• Konala Koala@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 days ago

    This is already looking like Microsuck is asking for a Windows 11/BitLocker based Class Action Lawsuit against them for this data lose blunder, and hopefully get their currently CEO fired.

  • Monstrosity@lemm.ee
    link
    fedilink
    English
    arrow-up
    10
    ·
    6 days ago

    Yes! This happened to me when I turned off the ‘safe boot’ on a laptop via BIOS. It locked me out but I had never agreed to install Bitlocker in the first place, let alone know what key I was supposed to have. It was a total loss & I had to wipe the drive.

    MS is hot trash.

    • Wispy2891@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 days ago

      The decryption key is saved in the Microsoft account, the error message explains that

      I also almost got a panic attack when my Lenovo updated the bios and i was locked out

      • IMALlama@lemmy.world
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        7 days ago

        Clearly you’ve never used a Mac. It wasn’t until 2024 that you could snap windows, they have a built in dark mode but the word processor that ships with their computer requires you to use a dark page template if you want black background/white text, and lord forgive you if you want to take a screenshot.

        • brbposting@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 days ago

          I think the vibe is kind of “works for grandma out of the box“, “someone in the small-but-mighty dev community made an [open-source] app for that”

          Yeah frustrates me too but seeing it as a kind of culture would probably help me be less frustrated

          Then Apple gets tiny bits of occasional flak for Sherlocking

          • IMALlama@lemmy.world
            link
            fedilink
            English
            arrow-up
            2
            ·
            5 days ago

            Apple is almost the tale of two companies.

            From the software usability perspective, they have the “it just works” reputation and that might be true if you’re doing really basic stuff. I’ve found both windows and Linux to be much more user friendly if you want to do mildly advanced things.

            Their hardware is generally pretty solid but comes at a premium, especially once you start talking about increasing RAM/SSD capacity. I have both a MacBook pro M3 pro and a Snapdragon X Elite Lenovo Yoga slim 7x. The 7x can give great battery life, but is much more inconsistent in doing so. On the other hand, the 7x has an amszing 3k OLED screen, has a removable m3 SSD, and you can upgrade to 32 GB of RAM for around $100.

            What I find interesting is that a large swath of developers have macs. I get it for some use cases (ARM emulation on ARM vs doing it on x86), but it seems like it’s a bit of a status symbol for others.

  • ArkyonVeil@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    1
    ·
    7 days ago

    I’m of the opinion that encryption based security should be compartmentalized. IE, an encrypted folder, or “safe” app. Safes in housing are already a concept that is already commonly known so it would be natural to extend a safe into the digital realm. This would also help in the idea that safes are locked with a key, so if the user loses their keys, whatever is inside the safe, might as well be lost.

    Now if EVERYTHING is a safe, (always on encryption). People will never known the difference. Its a dangerous type of security that is likely to be more a loss than a benefit.

    • ouch@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      7 days ago

      You are arguing for selective encryption, but I can’t really find any technical argument in your comment.

      Whether we are speaking of encryption at transit or rest, there’s a general consensus that encrypting everything is best in every way except possibly performance for select cases.

      For example, it allows hiding (meta)data about the really important bits, and with computers it’s really difficult to tell which bits of (meta)data could be combined to abuse. Tampering is a consideration as well.

    • michaelmrose@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 days ago

      For most folks they could just write down their encryption passphrase in a secure location with the rest of their papers since 99.9% of the risk is thieves stealing their laptops. For most folks the biggest secure item they have is the one they use constantly their browser and all the passwords it stores to all their services. You know the thing they use constantly.

      A compartmentalized approach makes sense when the laptop contains really vulnerable data like laptops which have been stolen with bunches of client data on it or a journalists communication with confidential sources etc etc. In that case you STILL want to encrypt the whole thing but you want to separately encrypt the really important stuff with a different key so that every time you open your laptop to watch cat videos on youtube you aren’t also unlocking all the data you will have to tell your companies users you lost.

    • dustyData@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 days ago

      But, houses have locks on the doors. The whole point of the house is to be a safe for people. Security is all about the threat model, your risk assessment should inform the security measures that make sense in the security/convenience continuum. Not everyone will be equally well served by the exact same risk mitigation methods.

      The point of whole disk encryption is to delay or nullify physical device control. If your disk is not encrypted, but you have a single encrypted file a bad actor wants to access. If they get physical control, then it is game over. They have all the time and power in the world to crack down that one file. Now, most people don’t have any one file(s) like that, but instead are worried about their private life in general. Without encryption, physical access to the device means total access to their entire life, the house had no locks and the thieves just waltzed in and took everything of value. Whole disk encryption is opting for a sturdier door, with better locks. Physical control is still bad, but access is orders of magnitude harder. Sure, if you lose the only key to your house, you better be prepared to break windows or walls to get in, but that is a user responsibility.

  • Not a replicant@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    7 days ago

    That’s extraordinary, even for Microsoft.

    If you’re on Win 11 Pro, up to 23H2, follow these steps to prevent 24H2:

    win+R, type GPEDIT.MSC, press enter Locate “Computer Configuration\Administrative Templates\Windows Components\Windows Update\Manage updates offered from Windows Update\Select the target feature update version”

    Now click the “Enabled” button, type “Windows 11” in the first prompt and “23H2” in the second prompt and click “Apply”

    That will prevent 24H2 from being downloaded and installed. When they’ve fixed this and the “Recall” mess, you can go back and undo the setting.

    You can still do the “bypassnro” thing, it’s just a script that’s been removed. All it did was write a registry entry and reboot. This is the registry key entry - you can still press shift-F10 at the same point and type this manually:

    reg add HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\OOBE /v BypassNRO /t REG_DWORD /d 1 /f
    shutdown /r /t 0
    

    another method to try is this, instead of the registry entry:

    start ms-cxh:localonly

    but I haven’t tried that one yet.

    • dubyakay@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      6 days ago

      I’ve fixed it by axing my bitlocker encrypted partition that contained my Pro version OS and just installed arch.

    • cute_noker@feddit.dk
      link
      fedilink
      English
      arrow-up
      6
      ·
      6 days ago

      I love how Windows fix has terminal and GUI configurations mixed as an unholy concoction directly from the HQ.

  • nek0d3r@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    13
    ·
    7 days ago

    I am LITERALLY in the process of migrating my servers to my new NixOS server after months of prep work. This couldn’t have been more timely lol Funniest part is, I just did my own TPM based encryption on my drives.

  • ipkpjersi@lemmy.ml
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    3
    ·
    7 days ago

    Windows is malware.

    I remember when Linux users used to say that, but it turns out they were right.

    I’m glad I leaved that cursed OS behind.

  • peetabix@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    6 days ago

    I had a small Win11 machine that I now have Ubuntu on. Win11 wouldn’t let me use the whole disk because of the BitLocker bullshit. I had to dig through the menus and disable it then wait hours for it to finish decrypting. Fuck Microsoft. I’m proud to say me and my GF dont have a single Microsoft product in our home, and I’m keeping that way.

  • polle@feddit.org
    link
    fedilink
    English
    arrow-up
    10
    ·
    7 days ago

    I read the article but am not smarter than before. I heard some time ago that windows does encrypt the drive but you need an active online account and the key will be saved online. So do people forget their online passwords and methods to recover that said account? I dont like m$ and am using linux, but people loosing their passwords, being uninformed about their systems and dont so backups is not the direct fault of the operating system.

    • pressanykeynow@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 days ago

      you need an active online account and the key will be saved online

      Is there a legit reason for this? Why can’t they just encrypt the data with the password used to access the online account?

      • calcopiritus@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        6 days ago

        Because then you can’t change your password. Since you would have to decrypt all the hard drives that use windows with that account, and then encrypt them again with the new one.

        This also means that if you forget your password you are fucked.

        • michaelmrose@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          6 days ago

          Typically an actual key is effectively just a very long pseaudorandom binary blob and the passphrase is just used to unlock the actual key. This means you can add a new key just by encrypting the actual key with the new passphrase

          • taladar@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 days ago

            Typically that is also the way you can use multiple accounts to unlock the same hard drive encryption. You just encrypt the actual key with each of the account passwords.

    • habitualcynic@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 days ago

      I helped my sister deal with this. Bitlocker activated itself, the keys were in her account which she had access to. She had done everything properly but nothing worked to resolve it.

      There’s countless forum posts on it since about 2021 if you go looking for it. None of the recovery processes worked so I reformatted and enabled bitlocker at the start. Next time I visit, she’s getting Linux Mint.

      Fuck Microsoft. End users shouldn’t be expected to troubleshoot like that.

    • michaelmrose@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      Setting up encryption has previously been an affirmative step wherein the user opted into being unable to access their data if they lose their password. Because of this users have the opportunity to back up their recovery key you know after they even learn what one is.

      Having it happen on upgrade to an existing machine is inherently confusing and its easy to see how it could lead to data loss.

    • InnerScientist@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      Lose access to your MS account = lose your data forever. No warnings, no second chances. Many people learn about BitLocker the first time it locks them out.

      It seems like they just got locked out of their Microsoft account (which stores the bitlocker key). Idk why they can’t just reset their password or if this article talks about the times where people couldn’t do that due to missing email access or maybe resetting the password deletes the bitlocker keys?

      Either way though, the problem is that Microsoft is forcing encryption on everyone and not properly educating them on the consequences like “Backup your decryption key if you care about the data” in a way a normal user actually listens to.

    • LoveSausage@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      7 days ago

      Just did a fresh win 11 install . In order to update bios before installing Linux. Refused to let me install without wifi but a quick googling and a command prompt later it was possible to work around easily

  • reddig33@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    7 days ago

    When are stockholders going to realize that the current Microsoft CEO is ruining Windows?

    • pressanykeynow@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      7 days ago

      They know, read their yearly financial reports. They said for a decade that Windows is not only not profitable, there’s no future for it. Microsoft for several years now is a company that sells cloud and opensource services(Linux, Github, etc).

    • freely1333@reddthat.com
      link
      fedilink
      English
      arrow-up
      4
      arrow-down
      8
      ·
      7 days ago

      Kinda joking because in many ways windows is better than ever… but also making windows have non starter features enhances Linux adoption soooo

      • OmgItBurns@discuss.online
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        7 days ago

        I’m getting daily or near daily BSODs since switch back from Debian. I was okay with Vista and 8, and maybe I’m just getting crankier as I get older, but I definitely am not a fan of the current direction Windows is taking.

        • spicehoarder@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          7 days ago

          It’s valid to feel disappointed. Windows 7 was really stable.

          My work still has a windows 7 machine with an uptime of something like 12 years.

          Windows 7 will idle in the low megabytes. But why does 11 want to use 6-8 Gigs on idle for no good reason?

          And it’s not like there’s that much difference between the two operating systems. One is just loaded up with electron wrappers and spyware

          • michaelmrose@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            6 days ago

            Windows can’t be updated in any meaningful way without being rebooted because Windows can’t overwrite a file that is in use. This makes it fairly unlikely for a machine to be up for 12 years.

            Windows 7 also doesn’t “idle in the low MBs” It uses almost 1G at least at startup more if you have apps that auto start and like every OS it caches recently accessed files.

        • freely1333@reddthat.com
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 days ago

          Better than ever in base usability as an operating system for the average person. And you can run wsl2 and have a full Linux environment too. It’s as close to a macOS user friendly experience as it has ever been without losing the windows identity.

          • spicehoarder@lemm.ee
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 days ago

            Okay, I’ll give you wsl2, and the “average user experience” being better, but Windows is losing its identity with the IT and customization front. For both destroying the win32 control panel and locking down the shell so you can no longer customize it.

            Somewhat ironically OSX recently added widgets to the desktop. Something Microsoft did years ago, removed it for no reason, and then added a flyout to tick almost the same check boxes.

            As for me, the spike in resource usage and over saturation of “AI” was enough for me to decide to jump ship.

            I’m currently attempting to daily drive Manjaro so maybe my opinion will change, but so far, it feels like home.

            • freely1333@reddthat.com
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 days ago

              Oh yeah some of the bloat is terrible and I wish the ai stuff came off by default but a lot of the issues can be handled with Chris Titus script. But to me win 11 with some tweaks feels better than anything since xp and I know I have rose tinted glasses on xp.