Bitlocker To Go help


very_452001

Member
Local time
10:44 AM
Posts
101
OS
Windows 11
Hi,

Does Bitlocker use the same recovery key for both the Internal fixed hard drive and external USB drives or they get a separate recovery key each after encryption?

Lets say I encrypt a exFat USB Flash Pen Drive with Bitlocker To Go. Can I use that encrypted USB drive on another/system or computer such as MAC, Linux or another Windows Home OS and decrypt it on that another system by just entering my password or do I need to import recovery keys on that system to recognise the usb drive or it wont work at all or only works on Windows Pro OS or only on my system/computer (not portable)?

Thanks,
 
Windows Build/Version
Windows 11 Pro

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
Each volume will have it's own recovery key including B2G
 

My Computer

System One

  • OS
    Windows 11
Each volume will have it's own recovery key including B2G

Okay as long I don't forget the password then I don't need the recovery key basically yeah?

Ok what about using B2G encrypted USB drives on other computers apart from my own? The other computers, macs, linux systems has to have Bitlocker installed on them to recognise my bitlocker encrypted usb drive and can be decrypted just by a password, no need to import recovery keys?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
The password is sufficient to decrypt on any OS. There are tools available to mount Bitlocker encrypted drives including B2G
 

My Computer

System One

  • OS
    Windows 11
The password is sufficient to decrypt on any OS. There are tools available to mount Bitlocker encrypted drives including B2G

Which encryption Algorithm you recommend to go with in B2G that has the best compatibility and is the fastest for external drives?

So what Tools do I need and if those other computers/systems don't have these tools then you saying I cant mount my encrypted external drives on those other systems? Does Apple Mac for example support Microsoft Bitlocker?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
Hi can anyone please advise to my last post?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
Nothing could go wrong with any of the encr. algorithms.
As for "the fastest" - do your own benchmarks. I guess nobody will ever have cared since BL2Go is a niche product and no longer supported.
I don't think switching from (default) "XTS_AES128" to "aes128" will make a difference.
 

My Computer

System One

  • OS
    Win11
As for "the fastest" - do your own benchmarks. I guess nobody will ever have cared since BL2Go is a niche product and no longer supported.
Hi you mean BL2Go is obsolete no longer supported by Microsoft?
So will I be able to mount a BL2Go Encrypted USB drive on a Linux system & a Mac system?
I don't think switching from (default) "XTS_AES128" to "aes128" will make a difference.
XTS is exclusive to Bitlocker?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
AES XTS is not unique to Bitlocker or Microsoft. It is an IEEE standard. Bitlocker To Go is not unsupported either. I can't speak to Mac but on Linux you can use dislocker to mount bitlocker encrypted volumes.
 

My Computer

System One

  • OS
    Windows 11
I believe that there may have been some confusion in earlier posts between the very similar terms "Windows To Go" and "BitLocker To Go". It is true that "Windows To Go" is no longer supported, however "BitLocker To Go" is very much supported!

BitLocker To Go is the term used when BitLocker is used to encrypt external storage such as a USB HDD, SSD, or flash drive.

By default, BitLocker will encrypt your drive using XTS-AES 128 encryption. I would suggest leaving this as is unless you have a very specific reason to change it.

As for speed, this should be VERY fast because on any modern hardware, BitLocker uses the hardware encryption capabilities of your CPU.

I have a very fast thumbdrive on which I have BitLocker enabled and I can easily WRITE to that drive, while encrypting the data with BitLocker, at around 550 MB/s.

On other Windows machines, you need no utilities whatsoever to decrypt the drive - the capability to read from a BitLocker encrypted drive is baked into the OS. Just supply the password. I have no experience trying to use a drive encrypted with BitLocker on any other OS (I am a Windows only kind of guy), so I'll leave answers to that question to others .

EDIT: A quick web search tells me that at least on a MAC, third-party utils are available:

"Since BitLocker is not natively supported on macOS, you’ll need to download a third-party application called macOS BitLocker Reader."
 

My Computers

System One System Two

  • OS
    Win11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-11700K
    Motherboard
    ASUS Prime Z590-A
    Memory
    128GB Crucial Ballistix 3200MHz DRAM
    Graphics Card(s)
    No GPU - CPU graphics only (for now)
    Sound Card
    Realtek (on motherboard)
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 1TB NVMe Gen 4 x 4 SSD
    1 x 2TB NVMe Gen 3 x 4 SSD
    2 x 512GB 2.5" SSDs
    2 x 8TB HD
    PSU
    Corsair HX850i
    Case
    Corsair iCue 5000X RGB
    Cooling
    Noctua NH-D15 chromax.black cooler + 10 case fans
    Keyboard
    CODE backlit mechanical keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    Additional options installed:
    WiFi 6E PCIe adapter
    ASUS ThunderboltEX 4 PCIe adapter
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
On other Windows machines, you need no utilities whatsoever to decrypt the drive - the capability to read from a BitLocker encrypted drive is baked into the OS. Just supply the password. I have no experience trying to use a drive encrypted with BitLocker on any other OS (I am a Windows only kind of guy), so I'll leave answers to that question to others .

Okay many thanks. To confirm it will work on any windows that are not the 'Pro' versions? I ask because you only find Bitlocker in Pro versions of windows.

Work on Windows XP and Windows 7?
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
I know for a fact that you can read a BitLocker encrypted drive even on the Home edition. My guess is that you can probably write to it as well, but that you simply cannot initialize a drive with BitLocker on the Home edition. You will have to test that to confirm.

As for XP and Win 7, maybe someone else can comment. Since Windows 7 and XP are long dead OSes (even extended support for 7 is gone), I put zero effort into looking for solutions on either of those OSes :-).
 

My Computers

System One System Two

  • OS
    Win11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-11700K
    Motherboard
    ASUS Prime Z590-A
    Memory
    128GB Crucial Ballistix 3200MHz DRAM
    Graphics Card(s)
    No GPU - CPU graphics only (for now)
    Sound Card
    Realtek (on motherboard)
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 1TB NVMe Gen 4 x 4 SSD
    1 x 2TB NVMe Gen 3 x 4 SSD
    2 x 512GB 2.5" SSDs
    2 x 8TB HD
    PSU
    Corsair HX850i
    Case
    Corsair iCue 5000X RGB
    Cooling
    Noctua NH-D15 chromax.black cooler + 10 case fans
    Keyboard
    CODE backlit mechanical keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    Additional options installed:
    WiFi 6E PCIe adapter
    ASUS ThunderboltEX 4 PCIe adapter
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
I would say it might work in XP or 7 but only with the older AES encryption methods. XTS-AES is definitely not supported even in Windows 8/8.1 I believe. My reply to questions about EoL operating systems will very repetitively be "Upgrade to a supported OS"
 

My Computer

System One

  • OS
    Windows 11
@neemober caused me to recall something I am embarressed to have forgotten about:

If you BitLocker encrypt a drive on current versions of Windows 10 or any version of Windows 11, one of the screens you get is this:

Image5.jpg

So, neemober is 100% correct. XTS-AES is only suitable for current versions of Windows, but the good news is that if you encrypt using the wizard, it will give you a choice as the above screen clearly shows. You may want to test this, but I would think that you would be good to go if you choose this option. I tried this and I see that the method used to encrypt with this option is AES 128.


Image6.jpg
 

My Computers

System One System Two

  • OS
    Win11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-11700K
    Motherboard
    ASUS Prime Z590-A
    Memory
    128GB Crucial Ballistix 3200MHz DRAM
    Graphics Card(s)
    No GPU - CPU graphics only (for now)
    Sound Card
    Realtek (on motherboard)
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 1TB NVMe Gen 4 x 4 SSD
    1 x 2TB NVMe Gen 3 x 4 SSD
    2 x 512GB 2.5" SSDs
    2 x 8TB HD
    PSU
    Corsair HX850i
    Case
    Corsair iCue 5000X RGB
    Cooling
    Noctua NH-D15 chromax.black cooler + 10 case fans
    Keyboard
    CODE backlit mechanical keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    Additional options installed:
    WiFi 6E PCIe adapter
    ASUS ThunderboltEX 4 PCIe adapter
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
...confusion in earlier posts between the very similar terms "Windows To Go" and "BitLocker To Go". It is true that "Windows To Go" is no longer supported, however "BitLocker To Go" is very much supported!
Exactly, sorry for the confusion. Windows2Go is no longer supported and thus, bitlocking Windows2Go as well, while Bitlocker2Go remains supported. Of course, Windows2Go still works, even with newer windows versions there are ways to set it up and I still use it myself.
 

My Computer

System One

  • OS
    Win11
Is AES much slower than XTS-AES?

Most computers around the world still using windows XP or Windows 7.
 

My Computer

System One

  • OS
    Windows 11
    Computer type
    Laptop
    Manufacturer/Model
    HP Victus 15-fa1006na
As said, for compatibility, you should use the compatible mode, as depicted. Since you want it to work on older OS', you have no choice.
 

My Computer

System One

  • OS
    Win11
Is AES much slower than XTS-AES?

Most computers around the world still using windows XP or Windows 7.
As Comport Colin noted, you really have no choice if you want to be compatible with older OSes. That said, as I noted before, speed is not an issue anyway. Encryption is done in hardware these days so speed is not any issue.

Also, asserting that "Most computers around the world still using windows XP or Windows 7" is pure fiction. Not even anywhere near reality. Here is the current market share (as of February 2024). Note that some sources may give slight variations to this, but this is a good ballpark:

Windows 10: 66.45%
Windows 11: 27.83%
Windows 7: 3.06%
Windows 8.1: 1.74%
Windows XP: 0.57%
Windows 8: 0.26%
 

My Computers

System One System Two

  • OS
    Win11 Pro 23H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Home Built
    CPU
    Intel i7-11700K
    Motherboard
    ASUS Prime Z590-A
    Memory
    128GB Crucial Ballistix 3200MHz DRAM
    Graphics Card(s)
    No GPU - CPU graphics only (for now)
    Sound Card
    Realtek (on motherboard)
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 1TB NVMe Gen 4 x 4 SSD
    1 x 2TB NVMe Gen 3 x 4 SSD
    2 x 512GB 2.5" SSDs
    2 x 8TB HD
    PSU
    Corsair HX850i
    Case
    Corsair iCue 5000X RGB
    Cooling
    Noctua NH-D15 chromax.black cooler + 10 case fans
    Keyboard
    CODE backlit mechanical keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    Additional options installed:
    WiFi 6E PCIe adapter
    ASUS ThunderboltEX 4 PCIe adapter
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor

Latest Support Threads

Back
Top Bottom