Це відео не доступне.
Перепрошуємо.

Why I (No Longer) Avoid BitLocker

Поділитися
Вставка
  • Опубліковано 17 сер 2024

КОМЕНТАРІ • 83

  • @littlestinker9716
    @littlestinker9716 8 місяців тому +17

    Don't just save your Bitlocker keys on a thumb drive. *PRINT* your keys and include comments about what each key is for. Store the paperwork securely.

    • @portman8909
      @portman8909 5 місяців тому +2

      Printed, on a mobile device, and saved to usb ideally

    • @pow1983
      @pow1983 24 дні тому +1

      I save mine within an encrypted zip file, backup up twice. I'm definitely not printing them.

  • @MegaGeorge1948
    @MegaGeorge1948 2 місяці тому +3

    Another situation of Bit Locker not allowing access to the encrypted drive on boot up is a BIOS upgrade of a new machine by the manufacture after the Bit Locker encryption took place. The TPM (Trusted Platform Module) stores the Bit Locker key configuration of the encrypted drive.
    it's a separate chip on the motherboard. Though the TPM 2.0 standard allows manufacturers like Intel or AMD to build the TPM capability into their chipsets rather than requiring a separate chip. If the data on the TPM (e.g. a bios upgrade) does not match the key data on the encrypted drive, you better have your Bit Locker key handy or you're screwed.

    • @lohphat
      @lohphat 26 днів тому

      You should suspend -- not disable -- Bitlocker before upgrading your BIOS and then re-enable after the BIOS is upgraded.

    • @dasgs8450
      @dasgs8450 21 день тому

      tpm module on motherboard can be easily opened

  • @SaneCatLady429
    @SaneCatLady429 11 днів тому

    What is frustrating is that the printed out key says to check the key number to the number on the computer, but I can't find that information on the computer.

  • @warp00009
    @warp00009 2 місяці тому

    Thank you for this video! I've also always avoided BitLocker like the plague, not trusting that Microsoft wouldn't mess something up, lose my key, and leave me whistling in the dark to get my data back. Not happy that now they're trying to force BitLocker encryption on all Windows systems, which just seems unnecessarily stupid for anything other than easily stolen laptops.

  • @NoEgg4u
    @NoEgg4u Рік тому +8

    @0:20 "...in every edition of Windows, other than Home."
    The "Home" addition does have BitLocker (in a way). It is not enabled. If you were to enter a "Pro" license key, BitLocker would become enabled, and nothing BitLocker related gets installed (it was already there).
    Windows does this with other tools, such as Remote Desktop.
    Only Pro and above can act as the server. But Home versions of Windows can start the Remote Desktop client and connect to a Windows machine running the Server end of Remote Desktop.
    Back to BitLocker...
    If someone hands you a USB drive that is BitLocker encrypted, your Home version will be able to decrypt it, the same as Pro.

    • @Dafoosa2
      @Dafoosa2 6 місяців тому

      Update: 2024: Windows 11 Home version will now automatically enable bitlocker on internal drives if you log into a microsoft account on a modern device. Ref: ua-cam.com/video/qnqnIuGEnH0/v-deo.html I can personally confirm this, as I bought a windows surface pro 8 last year with Windows Home and bitlocker is turned on on C: drive. Whats bad, is I didnt know it was on, but got lucky and noticed and have now made a backup of my c drive recovery key

  • @cadelepski5161
    @cadelepski5161 Рік тому +2

    I've used Bitlocker for several years now. Works great!

    • @monza8844
      @monza8844 6 місяців тому +1

      Works great.... until you have issues.

    • @cadelepski5161
      @cadelepski5161 6 місяців тому

      @@monza8844 Like everything else...ever. Like I said, several years and no issues. To me, that's working great.

  • @ramcholan2034
    @ramcholan2034 13 годин тому

    Thanks, well explained. couple of questions.
    1. Does BitLocker encryption extends to OneDrive when enabled? Objective: making zero-knowledge encryption on OneDrive. I believe its not, want to confirm with you.
    2. What happens when using CryptoMator on a BitLocker enabled device, to synch with OneDrive? any conflicts I should be concerned? thanks

  • @chester8459
    @chester8459 2 місяці тому +2

    When someones steals my computer tpm+pin is there an way to decrypt it? Or is it 100% safe? I mean no one can bruteforce an long pin

  • @polka23dot70
    @polka23dot70 3 місяці тому +3

    According to TomsHardware, BitLocker slows down SSD by up to 45%.

    • @askleonotenboom
      @askleonotenboom  3 місяці тому

      Any chance you can provide a link? I'd love to confirm that. Fascinating if true, I was under the impression performance impact was negligible.

    • @SBDavin
      @SBDavin 3 дні тому

      Google for an article from May titled "Windows 11 24H2 will enable BitLocker encryption for everyone - happens on both clean installs and reinstalls"

  • @bishnuchowdhury4939
    @bishnuchowdhury4939 3 місяці тому +1

    What are you talking about. I've been using bitlocker encrypted drive after new windows setup and on other computer

  • @colt5189
    @colt5189 3 місяці тому

    I would do all three. Save to Microsoft account if you have one in use. Save the file to an external drive, and make sure it's backed up to several other drives as USB or SD cards or whatever are cheap. And 3rd, print out a few copies to keep a copy and maybe give a copy to a relative or keep in your car or something.

  • @340dave
    @340dave Рік тому +5

    One thing I recently encountered on a bit-locked drive, I couldn't clone it. Only after turning off bitlocker could I clone drive (Win10).

    • @electrocat9
      @electrocat9 Рік тому

      logic if you try clone with windows

    • @340dave
      @340dave Рік тому

      @@electrocat9 Not cloning with windows, using Acronis or AOMEi (Windows versions though..)

  • @JoshuaTrenge
    @JoshuaTrenge 4 місяці тому +3

    Hi Leo.. I almost decided to turn on Bitlocker… then learned of the issue with SSD drive slowdowns with Windows 11. I’d love to hear your take on this problem?

    • @rcazzador
      @rcazzador 2 години тому

      Same thing happens with Veracrypt.
      My SSD usually got 3000MB/s (Bc my laptop only supports PCie 3.0) and now it's less than 1000MB/s (read/write speed)

  • @lohphat
    @lohphat 26 днів тому

    I store my recovery key in 1password.
    Saving it in your MSFT account means you've enabled a 3rd party to decrypt your drive. It's not clear that recovery key is protected. I assume it's not and is recoverable by MSFT or the NSA if they request it. So it's only saved in places I trust.
    Can you upgrade a Win10 + BL + TPM install to Win11 while BL+TPM are still active or do you have to disable BL first?

  • @colt5189
    @colt5189 3 місяці тому

    I believe you can buy SSD drives that are self incrypting, i.e. hardware encrypting. So may be a better way of doing it than via software. I have used Veracrypt a few times in the past when I went on vacation and brought my laptop with me. Though in that instance, I also loaded a new install of the OS on a spare drive and only loaded files that I may have needed access to while on vacation instead of using my main drive at the time that was loaded with all of my docs/pics, etc. Just in case it got stolen.

  • @GgfdfgggsgZ
    @GgfdfgggsgZ 5 місяців тому

    i saved the code for my combination lock on my computer before loading a corrupted world and i had bitlocker enabled and now I can’t open the combination lock

  • @pitsmcgoo
    @pitsmcgoo 7 місяців тому +1

    I must have a boring life I can't think of a reason I need this.

    • @jamesedwards3923
      @jamesedwards3923 6 місяців тому

      That is exactly the wrong thought process. If you keep information. Important to anything thief. It needs to be protected.

    • @portman8909
      @portman8909 5 місяців тому

      It's default on mobile devices and should be default on any desktops or laptops. There's no noticeable performance impact. My applications and games run smooth as before.@@jamesedwards3923

  • @spambedam
    @spambedam Рік тому +2

    Leo the warning came too late to save me from Bitlocker being on by default. Encrypted into a corner describes it well. I ended up in frustration wiping everything and re-installing. I have Bitlocker turned off since then. This seems to me best described as a malicious booby trap in Windows waiting to ensnare the unwitting like me. Why is it on by default?

    • @askleonotenboom
      @askleonotenboom  Рік тому +2

      "For your protection" I would assume. It's totally safe AS LONG AS you back up the recovery key.

    • @sirensatnight4463
      @sirensatnight4463 3 місяці тому

      @@askleonotenboom This is not true. If you use Bitlocker and update your drivers, and then the computer won't boot, Bitlocker won't save you either. You should NEVER use Bitlocker under any circumstances. It is a bomb which can and will go off, destroying your data and hard drive. I know. I've dealt with this many times with clients who accidentally turned it on when they bought the computer, not knowing any better. Some day though, we find out that they didn't save the key, and they did somehow get themselves into a mess. Bitlocker is a horrible thing. Don't do it. Learn how to remove it so ignorant users don't accidentally screw themselves up. What an awful thing Microsoft has done here. If you need encryption, why is that? Find some other way, don't allow Microsoft to turn on anything that you are not sure of. They will screw you, for sure. Dang, Stop this, Microsoft. We don't want you to make something that people can accidentally enable and destroy their ability to get back into their computer and data.

  • @nobody1841
    @nobody1841 Місяць тому

    Is it possible to change the BL key or password to something you can remember?

    • @askleonotenboom
      @askleonotenboom  Місяць тому

      Decrypt, and then re-encrypt.

    • @nobody1841
      @nobody1841 Місяць тому

      @@askleonotenboom i will look into that. Thank you for responding, much appreciated.

  • @franciscohorna5542
    @franciscohorna5542 Рік тому +3

    im on windows 10 home so i dont have or use that

  • @codywy5579
    @codywy5579 7 місяців тому +1

    Hi, Does Macrium back up the data unencrypted? I am 99% sure that it does but want to ask you to be 100%. Thank You! 🤔

    • @askleonotenboom
      @askleonotenboom  7 місяців тому +1

      It does by default. You can password protect a backup, which encrypts it.

  • @graytonw5238
    @graytonw5238 Рік тому

    Thanks, I've been thinking about trying Bitlocker for some time, this helps alleviate some of my trepidation!

    • @SpiritintheSky.
      @SpiritintheSky. 9 місяців тому +1

      I'm pleased to learn that it has alleviated your trepidation. However, it has increased mine.

  • @tonytech5520
    @tonytech5520 2 місяці тому

    What happens if the owner of the computer is not tech-savvy, has never saved the recovery key, and now she is unable to log into the computer?

    • @frankdaeran352
      @frankdaeran352 2 місяці тому

      That's a perfect example of Bitlocker doing it's job. If it were that easy to recover, then it would be pointless to use any encryption.

    • @tonytech5520
      @tonytech5520 2 місяці тому

      @@frankdaeran352 My question is not if it is easy to recover; my question is, is it possible to recover without wiping out the disk?

  • @Allessio777
    @Allessio777 Рік тому +1

    If you make an image backup of a Bitlocker encripted drive; if you have to boot from it, can you? or do you need the recovery key?

    • @askleonotenboom
      @askleonotenboom  Рік тому

      Generally you cannot boot from image backups - you need to restore them first. As to whether or not the key is needed depends on exactly how the backup was created and what tool was used.

    • @jamesedwards3923
      @jamesedwards3923 6 місяців тому +3

      Saving a single copy of all your important data. To a boot drive. For long term storage. A horrible idea.
      Your OS drive. Should never be a permanent long term storage unit.

  • @johnpalma7265
    @johnpalma7265 4 місяці тому

    Question: does veracrypt need to be installed on a computer in order to make a veracrypt encrypted file accesable? Thanks for the video

  • @MoreBollocks-ui2zs
    @MoreBollocks-ui2zs 3 місяці тому

    And here I struggle with eh idea that I even need to have a Microsoft account...
    I admit I did not finish the video as the first half had nothing new or helpful. Its simply reading the bitlocker instructions...

  • @robertagallant3819
    @robertagallant3819 4 місяці тому

    BitLocker Encryption is not listed in Control Panel on Windows 11 Home Edition, Leo. What should i do now?

    • @pao_jacare
      @pao_jacare 4 місяці тому

      It's only available on pro edition.

    • @robertagallant3819
      @robertagallant3819 4 місяці тому +1

      Thank you for letting me know
      that the BitLocker Encryption is
      available on Windows Pro Edition.

  • @ContantContact
    @ContantContact 3 місяці тому +1

    I avoid BitLocker totally. And also Windows.
    After decades of Microsoft, starting before MS Windows, I got fed up with it, and moved from Windows to Linux Mint 26 months ago. Don't miss Windows at all, and am not going back.
    Windows Shows Us How NOT To Encrypt Our Drives
    ua-cam.com/video/JIia8Hj_3tE/v-deo.html

  • @UHFStation1
    @UHFStation1 5 місяців тому

    Is bitlocker about physical theft of drives only? If there is no threat of that can it be disabled?

    • @askleonotenboom
      @askleonotenboom  5 місяців тому

      Mostly physical theft or access yes. I consider it important for mobile computers, and optional for desktop/stationary depending on their environment.

  • @SpiritintheSky.
    @SpiritintheSky. 9 місяців тому

    For the only time, find myself out of my depth with one of your admirable videos. It doesn't help that you begin with using BL before you've checked whether or not it has already been set by Microsoft and there is some sort of Key or password - confusing - to be found somewhere. (For information, I'd already tried another video and had to give up.) I'll have to persist somehow to protect myself against BL already running in situ, or suddenly find myself like the very unfortunate "spambedam" below.

    • @SpiritintheSky.
      @SpiritintheSky. 9 місяців тому

      Further to my comments two days ago, I've followed the video's advice to see if BL is on or not. But my Win 11 laptop, fully up to date, as of 17.11.23 / 11.17.23, displays neither "Manage BL" nor the ability to turn off BL (if "on"!) under Show More Options. Perhaps it's "off" and therefore no mention of BL is necessary?

  • @XENONEOMORPH1979
    @XENONEOMORPH1979 8 місяців тому

    Never had to use it , i do not store photos etc , i use it as a gaming machine nothing more nothing less , if i want to use it for bank etc i use another pc that no one can use , but i have just noticed a bios flash update for the motherboard needs bitlocker turned on , that is not what i am happy about , It should be of choice to use it or not and not forced to use it .
    So it looks like i will buy a fresh drive specifically for it .

    • @paijokotak6996
      @paijokotak6996 6 місяців тому

      I eccounter big problem because of it 😢

    • @XENONEOMORPH1979
      @XENONEOMORPH1979 6 місяців тому

      @@paijokotak6996 what encounter would that be ?

  • @RotaryTeamVincent
    @RotaryTeamVincent Рік тому

    Is your file data available if you share to another person or device?

    • @askleonotenboom
      @askleonotenboom  Рік тому

      I'd need more specifics. Of course something you share with someone else makes that available to them, so I'm certain I'm not understanding the question.

  • @RealShadowfiend180x
    @RealShadowfiend180x 12 днів тому

    I'd rather die than use or trust a proprietary file disc encryption method or tool especially a Microsoft one 🤢

  • @user-bp1ec7zu4u
    @user-bp1ec7zu4u 4 місяці тому

    I will never buy Windows computer again, moving to Mac, less hassle

  • @MrDeviousdom
    @MrDeviousdom 6 місяців тому

    Bit locker encryption sounds like a great option yet it's another poor Microsoft implementation. It's basically an inconvenience for someone that wants to get your data off of your Windows computer.
    If you forget your PIN, a lot of times there is a link that will have Microsoft send a recovery code to your phone. (That's pretty damn insecure).
    There are also multiple attacks known against the TPM directly which can obtain your encrypted data.
    There are multiple other ways that an attacker can obtain your "encrypted" data in bitlocker.
    Obviously, if you are using Windows, security is not your top concern, but be aware.

    • @portman8909
      @portman8909 5 місяців тому

      Again that is the point. You don't want your drive easily accessible. Either pin code or recovery key. If you lose both, then that's your fault.
      Bitlocker is to prevent on site data stealing while the drive is locked. It doesn't do anything to prevent hacking because the Bitlocker is unlocked when you sign in obviously.
      There is no TPM hack for CPU integrated TPM. That trick only worked for dedicated TPM modules by jumping it with a tool.

  • @davideaston6872
    @davideaston6872 14 днів тому

    I wish Micro$oft Would Push end Users harder on installing Making it Clear you Need to save This Code SOME were..
    The Number of machine I have seen with windows 11 and end user has NO idear ..
    (and WHY Should They)
    Under Stand How Important this code is...
    Last one Here was a Wife Who's Husband Past..
    She Dose not Know the PIN to Log into this Laptop (She has Her Own)
    But knowing He Always download Photos from his devices over YEARS to this Machine..
    Backing up Equals Two or More Copys..
    Make a copy of your Family Photos today and Give them to Family..
    After All Off Site Back up is the GOLD standard!
    (Seen Two Many People Lose Photos Over 40 Years of working in IT)

  • @tvbox6955
    @tvbox6955 6 місяців тому

    The following error is preventing bitlocker: failed to open the bitlocker control panel tool: error code 0x80004005
    How do I fix this?