Encryption and Security on Windows 11
Loading summary
Paul Thurott
Coming up next on Hands on Windows, we're going to look at the Great Bitlocker Controversy of 2025, by which I mean there really isn't a controversy, but we need to talk about it.
Leo Laporte
This episode brought to you by the Electronic Frontier Foundation. In fact, if you ask me, the whole Internet's brought to you by the EFF. For 35 years, the electronic Frontier foundation has been fighting to make sure that when you go online, your rights go with you. Eff I owe them a big debt of gratitude. They rescued our podcast and every podcast from patent trolls. They helped encrypt the web to protect your privacy. They prevail in lawsuits against government secrecy and surveillance. These are the good guys and they have a podcast, how to Fix the Internet. It's all about what happens if we win the fight and get things right online. And it's a great listen. The fight for digital rights, it's bigger and more urgent than ever. EFF is member supported. I'm a member. You should be a member. The more members they have, the stronger they can fight in statehouses, courthouses and on the streets. Season six of how to Fix the Internet started May 7th. Listen@eff.org podcast and while you're there, join the EFF. They're the good guys.
Unknown
Missions to Mars, driverless cars, AI chatbots. Feels like we're already living in the future. Well, Robinhood is built for the future of trading. Robinhood's intuitive design makes trading seamless. Spot opportunities and take control of your trades. With tools like screeners, simulated returns and strategy builder on Robinhood, traders have access to hundreds of popular stocks and ETFs 24 hours a day, five days a week so you can keep up with today's fast paced markets. You can now even trade stocks and crypto all in one place with the new desktop platform Robinhood Legend. The future of trading is fast, powerful and precise. Experience it now on Robinhood Investing is risky. Robinhood Financial LLC Member SIPC is a registered broker dealer. Trading during extended hours involves additional risks. Cryptocurrency services are offered through an account with Robinhood Crypto LLC. NMLS ID 1702840 Robinhood Crypto is licensed to engage in virtual currency business activity by the New York State Department of Financial Services.
I'm no tech genius, but I knew if I wanted my business to crush it, I needed a website. Now, thankfully, Bluehost made it easy. I customized, optimized and monetized everything exactly how I wanted with AI. In minutes, my site was up I couldn't believe it. The search engine tools even helped me get more site visitors. Whatever your passion project is, you can set it up with Bluehost. With their 30 day money back guarantee. What do you got to lose? Head to bluehost.com that's B L U E H O S T.com to start now.
Leo Laporte
Podcasts you love from people you trust. This is Twit.
Paul Thurott
Hello, everybody, and welcome back to Hands on Windows. I'm Paul Thurat and this is a show I didn't really want to make, but I woke up one morning, like a lot of you, when I saw a story that said Microsoft is forcing users of Windows to encrypt their disks and people are losing their data. And then I saw the advice that we should Never turn on BitLocker or this disk encryption feature. And what's Microsoft thinking? And yikes. So let me clear the air on this one. So this started on Reddit, as things often do these days. This is the post that kind of started this whole thing off. This guy's a security expert and his complaint is that Microsoft now automatically enables BitLocker during onboarding. In other words, you set up a new computer computer when you sign into a Microsoft account. That's not new. This behavior actually started in Windows 8. So that was 13 years ago. Ish. He goes on and on about security and whatever, but his. So what's, what's the complaint here? What's going on? So this is something we have talked about on this show, that in Windows 11 they've started pushing consumers to Microsoft accounts, right? And so the original version of Windows 11, when you signed in, like I've signed in here with my Microsoft account, it would basically force you to do that. There are workarounds for this. There's workarounds for everything. But at the time, if you signed in with Windows 11 Pro, you got the opportunity to choose between the account types. You could choose a local account, which is the old fashioned way of doing this. You could choose a Microsoft account, and of course you can choose a work or school account, which is like an Entra ID account now, or what used to be in Active Directory or Azure. Active Directory account, an account for work or school. Okay. When you sign in with an online account to Windows 11, it encrypts the disk. You want this. This is just good security. In fact, several months ago now, I did an episode about whether it was safe to sign in with a local account. Windows 11, it's not as safe, but you can make it safer. And One of the things you need to do is get that disk encrypted. The reason you encrypt a disk is because if the device is physically stolen and someone accesses that chip or that set of chips or whatever it is that constitutes the storage, they can't get at the contents of it. Right. If it's encrypted. If it's not encrypted, it's just wide open. Anyone could just look at it, take it, steal it, do whatever they want with it. The problem with encryption that the security expert on Reddit was pointing out is that Microsoft doesn't really communicate that this is happening. I think of it as a big benefit, but their fear is that you could lose access to your Microsoft account, which is remotely possible. It could happen, I suppose. And if you lost access to your Microsoft account, you would then lose access to the ability to recover your computer. If for some reason something went wrong with the boot process and it couldn't load Windows normally, you might be asked to enter what's called a BitLocker recovery key. If you can't get into your Microsoft account, you can't access that key because when BitLocker or Drive encryption is automatically enabled for you, it's put in your Microsoft account. It's basically put in OneDrive. You don't know this. Like, in other words, this seems underhanded. Microsoft is doing this behind your back. My argument is that this is what you want, this is a good thing. But apprised of this information, you may want to go take a look at this. And one of the things you can do is back up that key. You can put it somewhere else. So we're going to look at that right now.
Unknown
So when I ask, what is Odoo, what comes to mind? Well, Odoo is a bit of everything. Odoo is a suite of business management software that some people say is like fertilizer because of the way it promotes growth. But, you know, some people also say Odoo is like a magic beanstalk because it grows with your company and is also magically affordable. But then again, you could look at Odoo in terms of how its individual software programs are a lot like building blocks. I mean, whatever your business needs, manufacturing, accounting, HR programs, you can build a custom software suite that's perfect for your company. So what does Odoo. Well, I guess Odoo is a bit of everything. Odoo is a fertilizer, magic beanstalk, building blocks for business. Yeah, that's it. Which means that Odoo is exactly what every business needs. Learn more and sign up now@odoo.com that's O-O-O.com does it ever feel like you're.
A marketing professional just speaking into the void? Well, with LinkedIn ads you can know you're reaching the right decision makers. You can even target buyers by job title, industry, company seniority skills. Wait, did I say job title yet? Get started today and see how you can avoid the void and reach the right buyers with LinkedIn ads. We'll even give you a $100 credit on your next campaign. Get started at LinkedIn.com results terms and conditions apply. Ryan Reynolds here from Mint Mobile. I don't know if you knew this, but anyone can get the same Premium Wireless for $15 a month plan that I've been enjoying. It's not just for celebrities, so so do like I did and have one of your assistant's assistants switch you to Mint Mobile today. I'm told it's super easy to do@mintmobile.com.
Paul Thurott
Switch upfront payment of $45 for 3 month plan equivalent to $15 per month required intro rate first 3 months only, then full price plan options available, taxes and fees, extra fee, full terms@mintmobile.com so this would have come up when we did that episode again several months ago about signing in with a local account. If you go and look at the disk, there's nothing really to suggest anything is happening here with encryption or whatever. I think you could probably look around and find it eventually. But you really have to know that this is what's going on. And so in Windows 11 they've really simplified this user interface. You go to privacy and security and then you go to device encryption. And if you've signed in with an online account of any kind, so this would be work or school or Microsoft account, this will be enabled for you by default. Strongly recommend leaving that alone. Okay. This particular computer is running Windows 11 Pro, not home. So I actually get BitLocker Drive encryption, which is a user interface that is actually kind of old school and desktop based and dates back several years. But it allows you to do some things that you can't do on Windows 11 Home, including the ability, by the way, to encrypt portable disks like from a USB key or whatever or hard drive. But the other nice thing about this interface is that which doesn't support dark mode, right? Because it's so old is it gives you this backup your recovery key option and if you click here you'll get three choices, right? So you can save to your Microsoft account, which it already is, by the way. You can save to a file and I suspect because this is the disk that is being encrypted, that if I went into the desktop, for example, try to save it, it's going to say, no, you can't save the recovery key to the encrypted disk because the point of this recovery key is to access the encrypted disk if you get locked out of it, right? So you can't put it there. So you have to plug in a USB key or an external hard drive, or if you have a second hard drive, whatever it might be, you can't save it to the disk. That's good, that's what you want. You could also print the recovery key. In this case, you could print it to PDF and the hilarity here is it. If I do that, I just saved it to the disk. So that's how you can bypass that. But okay. Now the problem is you don't get this Interface in Windows 11 Home, which by the way, is an oversight on Microsoft's part. It does have this link here. I'm gonna, I'm just gonna go to it. I've already loaded it. But this will go to the Microsoft account website if you click it here. So when I bring up this, if I bring up the browser here, what you can see is the beginning of my gigantic list of BitLocker recovery keys. And so in this case, what you need to know is the name of the machine. And the name of this machine is probably HP Mini. So with that, armed with this information, I could then search that page for that thing. I'm not going to do that. If you look at these recovery keys at the beginning of this page, these are all from computers that are long gone, right? So it's safe to show this to somebody. Nobody can, you know, hack into my computers and get this. But what you could do with this is just copy, say that was the correct key, copy it somewhere and then save it. Right? Put it in a safe place. You know, one of those safe places, by the way, is personal vault in OneDrive, right? This will put it in the cloud. This is also encrypted. And this is something that's hard to get into. You have to provide a two factor authentication, et cetera, et cetera. So that's a nice place to store something like this. In fact, that is where I store things like that. So that's that you can also. I wouldn't do this, but in that interface that I Just closed stupidly. If you wanted to, I suppose you could turn it off and then turn it back on. And then when you did that, you would be prompted. Well, no, actually you wouldn't be prompted because you're saving it to your Microsoft account. So it would save to a new version, a new key. Right, to your Microsoft account and you could access it again from the Microsoft account website. So telling people that they should turn off encryption because they might lose access to the data on that disk is, to me, irresponsible, especially from someone who's supposed to be a security professional. But the other part of this is that if you're doing things correctly right, you should never lose data anyway. It's horrible to wake up in the morning and turn on a computer and have it not boot. And by the way, if you haven't seen the screen, Let me see if I can bring this thing up here. This is what it looks like if you have to enter this key. So this is a 48 character alphanumeric code. Essentially. It is a nightmare typing this in, right? The good news is if you get it wrong, it doesn't delete it, make it type the whole thing again. You can kind of look at it and try to get it right, whatever. But this is the type of screen you'll see if something goes horribly wrong with your computer. You won't see it otherwise. So this is bad. But in the good news department, if you're, if you're doing things correctly, like I said, and by correctly, what I mean is if you. This is a kind of a clean computer. There's nothing here on the desktop. This desktop is not in OneDrive folder backup, but it could be, and it would be by default, as long as your personal files, your data is all syncing to the cloud. The worst thing that's going to happen to you is that you have to maybe have to reinstall windows, which, by the way, you can, you can do without having to enter your BitLocker recovery key, right? You could just blow the whole disk away. You might. You'll have to reinstall your apps. We don't really have too many apps anymore where there's activation codes and we have to worry about that kind of stuff. But if you do have things like that, you know, you should be saving that information. By the way, save that to your personal vault. Right? I've talked about how I bulk install apps using winget, the Windows Package Manager. I have to go in and sign and do all that kind of stuff. But there's Nothing on this computer or any of my computers that's sitting out in a place where it's not being synced to the cloud at all times. So if I turn this thing on and it doesn't work. Yes, that's a hassle. Yes. I might have to restore the computer. I might actually have to reinstall the operating system. It's not great. But know where to find that BitLocker recovery key, and then that's the easiest course just to get into the computer. But again, if all goes south, you actually have a hardware problem. This thing is not going to boot. It's not going to matter if this thing's encrypted or not. And it's not going to matter because your stuff is safe. And so just do, just do things correctly and you'll be fine. All of your devices are encrypted these days, by the way. If you have an iPhone or an Android phone, a Mac, every one of those things is encrypted. That's the way we do things today. It's good security. So I don't see a controversy to Microsoft automatically enabling disk encryption or bitlocker on people's computers. I do agree they could communicate this a little bit better. In fact, it wouldn't be a horrible thing to give people the opportunity to save that key somewhere else during setup. Right. I think they're trying to streamline it and not make it take forever. But if you know what you're doing, you know where you can go to get the stuff. It's people. Most people can Google. You know, if you have a BitLocker recovery screen like that blue screen I showed you, you would probably Google that and that would tell you where you could get it. And you could get it on your phone. You could sign in again. I suppose there's this random chance that your computer could go south and Microsoft took away your Microsoft account. That doesn't happen a lot. You know, if that happens to you, things are really going south. But you can be prepared for that one too, Right? Because you can save that recovery key somewhere else. It doesn't have to only be or be at all in your Microsoft account. You can put it wherever you want. Right. So if you're really worried about it, I save it and save it to a couple of different places, I guess. But don't fall for the fud. This is the right thing for Microsoft to do. And for you as a user of Windows, it's the right thing for you to do. Your disk should be encrypted. Period. So I hope you found this useful. We'll have a new episode of Hands on Windows every Thursday. You can find out more at Twitter tv. H O W thank you so much for watching. Thank you especially to our Club Twit members. We love you. If you would like to know more about Club Twit and watch these videos without any ads and get all the other benefits of joining, you can find out more about that at Twit tv. Club Twit. Thanks so much. I'll see you next week.
Episode: Hands-On Windows 142: The Bitlocker Controversy of 2025
Host: Paul Thurott
Release Date: May 29, 2025
In the episode titled "Hands-On Windows 142: The Bitlocker Controversy of 2025," host Paul Thurott delves into a heated discussion sparked by a Reddit post questioning Microsoft's automatic enablement of BitLocker encryption on Windows devices. Paul aims to clarify misunderstandings and shed light on the true implications of BitLocker's integration within the Windows ecosystem.
Paul begins by recounting how the controversy emerged from a Reddit post authored by a self-proclaimed security expert. The post criticized Microsoft for automatically enabling BitLocker during the Windows onboarding process, especially when users sign in with a Microsoft account.
Paul Thurott (02:52): "This started on Reddit, as things often do these days. This is the post that kind of started this whole thing off."
He notes that this behavior isn't new, having been a feature since Windows 8, but the recent surge in discussions has amplified concerns among users about unforeseen data loss risks.
Paul explains that in Windows 11, especially the Pro version, encryption via BitLocker is automatically activated when users sign in with a Microsoft account. This measure is part of Microsoft's broader strategy to enhance security across its platforms.
Paul Thurott (04:30): "When you sign in with an online account to Windows 11, it encrypts the disk. You want this. This is just good security."
He emphasizes that while Windows 11 Home lacks the traditional BitLocker interface found in the Pro version, encryption remains active by default, ensuring consistent security standards across different editions.
BitLocker provides robust security by encrypting the entire disk, safeguarding user data against unauthorized access, especially in scenarios where devices might be physically compromised.
Paul Thurott (03:15): "The reason you encrypt a disk is because if the device is physically stolen and someone accesses that... they can't get at the contents of it. Right. If it's encrypted."
Paul advocates for encryption as a fundamental security practice, comparing it to encryption standards across various devices like smartphones and Macs, all of which employ similar protective measures.
A significant point of contention revolves around BitLocker recovery keys, which are essential for accessing encrypted data if standard login methods fail. Paul clarifies that these keys are securely stored in the user's Microsoft account, typically within OneDrive.
Paul Thurott (05:10): "And one of the things you can do is back up that key. You can put it somewhere else."
He demonstrates how users can access and manage their recovery keys via the Microsoft account website, ensuring they have multiple backups to prevent data loss.
Paul addresses the primary fear highlighted in the Reddit post: the potential loss of data if a user loses access to their Microsoft account. He acknowledges the scenario but downplays its likelihood, stressing that with proper key management, users can mitigate such risks.
Paul Thurott (07:00): "Telling people that they should turn off encryption because they might lose access to the data on that disk is, to me, irresponsible."
He advises users to proactively back up their recovery keys in secure locations, such as personal vaults in OneDrive, to ensure accessibility even in adverse situations.
To prevent data loss and ensure seamless access, Paul recommends the following practices:
Paul Thurott (08:15): "Your disk should be encrypted. Period."
Wrapping up, Paul firmly states that automatic disk encryption via BitLocker is a positive security advancement, aligning with industry standards across various devices and platforms. While he acknowledges that Microsoft could enhance communication around this feature, the overall benefits far outweigh the perceived drawbacks.
Paul Thurott (09:00): "This is the right thing for Microsoft to do. And for you as a user of Windows, it's the right thing for you to do."
He encourages users to embrace encryption, assuring them that with the right precautions, BitLocker enhances their data security without introducing significant risks.
Paul concludes by reaffirming the importance of staying informed about security features and best practices. He invites listeners to adopt proactive measures to safeguard their data, reinforcing the notion that encryption is a vital tool in the modern digital landscape.
Paul Thurott (09:45): "Don't fall for the fud. This is the right thing for Microsoft to do. And for you as a user of Windows, it's the right thing for you to do."
**Stay tuned for more insightful discussions on "Hands-On Windows" every Thursday on TWiT.tv.