this post was submitted on 23 Jan 2026
799 points (99.5% liked)

Technology

79236 readers
2308 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] adespoton@lemmy.ca 7 points 2 days ago (1 children)

This is configurable; you can set BitLocker to always require a password on boot. If you do that, the clearkey doesn’t get placed (yet). If you set this mode, the key also doesn’t get uploaded to OneDrive. Of course, there’s a big warning when you set it up, and it recommends you print off and save the one time recovery key list.

Easier just to use an OS that doesn’t require you to jump through hoops to secure it though.

[–] FauxLiving@lemmy.world 5 points 2 days ago

You can also disable it with a Group Policy too and delete any keys that were uploaded to Microsoft with manage-bde while adding your own keys, but for the average person Bitlocker is going to be how it comes by default.

Pre-builts are even worse because that's another party who has had access to your keys and there are not laws that they would violate by keeping copies (for your convenience, of course)