Это видео недоступно.
Сожалеем об этом.

Why I (No Longer) Avoid BitLocker

Поделиться
HTML-код
  • Опубликовано: 16 авг 2024
  • ➕ BitLocker is fine encryption if you avoid encrypting yourself into a corner. The problem is that it's too easy for the average user to skip steps that could result in data loss.
    ➕ Using Bitlocker safely
    To encrypt your drive with BitLocker safely, right click the drive in Windows File Explorer and click on Turn on BitLocker. Save the recovery key as part of the setup process. Do not skip this step, or you may lose access to your data. Then back up your data as well.
    Updates, related links, and more discussion: askleo.com/17437
    🔔 Subscribe to the Ask Leo! RUclips channel for more tech videos & answers: go.askleo.com/...
    ✅ Watch next ▶ Find Your Lost Bitlocker Recovery Key in Your Microsoft Account ▶ • Find Your Lost Bitlock...
    Chapters
    0:00 No Longer Avoid BitLocker
    0:20 Encrypt yourself into a corner
    1:00 Using Bitlocker safely
    2:00 Back up your recovery key
    4:20 A second opportunity to backup your key
    4:20 Bitsocker enabled by default
    5:00 Check if you have your recovery key
    5:40 How you can get locked out
    7:20 How to recover
    8:00 Proper backups can protect you
    9:24 Alternatives
    ❤️ My best articles: go.askleo.com/...
    ❤️ My Most Important Article: go.askleo.com/...
    More Ask Leo!
    ☑️ askleo.com to get your questions answered
    ☑️ newsletter.ask... to subscribe to the Confident Computing newsletter.
    ☑️ askleo.com/patron to help support Ask Leo!
    ☑️ askleo.com/all... for even more!
    #askleo #bitlocker #encryption

Комментарии • 81

  • @littlestinker9716
    @littlestinker9716 8 месяцев назад +16

    Don't just save your Bitlocker keys on a thumb drive. *PRINT* your keys and include comments about what each key is for. Store the paperwork securely.

    • @portman8909
      @portman8909 5 месяцев назад +2

      Printed, on a mobile device, and saved to usb ideally

    • @pow1983
      @pow1983 22 дня назад +1

      I save mine within an encrypted zip file, backup up twice. I'm definitely not printing them.

  • @MegaGeorge1948
    @MegaGeorge1948 2 месяца назад +3

    Another situation of Bit Locker not allowing access to the encrypted drive on boot up is a BIOS upgrade of a new machine by the manufacture after the Bit Locker encryption took place. The TPM (Trusted Platform Module) stores the Bit Locker key configuration of the encrypted drive.
    it's a separate chip on the motherboard. Though the TPM 2.0 standard allows manufacturers like Intel or AMD to build the TPM capability into their chipsets rather than requiring a separate chip. If the data on the TPM (e.g. a bios upgrade) does not match the key data on the encrypted drive, you better have your Bit Locker key handy or you're screwed.

    • @lohphat
      @lohphat 25 дней назад

      You should suspend -- not disable -- Bitlocker before upgrading your BIOS and then re-enable after the BIOS is upgraded.

    • @dasgs8450
      @dasgs8450 20 дней назад

      tpm module on motherboard can be easily opened

  • @SaneCatLady429
    @SaneCatLady429 9 дней назад

    What is frustrating is that the printed out key says to check the key number to the number on the computer, but I can't find that information on the computer.

  • @warp00009
    @warp00009 2 месяца назад

    Thank you for this video! I've also always avoided BitLocker like the plague, not trusting that Microsoft wouldn't mess something up, lose my key, and leave me whistling in the dark to get my data back. Not happy that now they're trying to force BitLocker encryption on all Windows systems, which just seems unnecessarily stupid for anything other than easily stolen laptops.

  • @NoEgg4u
    @NoEgg4u Год назад +7

    @0:20 "...in every edition of Windows, other than Home."
    The "Home" addition does have BitLocker (in a way). It is not enabled. If you were to enter a "Pro" license key, BitLocker would become enabled, and nothing BitLocker related gets installed (it was already there).
    Windows does this with other tools, such as Remote Desktop.
    Only Pro and above can act as the server. But Home versions of Windows can start the Remote Desktop client and connect to a Windows machine running the Server end of Remote Desktop.
    Back to BitLocker...
    If someone hands you a USB drive that is BitLocker encrypted, your Home version will be able to decrypt it, the same as Pro.

    • @Dafoosa2
      @Dafoosa2 5 месяцев назад

      Update: 2024: Windows 11 Home version will now automatically enable bitlocker on internal drives if you log into a microsoft account on a modern device. Ref: ruclips.net/video/qnqnIuGEnH0/видео.html I can personally confirm this, as I bought a windows surface pro 8 last year with Windows Home and bitlocker is turned on on C: drive. Whats bad, is I didnt know it was on, but got lucky and noticed and have now made a backup of my c drive recovery key

  • @JoshuaTrenge
    @JoshuaTrenge 4 месяца назад +2

    Hi Leo.. I almost decided to turn on Bitlocker… then learned of the issue with SSD drive slowdowns with Windows 11. I’d love to hear your take on this problem?

  • @colt5189
    @colt5189 3 месяца назад

    I would do all three. Save to Microsoft account if you have one in use. Save the file to an external drive, and make sure it's backed up to several other drives as USB or SD cards or whatever are cheap. And 3rd, print out a few copies to keep a copy and maybe give a copy to a relative or keep in your car or something.

  • @cadelepski5161
    @cadelepski5161 Год назад +2

    I've used Bitlocker for several years now. Works great!

    • @monza8844
      @monza8844 6 месяцев назад +1

      Works great.... until you have issues.

    • @cadelepski5161
      @cadelepski5161 6 месяцев назад

      @@monza8844 Like everything else...ever. Like I said, several years and no issues. To me, that's working great.

  • @340dave
    @340dave Год назад +5

    One thing I recently encountered on a bit-locked drive, I couldn't clone it. Only after turning off bitlocker could I clone drive (Win10).

    • @electrocat9
      @electrocat9 Год назад

      logic if you try clone with windows

    • @340dave
      @340dave Год назад

      @@electrocat9 Not cloning with windows, using Acronis or AOMEi (Windows versions though..)

  • @bishnuchowdhury4939
    @bishnuchowdhury4939 3 месяца назад +1

    What are you talking about. I've been using bitlocker encrypted drive after new windows setup and on other computer

  • @polka23dot70
    @polka23dot70 3 месяца назад +2

    According to TomsHardware, BitLocker slows down SSD by up to 45%.

    • @askleonotenboom
      @askleonotenboom  3 месяца назад

      Any chance you can provide a link? I'd love to confirm that. Fascinating if true, I was under the impression performance impact was negligible.

    • @SBDavin
      @SBDavin 2 дня назад

      Google for an article from May titled "Windows 11 24H2 will enable BitLocker encryption for everyone - happens on both clean installs and reinstalls"

  • @chester8459
    @chester8459 2 месяца назад +1

    When someones steals my computer tpm+pin is there an way to decrypt it? Or is it 100% safe? I mean no one can bruteforce an long pin

  • @GgfdfgggsgZ
    @GgfdfgggsgZ 5 месяцев назад

    i saved the code for my combination lock on my computer before loading a corrupted world and i had bitlocker enabled and now I can’t open the combination lock

  • @lohphat
    @lohphat 25 дней назад

    I store my recovery key in 1password.
    Saving it in your MSFT account means you've enabled a 3rd party to decrypt your drive. It's not clear that recovery key is protected. I assume it's not and is recoverable by MSFT or the NSA if they request it. So it's only saved in places I trust.
    Can you upgrade a Win10 + BL + TPM install to Win11 while BL+TPM are still active or do you have to disable BL first?

  • @colt5189
    @colt5189 3 месяца назад

    I believe you can buy SSD drives that are self incrypting, i.e. hardware encrypting. So may be a better way of doing it than via software. I have used Veracrypt a few times in the past when I went on vacation and brought my laptop with me. Though in that instance, I also loaded a new install of the OS on a spare drive and only loaded files that I may have needed access to while on vacation instead of using my main drive at the time that was loaded with all of my docs/pics, etc. Just in case it got stolen.

  • @pitsmcgoo
    @pitsmcgoo 7 месяцев назад +1

    I must have a boring life I can't think of a reason I need this.

    • @jamesedwards3923
      @jamesedwards3923 6 месяцев назад

      That is exactly the wrong thought process. If you keep information. Important to anything thief. It needs to be protected.

    • @portman8909
      @portman8909 5 месяцев назад

      It's default on mobile devices and should be default on any desktops or laptops. There's no noticeable performance impact. My applications and games run smooth as before.@@jamesedwards3923

  • @spambedam
    @spambedam Год назад +2

    Leo the warning came too late to save me from Bitlocker being on by default. Encrypted into a corner describes it well. I ended up in frustration wiping everything and re-installing. I have Bitlocker turned off since then. This seems to me best described as a malicious booby trap in Windows waiting to ensnare the unwitting like me. Why is it on by default?

    • @askleonotenboom
      @askleonotenboom  Год назад +2

      "For your protection" I would assume. It's totally safe AS LONG AS you back up the recovery key.

    • @sirensatnight4463
      @sirensatnight4463 3 месяца назад

      @@askleonotenboom This is not true. If you use Bitlocker and update your drivers, and then the computer won't boot, Bitlocker won't save you either. You should NEVER use Bitlocker under any circumstances. It is a bomb which can and will go off, destroying your data and hard drive. I know. I've dealt with this many times with clients who accidentally turned it on when they bought the computer, not knowing any better. Some day though, we find out that they didn't save the key, and they did somehow get themselves into a mess. Bitlocker is a horrible thing. Don't do it. Learn how to remove it so ignorant users don't accidentally screw themselves up. What an awful thing Microsoft has done here. If you need encryption, why is that? Find some other way, don't allow Microsoft to turn on anything that you are not sure of. They will screw you, for sure. Dang, Stop this, Microsoft. We don't want you to make something that people can accidentally enable and destroy their ability to get back into their computer and data.

  • @franciscohorna5542
    @franciscohorna5542 Год назад +3

    im on windows 10 home so i dont have or use that

  • @MoreBollocks-ui2zs
    @MoreBollocks-ui2zs 3 месяца назад

    And here I struggle with eh idea that I even need to have a Microsoft account...
    I admit I did not finish the video as the first half had nothing new or helpful. Its simply reading the bitlocker instructions...

  • @tonytech5520
    @tonytech5520 2 месяца назад

    What happens if the owner of the computer is not tech-savvy, has never saved the recovery key, and now she is unable to log into the computer?

    • @frankdaeran352
      @frankdaeran352 2 месяца назад

      That's a perfect example of Bitlocker doing it's job. If it were that easy to recover, then it would be pointless to use any encryption.

    • @tonytech5520
      @tonytech5520 2 месяца назад

      @@frankdaeran352 My question is not if it is easy to recover; my question is, is it possible to recover without wiping out the disk?

  • @codywy5579
    @codywy5579 7 месяцев назад +1

    Hi, Does Macrium back up the data unencrypted? I am 99% sure that it does but want to ask you to be 100%. Thank You! 🤔

    • @askleonotenboom
      @askleonotenboom  7 месяцев назад +1

      It does by default. You can password protect a backup, which encrypts it.

  • @Allessio777
    @Allessio777 Год назад +1

    If you make an image backup of a Bitlocker encripted drive; if you have to boot from it, can you? or do you need the recovery key?

    • @askleonotenboom
      @askleonotenboom  Год назад

      Generally you cannot boot from image backups - you need to restore them first. As to whether or not the key is needed depends on exactly how the backup was created and what tool was used.

    • @jamesedwards3923
      @jamesedwards3923 6 месяцев назад +3

      Saving a single copy of all your important data. To a boot drive. For long term storage. A horrible idea.
      Your OS drive. Should never be a permanent long term storage unit.

  • @UHFStation1
    @UHFStation1 5 месяцев назад

    Is bitlocker about physical theft of drives only? If there is no threat of that can it be disabled?

    • @askleonotenboom
      @askleonotenboom  5 месяцев назад

      Mostly physical theft or access yes. I consider it important for mobile computers, and optional for desktop/stationary depending on their environment.

  • @nobody1841
    @nobody1841 Месяц назад

    Is it possible to change the BL key or password to something you can remember?

    • @askleonotenboom
      @askleonotenboom  Месяц назад

      Decrypt, and then re-encrypt.

    • @nobody1841
      @nobody1841 Месяц назад

      @@askleonotenboom i will look into that. Thank you for responding, much appreciated.

  • @johnpalma7265
    @johnpalma7265 4 месяца назад

    Question: does veracrypt need to be installed on a computer in order to make a veracrypt encrypted file accesable? Thanks for the video

  • @SpiritintheSky.
    @SpiritintheSky. 9 месяцев назад

    For the only time, find myself out of my depth with one of your admirable videos. It doesn't help that you begin with using BL before you've checked whether or not it has already been set by Microsoft and there is some sort of Key or password - confusing - to be found somewhere. (For information, I'd already tried another video and had to give up.) I'll have to persist somehow to protect myself against BL already running in situ, or suddenly find myself like the very unfortunate "spambedam" below.

    • @SpiritintheSky.
      @SpiritintheSky. 9 месяцев назад

      Further to my comments two days ago, I've followed the video's advice to see if BL is on or not. But my Win 11 laptop, fully up to date, as of 17.11.23 / 11.17.23, displays neither "Manage BL" nor the ability to turn off BL (if "on"!) under Show More Options. Perhaps it's "off" and therefore no mention of BL is necessary?

  • @graytonw5238
    @graytonw5238 Год назад

    Thanks, I've been thinking about trying Bitlocker for some time, this helps alleviate some of my trepidation!

    • @SpiritintheSky.
      @SpiritintheSky. 9 месяцев назад +1

      I'm pleased to learn that it has alleviated your trepidation. However, it has increased mine.

  • @robertagallant3819
    @robertagallant3819 4 месяца назад

    BitLocker Encryption is not listed in Control Panel on Windows 11 Home Edition, Leo. What should i do now?

    • @pao_jacare
      @pao_jacare 4 месяца назад

      It's only available on pro edition.

    • @robertagallant3819
      @robertagallant3819 4 месяца назад +1

      Thank you for letting me know
      that the BitLocker Encryption is
      available on Windows Pro Edition.

  • @XENONEOMORPH1979
    @XENONEOMORPH1979 8 месяцев назад

    Never had to use it , i do not store photos etc , i use it as a gaming machine nothing more nothing less , if i want to use it for bank etc i use another pc that no one can use , but i have just noticed a bios flash update for the motherboard needs bitlocker turned on , that is not what i am happy about , It should be of choice to use it or not and not forced to use it .
    So it looks like i will buy a fresh drive specifically for it .

    • @paijokotak6996
      @paijokotak6996 6 месяцев назад

      I eccounter big problem because of it 😢

    • @XENONEOMORPH1979
      @XENONEOMORPH1979 6 месяцев назад

      @@paijokotak6996 what encounter would that be ?

  • @ContantContact
    @ContantContact 3 месяца назад +1

    I avoid BitLocker totally. And also Windows.
    After decades of Microsoft, starting before MS Windows, I got fed up with it, and moved from Windows to Linux Mint 26 months ago. Don't miss Windows at all, and am not going back.
    Windows Shows Us How NOT To Encrypt Our Drives
    ruclips.net/video/JIia8Hj_3tE/видео.html

  • @RotaryTeamVincent
    @RotaryTeamVincent Год назад

    Is your file data available if you share to another person or device?

    • @askleonotenboom
      @askleonotenboom  Год назад

      I'd need more specifics. Of course something you share with someone else makes that available to them, so I'm certain I'm not understanding the question.

  • @RealShadowfiend180x
    @RealShadowfiend180x 11 дней назад

    I'd rather die than use or trust a proprietary file disc encryption method or tool especially a Microsoft one 🤢

  • @user-bp1ec7zu4u
    @user-bp1ec7zu4u 4 месяца назад

    I will never buy Windows computer again, moving to Mac, less hassle

  • @MrDeviousdom
    @MrDeviousdom 6 месяцев назад

    Bit locker encryption sounds like a great option yet it's another poor Microsoft implementation. It's basically an inconvenience for someone that wants to get your data off of your Windows computer.
    If you forget your PIN, a lot of times there is a link that will have Microsoft send a recovery code to your phone. (That's pretty damn insecure).
    There are also multiple attacks known against the TPM directly which can obtain your encrypted data.
    There are multiple other ways that an attacker can obtain your "encrypted" data in bitlocker.
    Obviously, if you are using Windows, security is not your top concern, but be aware.

    • @portman8909
      @portman8909 5 месяцев назад

      Again that is the point. You don't want your drive easily accessible. Either pin code or recovery key. If you lose both, then that's your fault.
      Bitlocker is to prevent on site data stealing while the drive is locked. It doesn't do anything to prevent hacking because the Bitlocker is unlocked when you sign in obviously.
      There is no TPM hack for CPU integrated TPM. That trick only worked for dedicated TPM modules by jumping it with a tool.

  • @davideaston6872
    @davideaston6872 12 дней назад

    I wish Micro$oft Would Push end Users harder on installing Making it Clear you Need to save This Code SOME were..
    The Number of machine I have seen with windows 11 and end user has NO idear ..
    (and WHY Should They)
    Under Stand How Important this code is...
    Last one Here was a Wife Who's Husband Past..
    She Dose not Know the PIN to Log into this Laptop (She has Her Own)
    But knowing He Always download Photos from his devices over YEARS to this Machine..
    Backing up Equals Two or More Copys..
    Make a copy of your Family Photos today and Give them to Family..
    After All Off Site Back up is the GOLD standard!
    (Seen Two Many People Lose Photos Over 40 Years of working in IT)

  • @tvbox6955
    @tvbox6955 6 месяцев назад

    The following error is preventing bitlocker: failed to open the bitlocker control panel tool: error code 0x80004005
    How do I fix this?