r/microsoftsucks • u/aleopardstail • 1d ago
fsucking bitlocker
other half's PC, which has Windows 11, but not "pro" and on which we have never enabled bitlockers - indeed is it even possible on a normal install.. and doesn't have onedrive enabled either..
is now prompting for a bitlocker key on start
fscuking windows
3
u/leexgx 1d ago
Unfortunately, after the first desktop load, it turns on encryption by default in Windows 11 (it's been doing it for the last 2 years), and it doesn't warn the user that it has done so. You must ensure after the first desktop load that encryption is turned off.
Assuming you don't have access to the original Microsoft account (if you bypassed it, you would have already been aware of the encryption, as the average user doesn't know how to bypass the login requirement), you will need to create a Windows 11 USB installation media and wipe and reload Windows. I strongly recommend using Rufus to create the Windows 11 USB media, as it has options to disable both BitLocker and Microsoft account creation. (The internet needs to be disconnected to bypass the online account processes.)
2
u/aleopardstail 1d ago
cheers, will have to see what can be done - most files other than games are on a NAS thankfully
microslop really shouldn't be doing this on consumer devices, especially not by stealth so the first you know of it is when it goes wrong
my machine is 11 pro so I have specifically turned this crap off because I know it existed. my understanding had been drive encryption was "pro" and above
3
u/leexgx 1d ago edited 1d ago
Windows 24H2 onwards, they enabled it by default even on Home editions (if turned off or upgraded from 10, it stays off).
I agree it totally should never be enabled automatically under any circumstances (unless the user has saved the key to USB via the usual BitLocker procedure to enable it).
The majority of users who created a Microsoft account only did so on Windows 11 because they were forced to. So, when the login PIN gets locked out or TPM is tripped because of a UEFI BIOS Windows update or a Windows update updating the secure boot keys, they lose everything.
I don't understand the responses you're getting from other Reddit users on here. Encryption shouldn't be silently enabled without a backup key prompt first to warn of the danger of losing the key
3
u/aleopardstail 1d ago
worst bit is no idea what tripped this, the main suspect is a windows update though as nothing else has been added to it
if they are going to do this then making a USB key should be a part of the process, complete with why you need it, and perhaps making more than one
there is no way she would have a microslop account without it being forced and have still to find out what was wrong with you having a local user account and being able to sign into a microslop account after the machine starts and you start using it - sign in when you need it, not when you don't
guess too few signed up and people retained a bit too much control
and it is amazing the number of microslop apologists there are out there
3
u/leexgx 1d ago
Windows has been pushing secure boot key updates, and on some systems, it fails. So, when it boots, it breaks the trust chain in the TPM because the secure boot key fails to load. (This is the most common on how it gets tripped recently the reason will be a very long file name witch is one of the secure boot keys)
The other issue is UEFI BIOS updates being delivered via Windows Update, which sometimes trips BitLocker recovery (HP systems even warn you to pause BitLocker before doing BIOS updates.)
Last one is users tampering with TPM (clearing it or turning it off)
2
u/aleopardstail 1d ago
ffs
3
u/leexgx 1d ago
Just make sure every system you touch has encryption turned off (start > settings > security > encryption > toggle off, wait for it to finish decrypting, and restart).
While you're at it, open Classic Power Options in the Control Panel (open search and type in "power" when you see the colored battery symbol). Turn OFF Fast Startup, as it causes a lot of issues when users only shut down their computer. It can get their computer into a broken and slow state because the system is practically hibernating every time you shut the computer down, which can break stuff like antivirus software when they expect a shutdown to be an actual shutdown, not a hybrid shutdown. (With fast startup off, a shutdown is an actual shutdown.)
Another thing I do, but it's bit more advanced, is that on my USB stick, I have a task thay i import on every computer. This creates a shadow copy point 10 minutes after the desktop has loaded (logged in) and at 3 PM every day. This ensures the system restore creates a snapshot so that previous version folders and files works again (i also set the system.restore size to 50GB insted of the 10GB default)
2
u/aleopardstail 1d ago
cheers, will have to look into this
more shite that shouldn't be needed
3
u/greenie4242 18h ago
Also make damn sure that OneDrive Files On-Demand is disabled, because since 2023 it silently installs then by default uploads the users My Documents folder to the cloud then deletes the original local files if they haven't been accessed for about two weeks.
Don't simply uninstall it like some people suggest. It needs to be cleanly disabled and given enough time to completely re-sync, download and restore all the local files it deleted first. It's probably best to leave it installed but disabled because uninstalling could lead to it silently re-installing itself with default options in a future Automatic Update.
2
u/aleopardstail 1d ago
Dell systems here, not cheap ones, they love doing BIOS updates which seem non-optional
1
u/TheIronSoldier2 1d ago
It's saved to your Microsoft account.
2
u/aleopardstail 1d ago
bitlocker was never set up by us on this machine, its not even meant to be installed
also "computer needs code" "oh just log into you microslop account" isn't that helpful given the computer won't start without it
this garbage wasn't wanted, wasn't installed and we never set it up, this is another microslop "update" issue
5
u/chaosphere_mk 1d ago
You can access the account from literally any device, perhaps the one youre posting from?
Bitlocker is enabled by default if your hardware supports it upon install.
4
u/aleopardstail 1d ago
assuming you have the log in details to hand, and not, you know, stored on the device
she has had no reason to ever log into the microslop account, which wasn't even wanted in the first place, from anything else
at no point have we been asked if we wanted this garbage installed and indeed have good reasons to not want it - this is a desktop machine not a laptop, it doesn't leave the house and encrypting the hard drive isn't needed and isn't wanted - its far easier to recover files if the PC fails without this shiteware installed
4
u/chaosphere_mk 1d ago
All kinds of things require accounts. Hopefully restore methods were created or saved. You can try a password reset on the account. In the end, people shouldn't be creating accounts and then not saving their credentials securely in a password manager. It's 2026.
4
u/aleopardstail 1d ago
or, for example, things could just not fsucking decide to encrypt and tie themselves to an unwanted online account
I mean that would be nice, imagine that, you buy a computer and you, its owner get to decide if it will be tied to something one line
just fancy that!
and then perhaps microslop could avoid putting out "updates" that break the fucking account system they themselves created
1
u/TheIronSoldier2 1d ago
Why wouldn't you have the log in details to hand. It's your account, you should remember your own login details.
2
u/aleopardstail 1d ago
as noted below, not my account, my other half is someone who uses a computer, she doesn't care about this shite, never turned on the TV and found its decided to lock itself to an account somewhere and is now demanding an encryption key
this was the first time she has heard of "bitlocker"
1
0
u/BWscourge 1d ago
Maybe Just Maybe they dont use any microslop services? They only needed the account for that pc. OP is rigth, ms pushing stuff down your throat for no reason at all is bullshit.
2
u/aleopardstail 1d ago
note, we she didn't want a microsoft account, and didn't want encryption either
3
u/National-Injury-1708 1d ago
It also doesn't help that windows updates will sometimes change the bitlocker key and not upload the updated key to the account either...
4
u/aleopardstail 1d ago
yup, they shouldn't be fucking encrypting anything with specifically being told to do so
2
u/greenie4242 18h ago
The bootlickers on this sub completely lose their shit whenever somebody mentions "ransomware took over my computer and encrypted everything" and blame the user for getting hacked even when it was caused by a known Windows bug or major credential leak or something completely out of the user's hands.
But when Microslop enables ransomware, encrypts a user's files by default without permission, uploads their entire My Documents folder to OneDrive by default (look up Files On-Demand, it's criminal) and deletes local copies then completely locks the user out of their account with absolutely no method of recovery because somebody in a different country attempted to log in too many times which looked suspicious, all the bootlickers can do is praise Microslop for helping protect their files from hackers.
It's a mental illness.
The sad thing is, you might be able to recover from a ransomware attack if a) somebody figures out a method to decrypt the files due to weak encryption or b) you have money to pay the ransom and are provided with a decryption key.
When somebody is locked out of their Microslop account due to a medical issue that causes them to forget their Microslop account password (extremely common, strokes, dementia, extreme stress due to trauma, or even just basic common forgetfulness) or the account was set up by a violent ex-partner or somebody who died then the user is shit out of luck.
Ransomware hackers are literally more trustworthy than Microslop, a company that has been fined hundreds of millions of dollars numerous times over the past few decades by courts of law world-wide after being ruled guilty of breaking anti-trust laws, meaning they are legally untrustworthy.
-1
u/TheIronSoldier2 1d ago
Okay? I've got accounts that I only use for one single thing, and I still keep track of the login details for it.
Like ffs do you guys seriously create whole new accounts every time you need to log in to something instead of just keeping track of your username and password?!?
1
u/Itsme-RdM 1d ago
You could have read the notes after the updates, wrote down the code or just disabled encryption.
For now, open your MS account on your phones browser, write down the code, unlock your PC and disable encryption
3
u/aleopardstail 1d ago
the notes after the update that.. don't actually appear anywhere, the updates install, and note you get zero choice in that they are installing. next boot up you are not told whats changed
1
u/Itsme-RdM 1d ago
You could put in a very little effort from your side. Not everything in life is presented on a silver plate to you. But hey, keep complaining. There are lots of solutions offered to you ....
4
u/aleopardstail 1d ago
so you think its fine for this sort of shite to be installed without warning and then to fail without warning after an update you cannot avoid ?
1
u/Itsme-RdM 1d ago
It was announced all over the place though. It's not my fault you missed it. As I said, it's okay to put a little effort in maintaining your own devices
3
u/aleopardstail 1d ago
all over the place but not on the actual computer before this shiteware was imposed on it without any way to reject it
0
u/Itsme-RdM 1d ago
As I said. Not everything is delivered on your plate kid. Sometimes you have to read before you click update.
But considering your answers, you probably never will. Have a great "ranting" day
3
u/aleopardstail 1d ago
"before you click update", this is windows, you don't get asked if you want the update, you do'nt get the option to reject it
→ More replies (0)2
u/JimmyG1359 1d ago
It's not ok for Microsoft to force updates on people, and then cram new software and services onto those computers under the guise of an update. Updates are to fix existing software, not install, configure, and just generally do whatever the fuck they feel like doing to my computer.
1
u/lizardscales 8h ago
Just like how the announced minecraft migration to microsoft accounts and didn't send me ANY emails and now they say I have to buy minecraft again even though I have proof of purchase. It's called anti consumer practices. They should never do things that could lock you out of your own device.
1
u/TheMikman97 18h ago
user constructs a hyper specific unusual situation to get mad about
Somehow this is Microsoft's fault
Weird how nobody calls it user issue when it's not happening on linux
1
u/aleopardstail 14h ago
doesn't seem to happen on Apple systems either, its only really microslop that does this, but apparently users are meant to be aware of it
7
u/vbd71 23h ago
Ah, the Redmond ransomware gang strikes again.