Does Bitlocker Full Disk Encryption Work With Intel PTT (Firmware TPM)?

Discussion in 'Windows 10' started by PolidelticusFire, Jun 18, 2021.

  1. PolidelticusFire

    PolidelticusFire MDL Addicted

    May 7, 2020
    997
    390
    30
    Since we are just 5 days away from Windows 11's official public testing, I figured I'll just reinstall official build 21390 and wait for June 24.


    Since I found that my CPU actually has TPM 2.0 functionality in the form of Platform Trust Technology (PTT), can I use this to encrypt my Windows drive?

    Also will this Full Disk Encryption cause any performance hits?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  2. BiLL86

    BiLL86 MDL Novice

    Apr 24, 2010
    29
    28
    0
    In that order: Yes you can. No if you encrypt the whole disk, not just the existing data.
     
  3. PolidelticusFire

    PolidelticusFire MDL Addicted

    May 7, 2020
    997
    390
    30
    Thanks yeah I intend to encrypt the entire SSD.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. BiLL86

    BiLL86 MDL Novice

    Apr 24, 2010
    29
    28
    0
    I wasn't very clear with the "whole disk", entire volume - your C drive - is better . The volume you encrypt can be smaller than the drive.
    BitLocker has two options: encrypt the data you have on the volume and leave the empty blocks alone. All incoming data after that will be encrypted on-the-fly effectively halving the disk performance. Or encrypt the entire volume including the empty space at once, it takes longer but has no performance impact.
     
  5. PolidelticusFire

    PolidelticusFire MDL Addicted

    May 7, 2020
    997
    390
    30
    How long would it take to Full encrypt a 500GB NVMe SSD?
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  6. BiLL86

    BiLL86 MDL Novice

    Apr 24, 2010
    29
    28
    0
    Depends on the drive, and if it has any cooling. If it doesn't it have a heatsink it will overheat and slows down.
    My Samsung PM981 (afaik an OEM 970 EVO) slowed down to 100MB/s @ 97°C and stayed there without a heatsink. With proper cooling maxing out at high fifties it did 1500MB/s.