MS Ransomware -> Windows 11 24H2 BitLocker

Discussion in 'Windows 11' started by naxal, Nov 21, 2024.

  1. naxal

    naxal MDL Member

    May 15, 2014
    134
    28
    10
    BitLocker drive encryption is turned on by default in Windows 11 24H2 and there is no warning or information given to the user about it.

    Down the line, in future,

    * in case Windows Fails
    * or for any other reason and user do a fresh install
    * or for any reason wish to switch Operating system
    * or wish to detach a storage drive and plug it in another Computer

    -> all the data in those disks are now gone.

    You can't read data from any of your disk now unless you are booting up from that same PC and with the same Windows 11 installation instance, in which the encryption happened.

    This is like a Ransomware, no warning or information is given to the user about backing up their Encryption key.

    Users are expected to be born aware of this feature and potential risks of it.

    Stupid decision
     
  2. endbase

    endbase MDL Guru

    Aug 12, 2012
    4,694
    1,717
    150
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Dark Dinosaur

    Dark Dinosaur X Æ A-12

    Feb 2, 2011
    4,150
    5,947
    150
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  4. whitestar_999

    whitestar_999 MDL Addicted

    Dec 9, 2011
    737
    328
    30
    It is not possible to bitlocker encrypt a drive without saving its recovery key first.
    upload_2024-11-25_10-2-29.png
     
  5. MG86

    MG86 MDL Junior Member

    Jul 26, 2024
    53
    10
    0
    BitLocker is close-to-metal and does a great job encrypting data without causing performance loss, but it has some issues. Home edition of 24H2 automatically encrypts 24H2 with BitLocker key and sends it to Microsoft account unless you perform OOBE NRO Bypass. In other editions, you are forced to save BitLocker key before drive can be encrypted, but you can't save it onto drive you want to encrypt and you can't save it onto drive that is already encrypted. A way around that is to create an encrypted container file in VeraCrypt, mount it, and save BitLocker key onto mounted container.
     
  6. sebus

    sebus MDL Guru

    Jul 23, 2008
    6,384
    2,037
    210
    That is insane!
     
  7. sajtoskenyér

    sajtoskenyér MDL Novice

    Apr 2, 2024
    1
    1
    0
    #7 sajtoskenyér, Dec 22, 2024 at 09:31
    Last edited: Dec 24, 2024 at 09:30
    OP is talking about Device Encryption, right?

    Bitlocker Drive Encryption was 'ready' or something on my Windows 11 (fresh ESD install, Education, build 26100.2605), meaning if i log in to my MS Acc, then it will encrypt the drive, giving me an online stored key for decryption.
    Since i use local accounts all the time, this didnt happen.

    But Device Encryption (in Settings->Privacy&security) was enabled by default, without notifying me about anything. Thats the OP situation, if i'm understanding this correctly.
    So if things go sideways, and lets be honest, with Windows, they do, then i have no way of getting my data back, right?
    (I did turn this off for now.)

    Please enlighten me with some info, am i seeing this correctly?
    Thanks.
     
  8. haber123

    haber123 MDL Junior Member

    Nov 5, 2009
    93
    43
    0
    Why would anyone want this? Think of the average user. Forced to setup a Microsoft account with no intent on using it. Lets switch windows back to a local account so its like it used to be. Years of collecting, gigs of highly organized data. What can go wrong? Then it does. Keep it simple, much easier to get back. Who is encrypting your PC protecting you from? If I had worldly secrets on my PC, maybe, but I would use TrueCrypt, or a similar program that I control. And i certainly wouldn't put the key out on the cloud. Encryption should be a choice not mandated. Besides it does nothing to protect a running PC where the trojan just got your browser user name/password list. So why would anyone make recovery more difficult or impossible?
     
  9. haber123

    haber123 MDL Junior Member

    Nov 5, 2009
    93
    43
    0
    My script is similar to Dark Dinosaur's, but one step further, in secpol, local policies, security options, accounts: block Microsoft accounts, change to "users cant add or logon on with Microsoft accounts".
     
  10. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,252
    1,149
    60
    I decrypt and disable bitlocker after clean setup and then I disable everything like you do, but probably windows update enabled bitlocker again and when BDESVC is disabled, bitlocker can not be disabled and it will be hidden in Settings.
     

    Attached Files:

  11. Terepin

    Terepin MDL Senior Member

    Sep 19, 2012
    286
    73
    10
    MS can't encrypt anything if CPU virtualization is disabled. :p
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...