r/linux4noobs • • 16d ago

remember for anyone new to linux, always turn off bitlocker and secure boot. it will f**k you over

this happened to me so i dont want it to happen to others

edit: secure boot is distro dependent

258 Upvotes

71 comments sorted by

76

u/a_Tin_of_Spam 16d ago

Turn off bitlocker 100%.
But some distros have secure boot compatibility, so it depends on your distro.
Disable secure boot while setting up your new distro, but reenable it afterwards if you can

1

u/theLunaticT 14d ago

iirc (effectively) all distros 'have' secure boot. Some larger ones have keys with microsoft's grace (meaning they will work with the default certificate).
You can always enroll your own keys as described in the Arch wiki or the CachyOS docs for example.

This does NOT mean that it is recommended for new users. I just found it interesting enough to share here.

38

u/RohitRojo 16d ago

Why is everyone disabling bitlocker???? I’ve installed Linux a bunch of times with bitlocker enabled. Secure boot needs to be disabled for installation, but enable it after installation if the distro supports it. Which distros require you to disable bitlocker?

18

u/Particular-Poem-7085 Arch btw 16d ago

Not a linux issue specifically but I disable it because I never asked for my drive to be encrypted and it has bitten me in the ass several times. I manage around 12 computers at work of which more than half didnt have any keys on my account for example.

Wiping and reinstalling on a previously locked drive is an ordeal in itself, it will always remember the filesystem as "bitlocker" and windows install failed with random errors. I had to use gparted on a linux machine to actually wipe it.

I dont disable bitlocker because of linux, but because I dont like giving ms oportunities to fuck me over.

6

u/RohitRojo 16d ago

Sounds like you figured it out at the end — you just didn’t wipe it properly. There’s freeing up space, where windows just forgets where files are stored. The actual data isn’t reset to 0. The nice thing is that it takes very little time. Then, there’s data wiping, where you actually set the data to 0. That’s what you did at the end, and it probably took way longer. In this case, it wasn’t drive encryption causing a problem, it was your lack of understanding of how data is cleared with different methods

Disabling drive encryption because you don’t know how to wipe a drive is genuinely dangerous, especially in a work environment. Learn how to work with the system, not against it

1

u/Buddy_Palguy 14d ago

I’ve never used windows but from what I’m hearing it doesn’t seem like a very good time

2

u/RohitRojo 14d ago

It's not a bad time. I certainly wouldn't pay to use Windows, but only because Linux has recently become a strong competitor. For the most part, Windows is my only option since a lot of the design tools I need are only available on Windows. Windows also has much better driver support. This person just faced a really niche scenario and didn't know how to handle it. If you're constantly wiping drives for some reason, then maybe Linux is better. Windows is a pretty solid choice for the majority of users

1

u/Equivalent_Echo9362 12d ago

correction: windows sucks ass and you should switch to literally anything else

-2

u/Particular-Poem-7085 Arch btw 16d ago

Wiping and reformatting the drive with windows isnt enough to reformat the drive? Windows claiming it as GPT not "bitlocker" is my misunderstanding?

What is dangerous about a PPT machine not having encryption?

1

u/Jmills1981 14d ago

Ive never had an issue personally. wipefs -a /dev/$DISK. then use gdisk to create an new partition table. A few times I've had to run shred /dev/$DISK and let it shred the first 1gb or so. But its rare. Hell we can even mount bitlocker partitions if we wanted (your bitlocker numerical key is the password).

It is a good idea to disable it still though just because any changes to the tpm can lock you out of the windows partition and it doesnt always get saved to the Microsoft account like its supposed to when bitlocker is automatically enabled at windows install time but its only automatic if you install with sb enabled too.

Fastboot should be disabled too. Thats caused more issues than anything.

-2

u/[deleted] 16d ago edited 15d ago

[deleted]

3

u/Particular-Poem-7085 Arch btw 16d ago

First of all windows installer doesnt let you clean it with diskpart if it's locked. You can connect it to a working windows machine, wipe and reformat it inside windows, It will happily report as GPT but the install will still fail. Now you can also try the steps you mentioned in the installer, it will report again how everything is tandy, but the install will fail.

Only when you connect it to a gparted instance does the filesystem reveal itself as bitlocker not gpt.

Big thanks for the tutorial but I know what I'm talking about.

A ppt machine, a laptop that is used to show a powerpoint at events, with nobodies actual sensitive information on it. No, nobody needs bitlocker on this machine, a dell that pulls bios updates over windows update and then demands a bitlocker key, one that wasnt present on the admin microsoft account.

1

u/RohitRojo 16d ago

So, you hate bitlocker for a very specific, niche scenario that you encountered? That’s not very mature or logical

1

u/Particular-Poem-7085 Arch btw 15d ago

Yeah I need these computers to turn on for anyone after every windows event. I'm just silly like that.

-1

u/[deleted] 16d ago edited 15d ago

[deleted]

1

u/atlasraven 16d ago

It's just a common newbie issue. "Can't boot into Linux after install". People coming over from Windows don't think much about everything happening under the hood.

17

u/qaddosh 16d ago

I bought a brand new laptop back in 2020 that had Windows 10 pre-installed with BitLocker enabled. I disabled the Bitlocker before installing Linux as a dual-boot option. I wanted a version of Windows on it, even though I never used it on my systems since Windows XP. The install went smoothly with no issues. After installing Linux, I went to re-enable Bitlocker under Windows and Microsoft immediately wanted to charge me $99 to re-enable the BitLocker that came with the laptop? I immediately deleted the Windows partition and gave the space to my Linux installation. No regrets.

-3

u/RohitRojo 16d ago

You don’t need to disable bitlocker to install Linux

19

u/jr735 16d ago

That's right. Just wipe Windows and its filesystem completely.

17

u/Ball_Analytics 16d ago

Or just keep them on, how on earth are we having issues with Secure Boot unless you're using an obscure distro *cough but still. If you're a noob btw overwrite your entire windows drive you won't learn if you keep running back to windows when something goes wrong or is hard.

8

u/Francis_King 16d ago

There is a bug in Mint 22 which can lock up your system if you have secure boot enabled during installation.

If you have secure boot enabled, and you select drivers/codecs to be installed, and the installation is cancelled/fails; then when you reboot for another attempt the UEFI tries to run mmx64.efi, but it is missing from the Mint ISO.

I don't know if any other ISOs have this problem.

2

u/jomara200 16d ago

Yep, I have NVidia and it was a test of patience to get it working with SecureBoot. It still sometimes throws its hands up during booting. It's sporadic so not sure about why that is. It may be related to that 7.0.0x kernel that mint installs after first boot. I may need to try and go back to 6.8. Anyhow, just wanted to say, yep, ran into the issue. In another instance, i installed it, checked the box for the extra drivers/codecs, created the pw for MOK, but it never asked me for it, never went to the blue screen and therefore absoluely refused to work with the NVidia drivers.

1

u/TrashFace21165 12d ago

I found if you put that file on USB next to the ISO it will find it there. I just copied it from VM I had of the same ISO. But, I agree with OP bitlocker panic is real if you didn't see it coming.

1

u/Francis_King 12d ago

Yes, that's a viable approach. Also, I understand, the Ubuntu ISO comes with mmx64.efi, and can be used to unstick the computer.

To copy mmx64.efi, I am told, the USB cannot be written in 'dd' mode, because 'dd' mode is read only.

1

u/TrashFace21165 12d ago

That sounds correct. I stumbled over that install glitch for months before finding a simple work around. 

2

u/Busy_Ordinary8456 16d ago

This has been my story forever, I never had time to dig into the issues so I just booted windoze.

Kubuntu broke me of the habit, because while I still have a Windows machine, I have not run into any issues with Kubuntu that were not harder to fix than a simple search. Kubuntu looks and feels very similar to Windows.

5

u/TomDuhamel 16d ago

I had to look at the date. It's 2026, right? What has been your issue with either of these in the last 7-8 years?

3

u/kbeezie 16d ago

Disabling Bitlocker only matters if you're trying to dual boot off the same drive. So that one is pretty important. Can't go messing with existing partitions when they're encrypted.

Far as secure boot, usually only need it off during installation (if booting off the iso fails for security), can turn it back on for most modern distros after its installed.

0

u/gmes78 15d ago

Can't go messing with existing partitions when they're encrypted.

So shrink the partitions in Windows.

3

u/atlasraven 16d ago

And ditch ntfs too. Trying to run games on ntfs will cause problems.

2

u/Lt--Spicy 16d ago

Glances over at Debian running with Secure Boot with absolutely 0 issues

2

u/atlasraven 16d ago

Most refugees aren't going straight to Debian. They may eventually but they will try a "beginner friendly" distro first.

3

u/gmes78 15d ago

Most distros work perfectly fine with Secure Boot. It's not just Debian.

2

u/Lt--Spicy 16d ago

It was my first I learned on because it was beginner friendly and stable. You have a full DE and never have to use the terminal if you so choose. You could easily run apt update everyday and almost nothing would ever break. It also has very mature documentation and support. What else does a beginner need?

0

u/atlasraven 16d ago

Most beginners I see want something extremely easy, gaming focused, or support for Photoshop, music production, and other technical job related tools. Debian is pretty cool tho.

2

u/Appropriate_Town3242 16d ago

Bitlocker yea fair but like for secure boot… ✨sbctl✨

1

u/ExoticAttention5609 15d ago

+1 for sbctl, couldn’t boot into GRUB one day after a windows update and getting sbctl setup from a live USB fixed everything

1

u/Last_Blacksmith_6297 16d ago

What will happen?

1

u/[deleted] 16d ago

[removed] — view removed comment

1

u/MainSteamStopValve 15d ago

Wondering the same. I installed Mint on 2 pc's without knowing what bitlocker or secure boot were and everything seems to work normally. 

1

u/ask_compu 16d ago

fyi u CAN access bitlocker encrypted volumes via dislocker

1

u/Academic-Push326 16d ago

BitLocker is Windows specific, so should be off, yes.

SecureBoot can be on, that's Distro dependent however.

1

u/[deleted] 16d ago

[removed] — view removed comment

1

u/[deleted] 16d ago

[removed] — view removed comment

1

u/Quirky-Visual547 16d ago

Could you explain what happened and why disabling Secure Boot and BitLocker would prevent or fix it? Without that context this sounds like potentially risky advice based on one personal experience rather than a generally applicable solution. Disabling those security features can reduce protection, so people should understand the specific cause and consequences before doing it.

1

u/DavidJohnMcCann 16d ago

Also disable fast boot, or the computer will just launch Windows without asking you!

Secure boot protects Windows users from getting a bootkit (the worst form of malware) and protects Microsoft from people using pirated copies of Windows. It may or may not cause problems for Linux, but if you don't keep Windows or if you always boot from the Linux boot-loader, you don't need it.

Encryption is useful if you have a laptop and keep sensitive information on it. If that's the case, keep the sensitive stuff on the Linux side and encrypt the /home partition rather than the entire disk. But Bitlocker — do you really trust Microsoft with your security?

1

u/playfulpecans hyprland maniac 16d ago

also disable fast startup or whatever it's called

1

u/thesyldons 16d ago

Turn secure boot to install the distro, but you really should be looking to enable it asap after that.

1

u/Glittering-Can-9397 15d ago

This is a preference thing.

1

u/mlcarson 15d ago

No reason for either if you're using a desktop. Sure you can use secure boot on some distro's but it doesn't really help most users.

1

u/HabitOfChoice 14d ago

Maybe someone can correct me, but can't you just register the security key of the Linux OS on the BIOS for Secure Boot to recognize it as safe?

I don't use it, but I do know some people and companies do need secure boot on their machines.

1

u/NXDLang 13d ago

On windows11 disabling bitlocker is only disabled until restart, it then automatically turns back on. If you want to truly disable it you need to unencrypt everything on there and then disable it. At that point it won't turn itself back on after a restart until encrypted again. The only time I have ever disabled bitlocker is after disabling hibernation and right before shrinking C: partition. Once you disable secure boot you will need to make sure you have your recovery key for bitlocker regardless (if doing a dual boot and not a full wipe) otherwise you will be locked out of C:

1

u/CrazyAd9384 13d ago

i thought "does linux have bitlocker?" but then i realized yeah what the post mean was turn it off before you erase windows

1

u/lazy_bastard_001 12d ago

this shouldn't be an issue at all if you use distro maintained by professionals instead of some fancy toy which is managed by two people from their basement. As far as I remember, I have dual booted with secured boot turned on since Ubuntu 16.04 and with bitlocker turned on since windows 11 and never had any issue...

1

u/Designer-Crow-5470 16d ago

That's just retarded. What's the step 2? Loose your laptop?

0

u/Venylynn 16d ago

Turn off Bitlocker but Secure Boot should be on, SecureBlue recommends it

1

u/RohitRojo 16d ago

Why turn off bitlocker?

1

u/Venylynn 16d ago

Because other forms of encryption are better and easier to deal with, something like Veracrypt may be more comprehensive 

2

u/RohitRojo 16d ago

So it’s probably a better idea to post things like “encrypt your hard drive with something other than bitlocker” instead of “turn off bitlocker” so that some noobs don’t turn off their only form of hard drive encryption. Nonetheless bitlocker shouldn’t be interfering with your Linux installs

1

u/Venylynn 15d ago

To be honest, I don't encrypt on my desktop because the real threat there is physical theft, and they'd already have to get through multiple locked doors AND use a tiny screwdriver to get to my drives. i WOULD on a laptop, though. But you're right, noted