After a September 24 Windows 10 update, Microsoft's BitLocker uses software encryption by default even for SSDs that offer their own hardware-based encryption
Nathaniel Mott / Tom's Hardware :
Context & Ripple Effects
BitLocker has carried a trust question since 2015, when Microsoft declined to directly answer whether the encryption had backdoors (its carefully worded answers) and was later shown uploading Windows 10 disk encryption keys to its own servers (the key-upload report). The September 24 update adds a new wrinkle: on machines with self-encrypting SSDs, Windows now ignores the drive's hardware crypto and encrypts in software by default.
The change fits a recent pattern of Microsoft quietly rewriting Windows 10 defaults — earlier this year it flipped the external-drive removal policy from 'Better performance' to 'Quick removal' — leaving users and admins to discover behavior shifts after patching rather than through documented change notes.
First-order effects
- Users and IT departments whose SSDs were relying on the drive's own hardware encryption are now silently running software-based BitLocker instead, changing performance characteristics and requiring a manual policy change or re-encryption to restore hardware crypto.
Second-order effects
- SSD makers' built-in self-encryption becomes a feature buyers can no longer assume Windows will use, weakening one of the differentiators hardware vendors advertise to enterprise customers.
Third-order effects
- If Microsoft keeps shipping security-relevant default changes inside routine updates, enterprises will need to treat every Windows patch as a potential configuration change and audit encryption posture after deployment — extending the scrutiny the 2015 key-storage reporting already forced onto BitLocker.
The trend: Microsoft is consolidating control over Windows security defaults at the OS layer, even where third-party hardware already provides the capability.