In a fresh development, this doesn't affect our editorial independence. When you purchase through links in our articles, we may earn a small commission.
The report highlights that called BitLocker, it’s supposed to protect your files from unauthorized access when your PC is off or otherwise locked down. But not long ago, a security researcher discovered a loophole. Since then, I’ve been asked if BitLocker in Windows 10 or 11 Pro (and its Home license variant, “Device Encryption”) is still worth using. A lot of people don’t know Windows has built-in encryption.
Industry observers note that and, in fact, I like them best in combination with BitLocker. I still say yes—because a couple of other apps can keep sensitive files safe.
Industry observers note that part of them is stored within your motherboard (TPM) or CPU (fTPM). A second part is saved on your storage drive. And then a recovery key must be saved by the user to a removable disk, printout, or the cloud. When active, BitLocker encrypts your data within Windows with a set of keys.
According to the latest update, but always double-check it’s there—you’ll regret not having it when you need it. (Please don’t ask me how I know. I’m not over the experience yet.). For Home license users, Device Encryption typically saves a recovery key to the cloud by default.
The report highlights that someone won’t be able to tell what you have saved on there, whether tax documents, family photos, or anything else. It also prevents someone pulling the drive from your PC to read its contents through another computer. When your PC is off, its Windows data is scrambled using XTS-AES 128-bit encryption.
The report highlights that for that, you’ll need a dedicated encryption app—a.k.a., how you can sidestep the current issues with BitLocker. It does not protect your files when you’re logged into your system.
According to the latest update, for a fuller rundown of how BitLocker and Device Encryption work, check out our guide that explains how to use it.
As part of the ongoing story, the workaround gave full access to files and didn’t take much time to execute. Microsoft issued a mitigation, but not a full fix for the underlying issue. A couple of months ago, news broke of a major BitLocker vulnerability (“YellowKey”), where someone with physical access to a PC could bypass the encryption.
As part of the ongoing story, this one also involves a physical attack that allows bypassing of the encryption. Then another BitLocker vulnerability came to light in June, found by the same researcher who discovered YellowKey.
Industry observers note that no security system is foolproof, digital or physical. While these BitLocker vulnerabilities are concerning, they’re also not unexpected.
According to the latest update, the odds are more in favor them wanting to take and fence the machine, or stealing to wipe the drives and use computer themselves. (Obviously, this risk calculation changes for work PCs or if you deal in secrets, but we’re talking about most folks here.). On average, someone getting their hands on your PC for its data is less likely.
In a fresh development, it’s what I recommend even when BitLocker doesn’t look cooked, as the kids say. But for extra protection, you can use an additional encryption app for your sensitive or private files.
In a fresh development, think of it like putting a locked box within a bigger locked box. Using a separate encryption app doesn’t break or conflict BitLocker.
According to the latest update, but if you encrypt specific files with another program, those remain scrambled until you specifically unlock them. When you sign into your PC, all of your encrypted Windows data becomes accessible.
The report highlights that the other is best for creating a container to put documents in. Both are open source—a nice bonus to help vet their security strength, as anyone can see what’s in the code. Of the two free apps I recommend, one lets you create folders similar to standard ones in Windows.
According to the latest update, afterward, enter your password to gain access to it as a virtual drive. Cryptomator is easiest for most people to use—to get started, all you must do is choose a name, location, and password for your encrypted folder.
Industry observers note that it’s seamless and also works with cloud services like Dropbox, Google Drive, and OneDrive. The app handles all the work for applying the encryption (AES-256), assigning a virtual drive letter, and then mounting/dismounting the folder as a virtual drive.
In a fresh development, then create a Cryptomator folder within the app’s designated folder to secure your cloud-saved files.). (For cloud-based services, install that app in Windows.
According to the latest update, you don’t have to worry about storage management outside of your physical drive’s capacity. Another advantage of Cryptomator is that its folders expand to hold whatever amount and size of files you wish.
As part of the ongoing story, unlike Cryptomator, VeraCrypt’s interface is more advanced, with more steps and settings during setup. For example, you’ll choose your encryption algorithm. I like to use VeraCrypt for situations where stronger encryption is necessary.
In a fresh development, yes, that is a Windows 7 background. No, the interface hasn’t changed since then. A screenshot provided by VeraCrypt’s developers.
According to the latest update, for Windows users, I recommend leaving BitLocker to handle encrypting the whole of your PC’s internal drive. Create smaller containers as needed for high-security files. The bigger the size of your container, the longer it will take to decrypt, especially if you choose a very strong algorithm. You can use the app to create an encrypted container file or to encrypt a whole drive.
According to the latest update, but you can run into issues like Windows not recognizing the drives (and asking to reformat)—which is why I advise most people to just use its container files. VeraCrypt can be used to encrypt whole drives, including portable USB thumbsticks and external drives.
In a fresh development, you won’t need to go through a standard Windows install. Instead, it runs just out of a folder within Windows. Tip: To keep VeraCrypt’s presence even quieter on your PC, you can use its “portable” version.
The report highlights that it protects general files are not too personal or private. It is also a bit of defense for sensitive files that accidentally end up stored out in the open in Windows (like in temporary storage). First layer: BitLocker.
The report highlights that put tax documents, banking statements, private photos, and other files you don’t access as often in a Cryptomator folder. Remember, you can make more than one Cryptomator folder, so you can have separate ones for different types of docs, or based on frequency of use. Second layer: Cryptomator.
According to the latest update, put ultra-sensitive documents (e.g., scans of your identity paperwork) with stronger encryption in a smaller encrypted container file. You can then store a copy on a USB drive in a “go bag” or in the cloud for emergencies. Third layer: VeraCrypt.
In a fresh development, your biggest challenge: Save your passwords and any recovery keys in a secure location. Otherwise, if you lose or forget them, you’ll be locked out. (A password manager can do all the heavy lifting for you here!). Encryption and encrypting your files may sound complicated, but it’s simple once set up.
According to the latest update, since joining the team in 2016, she’s written about CPUs, Windows, PC building, Chrome, Raspberry Pi, and much more—while also serving as PCWorld’s resident bargain hunter (#slickdeals). Currently her focus is on security, helping people understand how best to protect themselves online. Her work has previously appeared in PC Gamer, IGN, Maximum PC, and Official Xbox Magazine. A 15-year veteran of technology and video platform releases journalism, Alaina Yee covers a variety of topics for PCWorld.