Unsolved

This post is more than 5 years old

1 Message

973

April 14th, 2019 02:00

Encrypt XPS13 9380 Win 10 Home - upgrade to Pro / use Veracrypt / use boot password - what is the best way?

Personal laptop that is occasionally used for work. 256 SSD. My aim is making sure that the data cannot be easily extracted in case it gets lost/stolen. Advice / tips?

11 Legend

 • 

14K Posts

 • 

79.9K Points

April 14th, 2019 08:00

VeraCrypt is free, open source, and is based on TrueCrypt, which passed a formal security audit of its code with only minor issues, which have since been corrected in VeraCrypt.  So it's definitely a solid choice.  However, BitLocker takes advantage of the TPM, which means you get a "platform integrity check" at boot that doesn't occur with solutions that don't use the TPM.  Using the TPM also means you have the option of having the system encrypted without you having to enter a password at every boot, which is helpful if you want to reboot your system remotely.  Just make sure you have a strong Windows password if you do that, and you can still also choose to have BitLocker require a PIN at boot for additional security.  BitLocker is also of course part of Windows, so you're less likely to run into compatibility issues especially during upgrades to new releases of Windows 10 that arrive roughly every 6 months nowadays.  And if you happen to use disk imaging as a backup or system recovery solution, Macrium Reflect is a popular tool for this purpose and has some special support for BitLocker partitions.  Reflect has a free version, although one of the best features (BitLocker Live Restore) only works with the paid version.  You can read more about those features here if you're curious.

No Events found!

Top