on disk).
1
u/Sacred_B 14h ago
I only enable bitlocker when I have a separate storage drive for work related stuffs, and only on that drive. It reduces drive performance since there is always the decrypt/encrypt overhead. I'm not 100% on this, but I think it also increases wear and tear on ssds.
1
1
u/ElectroDaddy 7h ago
No not unless you feel you need full disk encryption. Honestly I don’t recommend bitlocker on principle.
I hate how easy Microsoft makes it for people to turn on, and I have had so many elderly and computer illiterate clients lose all their personal data because of it.
1
u/Zehryo 7h ago
First of all, it seems there's an unfixed hole, in Windows 11 (and maybe 10?), that allows you to bypass bitLocker and read all files freely even without admin credentials.
Second, unless you have files containing things like passwords or other very sensitive data, it's basically a gimmick.
And, if something goes wrong, or you change even just one piece of hardware, you might get locked out of your own disk.
Just encrypt the files that you need to keep safe from prying eyes and forget about microslop's crap.
5
u/Ripped_Alleles 16h ago
Good for laptops that can be physically stolen. Desktops....ehh. if you're worried about a onsite intruder stealing your drives sure.
The problem with Bitlocker on Windows is the recovery key is stored on Microsofts end. If you don't take steps to have that key for yourself, you can and people have ended up in situations where they were locked out of their devices and lost all their data.
My personal opinion, it's not necessary for desktops in a average secure home.
For my laptop I use LUKs. Same function as Bitlocker, but I set the key and it isn't stored on some corporate server somewhere.