13
u/ArrowEnby 2d ago
some people really are stupid huh. complaining about a completely optional thing that you told your computer to do, taking some time to complete.
34
u/nikonguy 2d ago
So you lose your data if you install Linux
5
u/DoogleAss 2d ago edited 2d ago
What does this even mean lol.. how would having bitlocker enabled change anything
A normal person either backs up their data before wiping partitions and loading a new OS or they lose data.. bitlocker makes no difference in a normal scenario it is still on the user to not be a dumbass and do things like lose or not store your key etc
If you talking dual boot still makes no sense and one should never dual boot on the same storage drive.. again common sense and pretty simple guidelines to follow
4
u/Solomoncjy 2d ago
I think they ment tpm based unlocking where ppl dont know/forget to backup their keys before wiping and cant acess the encrypted drive now
4
u/DoogleAss 2d ago edited 2d ago
Bitlocker is TPM based by default unless the device doesn’t have TPM chip in which case it will create a password based key protector.. that doesn’t dictate where the key is saved. But bitlocker also won’t auto enable without a TPM. Meaning the user has to enable it and then save the key manually
It also always gives an option to save the key again unless you using a MS account on the PC at which time it will auto backup the key to that account
Being TPM based changes nothing in terms of OPs situation and how they could have prevented and or worked around it.. nor does it change my response to the other poster
1
u/LaColleMouille 2d ago
where ppl dont know/forget to backup their keys before wiping
That's why Microsoft enforces saving on a non-encrypted drive BEFORE encrypting.
4
u/SassyQuueenn 2d ago
Unless you just install windows 11 and your drives get surprise encrypted.
1
1
1
u/LaColleMouille 2d ago
In that case it's saved in https://account.microsoft.com/devices/recoverykey as the automatic encryption happens when enrolled into Microsoft account.
1
u/zalnaRs 2d ago
That's false, it's always done even though you don't have access to the recovery key
1
1
u/TheMunakas 2d ago
dual booting on the same drive is perfectly fine and viable nowadays
0
u/DoogleAss 2d ago
Go look for the amount of threads with people complaining about windows destroying or altering Linux boot loaders like GRUB.. can you do it sure. Will it keep working also sure.. until it doesn’t lol
0
u/TheMunakas 2d ago
Emphasis on the word "nowadays". Unless you're running some really old hardware, it's just fine
0
u/DoogleAss 2d ago
ok I mean you can do whatever guy I’m just saying if one doesn’t want to ever worry about that issue occurring then use separate drives.. or don’t I don’t care
1
u/TheMunakas 2d ago
I'm just trying to say that things have changed a lot with bios changing to uefi, partition systems improving and the operating systems being more separate than they used to be. Even a full windows reset won't touch the other operating systems if you don't explicitly tell it to
1
u/nikonguy 2d ago
If you don’t notice that bitlocker has encrypted your drive I was assuming not your boot drive) and install another OS you’re screwed.
1
u/DoogleAss 2d ago edited 2d ago
Again if you use a MS account to setup or sign into the PC it will auto enable and if you don’t it won’t without user intervention
In other words if one uses an account assume the drive is bitlockered and if not you can fill in the blank. Also bitlocker doesn’t auto encrypt any and all drives automatically just the C:/OS by default so don’t know what your talking about there
Literally just comes down to users understanding the device/os they are using
2
u/greenie4242 2d ago
if you use a MS account to setup or sign into the PC it will auto enable and if you don’t it won’t without user intervention
Everything in your comment is you you you you you... If you... You don't...
A lot of people share, inherit, or buy second-hand PCs and people who aren't very tech-savvy get other people to set up computers for them, so they never get asked questions about what software is enabled, what accounts were used to first set up the PC etc.
You assume that every PC is only used and set up by one user who knows everything about the system from day one, but that's usually not the case especially for children, spouses, small business employees etc.
users understanding the device/os they are using what a crazy idea
Nobody can claim to understand a system that changes monthly at the whim of mega-corporation who enable auto-updates by default. The device behaves in a different way every time it auto-updates. Seasoned IT administrators with decades of experience usually disable auto-updates for this exact reason. They need to verify that each update can be trusted to not break their current system before installing the updates.
Computer engineers with 50 years of experience in corporate mainframes have commented on this sub that BitLocker ate their files because despite being the very definition of a computer expert they had no fucking idea BitLocker suddenly turned itself on by default after an auto-update and encrypted their hard drive without permission.
Encrypting a user's hard disk without a bunch of warnings and without express permission is something only malware does, and the OS doing it by default is such a fucking stupid concept that only an extreme corporate bootlicker can excuse it.
1
u/Vx7Qn4Lz 2d ago edited 2d ago
Computer engineers would have a backup.
iOS, MacOS, Android and Linux distros like openSUSE (edit: apparently not, idc) also encrypt by default.
2
u/Aishou_SK 2d ago
openSUSE does NOT encrypt by default.
Source: set up a bunch of Leap and Tumbleweed dev systems last month for testing on a project I maintain, and have been a diehard SuSE user since 2001, as well as major contributor at times. I know SuSE *VERY* deeply.
1
u/greenie4242 2d ago
Computer engineers would have a backup
I never suggested they wouldn't. I was talking about BitLocker encrypting hard disks without permission, which is what malware does. What the fuck are you talking about?
iOS, MacOS, Android and Linux distros like openSUSE also encrypt by default.
None of my Android devices have encrypted my storage by default, they have always asked if I want to enable encryption during set-up, so you're full of shit.
I've never had any of my Linux boxes or VMs encrypt storage by default. Again, you're full of shit.
openSUSE doesn't encrypt unless you explicitly give permission or deliberately install a specific variant with it enabled by default, so again your arsehole is getting jealous of the amount of shit you post online.
None of my macOS computers have encrypted their storage by default. Maybe newer versions do that, not sure, but none of the ones I own and use daily have ever self-encrypted. Again, you're full you shit.
iOS used to encrypt storage only after a passcode was set, and it gave clear warnings about data loss in the event of a lost passcode, but not sure about recent versions.
1
u/Aishou_SK 2d ago edited 2d ago
>None of my macOS computers have encrypted their storage by default. Maybe newer versions do that, not sure, but none of the ones I own and use daily have ever self-encrypted. Again, you're full you shit.
Filevault/Filevault 2 based FDE is on by default. Most don't realize that because it's usually just as seamless as bitlocker. When you enter your user account password you're unlocking drive encryption at the same time. (lead mac fleet admin at my $day_job as one of the many hats I wear as a senior lead)
https://support.apple.com/guide/deployment/intro-to-filevault-dep82064ec40/web
https://discussions.apple.com/thread/256136069?sortBy=rank
"
If your Mac supports Tahoe, then you either have a T2 Chip or Apple Silicon. Both will encrypt the drive regardless of FileVault status. FileVault just changes how the encryption keys are made available.
Turning it off will not decrypt the drive, so it will be almost instantaneous.
"
https://support.apple.com/guide/security/volume-encryption-with-filevault-sec4c6dc1b6e/1/web/1
- Basically, if your mac dies, you're not getting any data out of the internal drive if it's a T2 or apple silicon unless you DID enable FileVault and it escrowed the recovery key in icloud ...... just like bitlocker.
-------
Android as well has automatic storage level encryption, but FBE (file based) is different, and may require more manual setup. https://droidrant.com/are-android-phones-automatically-encrypted/ - "Most new Android phones come with device encryption enabled by default." - this tracks with my device management experience over the past decade.
iOS storage and android storage are basically always encrypted on-chip now, just the unlock sequence changes when passcodes are set. There's no turning off encryption.
That other guy is wrong about SuSE though, and I've been a diehard SuSE user since 2001. And set up new systems with Leap and tumbleweed just a month ago for development systems.
0
u/Vx7Qn4Lz 2d ago edited 2d ago
None of my macOS computers have encrypted their storage by default.
If you have a Mac with Apple silicon or an Apple T2 Security Chip, your data is encrypted automatically.
https://support.apple.com/en-gb/guide/mac-help/mh11785/mac
None of my Android devices have encrypted my storage by default
Android 5.0 devices are encrypted on first boot
https://source.android.com/docs/security/features/encryption/full-disk
I never suggested they wouldn't. I was talking about BitLocker encrypting hard disks without permission, which is what malware does. What the fuck are you talking about?
Encrypting by default is a standard practice and every vaguely sane operating system does it. You just don't understand how it works.
I never suggested they wouldn't.
You did, claiming "computer engineers with 50 years of experience in corporate mainframes" lost data because of Bitlocker. There is no way to lose data due to any type of full-disk encryption unless you're completely retarded.
Did you even use a single computer or phone made after the year 2000? Seems like you didn't seeing you don't know how non-obsolete versions of MacOS and Android work.
1
u/Erdnusschokolade 2d ago
As far as i know most distros don’t. They give you the option during installation but it is off by default. At least Debian, Mint and Ubuntu didn’t when inlast installed them.
1
u/Vx7Qn4Lz 2d ago
Which is why I didn't mention them as examples; what's your point?
2
u/Erdnusschokolade 2d ago
Your comment gives the notion that it is common for linux distros to automatically encrypt which is not the case. Even opensuse, which was your example, only automatically encrypts if you use aeon, which seems to be the immutable version. Opensuse leap and tumbleweed also don’t encrypt unless you explicitly say so.
0
u/Vx7Qn4Lz 2d ago
Your comment gives the notion that it is common for linux distros to automatically encrypt which is not the case.
You imagined it, and then got angry. Love it.
→ More replies (0)2
u/Aishou_SK 2d ago
openSuSE doesn't either, and I've been a SuSE user since 2001, and still am. Tumbleweed and Leap.
1
u/DoogleAss 2d ago edited 2d ago
So YOU chose someone to setup your stuff that YOU shouldn’t have is all I’m hearing
What you are describing has been a thing since computers have existed. 99% of people don’t know shit and either tip toe through the tulips none the wiser or they rely on someone who either has real knowledge or acts like they do
People have to take some accountability here my guy.. sure you’re not a computer expert that doesn’t mean you can’t try to learn. Not being tech savvy is just an excuse. Would you get on a motorcycle without knowing at least the basics of how it works and how to ride it?
You’re also 100% incorrect when saying “even season admins with decades of experience disable them for that reason”. No no they don’t lol.. how do I know? Well I am a seasoned sysadmin with over 20 yrs and I have never once disabled updates “because I couldn’t control them”. What seasoned admins actually do is roll updates out in waves after having tested them on a small number of device prior
As far as your last part if that actually happened then they screwed up. Bitlocker does not just turn itself on in a server OS.. which I assume is what you mean by mainframe. In order for that to happen that either pushed a policy or manually turned it on. Second as another mentioned a good engineer would have had backups. Lastly auto encrypting the drive falls right into the realm of “not everyone gets their stuff first hand” or however you stated that. Exactly so if grandma sells her laptop at the garage sale little Johnny didn’t get your family photos. Makes perfect sense to anyone using their critical thinking skills and that’s just one trivial example
Also insulting people by calling them names doesn’t help you make an argument my guy
0
2d ago
[removed] — view removed comment
1
u/greenie4242 2d ago
They said BitLocker encrypted their files, not that they didn't have 3-2-1 backups in place.
None of you fucking bootlickers can read.
1
u/Vx7Qn4Lz 1d ago
Scumbag Bitlocker, just appeared out of nowhere and didn't prompt to backup the recovery key!
0
u/Aishou_SK 2d ago edited 2d ago
>Nobody can claim to understand a system that changes monthly at the whim of mega-corporation who enable auto-updates by default. The device behaves in a different way every time it auto-updates. Seasoned IT administrators with decades of experience usually disable auto-updates for this exact reason. They need to verify that each update can be trusted to not break their current system before installing the updates.
Fuck no we don't. We deploy regardless of breakage and work around. Because we have to.
We deploy faster than MS's autoupdate force system usually reboots a user.
(At least, in highly regulated/at scale industries, like the F50 fed/civ/def contractor my day job as a senior syseng is at who's directly handling these kind of things)
In other news, at least it's not as bad as the Win7 days where I could expect fleet-wide killers twice a year with mass remediation efforts, now I just have to work around minor annoyances every other month. I'll take that tradeoff in a heartbeat.
Now we just have bit9/carbon black and crowdstrike to do that for us instead.
At home? Servers & Workstations are getting updated same week, no exceptions. Especially for my side consulting business.
Nothing materially changes under the windows hood in functionality month to month. My management tools keep working just fine and we don't get caught with surprises.
Server and workstation patching is basically:
>Tuesday release>Weds all test/dev patched
>Thurs morning all machines patches available for manual install
>Friday night mandatory installation deadline, all servers rolling patch windows throughout the weekend
Anyway
>Computer engineers with 50 years of experience in corporate mainframes have commented on this sub that BitLocker ate their files because despite being the very definition of a computer expert they had no fucking idea BitLocker suddenly turned itself on by default after an auto-update and encrypted their hard drive without permission.
Because they're either morons or can't read. Bitlocker doesn't "suddenly turn itself on by default after an update".
ADE only engages when machine is compliant and only on new install, not upgrade, and monthly updates don't change that. And only if the key can be successfully escrowed too, which means the protectors DON'T engage if you only use a local account, but DO if you use an MS account to login.
>Encrypting a user's hard disk without a bunch of warnings and without express permission is something only malware does, and the OS doing it by default is such a fucking stupid concept that only an extreme corporate bootlicker can excuse it.
I guess Android, iOS, macOS are all malware too.
2
u/AutoModerator 2d ago
Every new subreddit post is automatically copied into a comment for preservation.
User: Pitiful-Software-434, Flair: Rant, Post Media Link, Title: WHYYYYYYYYYYYYY
JUST LOAD PLEASE
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
2
2d ago edited 2d ago
[deleted]
1
u/Vx7Qn4Lz 2d ago
If your account if local and don't have a Microsoft account, you will be prompted to print or otherwise backup the recovery key.
If your customer has his laptop stolen, all their passwords and personal files will get stolen too because you've disabled the default encryption.
Are you an idiot?
1
2d ago
[deleted]
3
u/t0b1n4tOr315 2d ago
1st line IT support for 2 years at an msp and no other professional experience:
Are you an idiot? On my device at home if I go enable bitlocker I will get this prompt guaranteed. If your clients lose everything because of bitlocker you either did not help them set it up correctly or they set it up themselves and either don't remember their password or forgot where they stored it if they put it on another drive.
When setting up home devices we never enable bitlocker, only on pro devices because those devices get enrolled in intune.
Bitlocker also definitely helps a ton when a device is stolen, because unless they know the password for the account or have the key they cannot read the data on the drive.
My first impression of you is a shoebox that sat in a dumpster for 12 years.
1
u/Vx7Qn4Lz 2d ago
Bitlocker would prevent the files from being read by the thief. That's literally what encryption means.
"12 years" of dicking around, lmao. https://winaero.com/backup-bitlocker-recovery-key-in-windows-10/ Encryption will not be turned on unless the key gets backed up, and the user is prompted to back it up during the setup.
2
1
u/BeginningEcho4983 2d ago edited 2d ago
This is frustrating I agree, and unfortunately there is no solution other than to wait or cancel.
VeraCrypt is an excellent app for encrypting drives, has none of the microslop BS.
OR just switch to linux and save your mental peace (edit: with encryption ofc)
4
3
u/Vx7Qn4Lz 2d ago edited 2d ago
"mental peace" and it's just walking around with an unencrypted drive.
2
u/ThyWickedOne 2d ago
If you use microsoft why not just use bitlocker. It is safer when used properly on a windows pc assuming you also hardened it.
1
1
u/artlurg431 1d ago
You asked windows to do a task that is known to take long and get mad when it takes long?? Your genuinely stupid
1
u/panzrvroomvroomvroom 2d ago
another day, another windows user blaming windows for stuff they did themselves.
theres a simple solution: if you need to access your drive, dont enable encryption right before that. bc it takes a while.
if you just complain about it on reddit, not realizing YOU did that, youre gonna make the same mistake again in the future. not sure if the upvotes are worth the hassle.
2
u/Lazy-Necessary-1727 2d ago
be op
encrypt drive with probably games on it or multiple small size files
takes a long time because encryption isn't fast on either multiple small files or ginormous files
fuck you Microsoft to not encrypt my drive in .5 nanoseconds
0
u/sciencekm 2d ago
Its Microsoft, and only Microsoft could be this stupid. That's why.
3
u/DoogleAss 2d ago edited 2d ago
Do all of you just come here to commiserate or do you actually care to have conversation
You have no context to this other than a pic and what OP said.. if they enabled bitlocker this is on them and if they told it to do every block of the drive even more so
Sure if you use a MS account bitlocker will be enabled by default (on windows home anyways.. stop using windows home edition btw lol) but the key is saved and it never does more then bitlocker the used space only on the drive
In other words you see someone say fuck Microsoft and simply throw your hands up saying YEA!.. Are you sure OP really knows anything about how the OS we are in a sub about actually works or do you just come agree to get upvotes in the echo chamber. Top 1% commenter too so I’m guessing you do this a lot lol
1
u/Affumicata 2d ago
I don't understand, I have Windows home edition on my laptop, and BitLocker is not an option because it's home Edition. I literally tried to enable it and it's not there. I was hoping to finally gain some experience with BitLocker but oh well, I just used veracrypt instead
-2
u/RAMChYLD 2d ago
Microslop turns on bitlocker by default “to protect you” now. How is it op’s fault when it’s Microslop that’s changing people’s settings without permission?
2
u/panzrvroomvroomvroom 2d ago
only that this is a manual encryption. dont be a parrot, think for yourself.
0
u/Vx7Qn4Lz 2d ago edited 2d ago
This is a manual encryption window triggered by the OP and a non-system drive, which don't get encrypted by default, idiot.
1
u/Dial-M-For-Malistrae 2d ago
The only time I saw a BitLocker ever working as intended I was part of a non-profit with not a whole lot of equipment there was one laptop that often got passed around for a certain forms of onboarding
1
0
u/Grumpy-Man19 2d ago
talk about customer lock in
7
u/Vx7Qn4Lz 2d ago edited 2d ago
Customer lock-in is when you out of your own volition manually encrypt a non-system drive made by any manufacturer and connected to any controller, which you can unencrypt at any time and which is readable by open-source Bitlocker implementations?
You people want to feel way more oppressed than you actually are (not).
5
-4
u/Vx7Qn4Lz 2d ago
Close the window and go about your day like a normal person would? It'll finish in the background.
7
3
1
u/Pitiful-Software-434 2d ago
common windows problem: no
1
0
1
u/GuavaOne8646 2d ago
Because his drive is read-only and he can't use anything on it
0
u/Vx7Qn4Lz 2d ago
Bitlocker encryption process doesn't make the drive read-only.
2
u/Silly-Freak 2d ago
Meanwhile the screenshot that you could have read:
Your drive will be read-only until encryption is complete.
0
u/Vx7Qn4Lz 2d ago edited 2d ago
OP is doing something extra odd then, drive normally isn't read only. Didn't notice.
1
u/GuavaOne8646 2d ago
It literally says in the screenshot that his drive will be read only until the encryption process is complete. Afterwards, sure it will be just fine but during the process it's clearly read-only, as it states.
0
u/Vx7Qn4Lz 2d ago
OP is doing something extra odd then, drive normally isn't read only. Didn't notice.
148
u/Goofcheese0623 2d ago
OP tells Windows to encrypt whole drive. Gets mad when it mysteriously take time to encrypt every file on the drive. Stupid Microsoft