Encrypting your computer: the often-overlooked protection

A laptop disappears — stolen from a car, forgotten on a train. The question that matters isn’t the machine’s price: it’s what a stranger can do with your files. Without encryption, the answer is “everything”: the session password protects nothing — the disk can be read in ten minutes from another computer. With encryption, the answer is “nothing”: the disk is just an unreadable block. This protection exists on all modern machines, often free, sometimes already active — you just need to check. Complete guide to a security that everyone forgets.

The fatal misunderstanding: session password ≠ data protection

The illusion is universal: “my computer asks for a password, my files are protected.” No — the session password only locks the “normal entry door”: an unencrypted disk removed from the machine (or booted from a USB key) can be read in full — photos, documents, tax returns, passwords saved in the browser, synced emails, everything — without ever encountering your password. It’s a trivial operation, within reach of any slightly equipped reseller. Disk encryption changes the nature of the problem: every byte written is scrambled by a cryptographic key itself protected by your password — without it, the extracted disk is just random noise, mathematically unreadable. The difference is binary: unencrypted = the thief has everything; encrypted = the thief has an object. And the cost of this protection, on modern machines with hardware acceleration, is nearly zero: no noticeable slowness, no change in usage — the computer unlocks exactly as before.

Without encryption, anyone with your laptop can access all your files. With encryption, they can’t read anything without your password. It’s like putting your files in a safe instead of leaving them on the desk.

A thief steals a laptop with an unencrypted disk. They boot it from a USB key, bypassing the login screen, and copy all files in 10 minutes. The same laptop with encryption enabled would require the thief to crack a strong password, which is nearly impossible without specialized tools.

Encrypting your computer: the forgotten protection

How to enable it on Mac: FileVault in five minutes

On Mac, the feature is called FileVault (System Settings → Privacy & Security): a toggle, and encryption runs in the background while you work — on recent Macs (Apple chips), data is already hardware-encrypted, and FileVault just links this encryption to your password: activation is almost instantaneous and has no performance impact. The crucial moment is choosing the recovery key: if you forget your password, it’s the only way out — two options: entrust it to your iCloud account (the pragmatic choice for most: recovery goes through your Apple ID), or keep a recovery key yourself — to print and store in a safe place (not in a file on the same computer!). Also check the extras: Time Machine, which backs up this encrypted disk, must also be encrypted (check “encrypt backup” when setting up the backup disk — otherwise, the unencrypted copy cancels everything out), and the session password must be worthy of what it now protects: it’s the key to the vault.

The right reflex. Check now if your disk is encrypted — two minutes: on Mac, System Settings → Privacy & Security → FileVault (enabled?); on Windows, Settings → Privacy & Security → Device Encryption, or search for “BitLocker” (enabled on C:?). Many recent machines encrypt by default… and many others don’t — especially older Windows Home editions and assembled or refurbished computers. Ten years of digital life might be walking around unprotected in your bag: knowing takes two minutes.

Encrypting your computer: the forgotten protection

How to enable it on Windows: BitLocker and device encryption

On Windows, two faces of the same protection: device encryption (enableable simply in Settings on most recent machines, linked to your Microsoft account which stores the recovery key) and full BitLocker (Pro editions and above — more options: encryption of external drives, fine-tuned key management). Activation is done in Settings → Device Encryption (or Control Panel → BitLocker): initial encryption runs in the background, the machine remains usable. The absolute point of vigilance, as always: the recovery key — Windows deposits it by default in your Microsoft account (check it’s there: account management page, devices/recovery keys section) and offers to print it: do both. This key is requested in legitimate situations (component change, firmware update, reset) — the blue screen “BitLocker recovery” that appears without the key in hand is THE nightmare scenario for technicians: perfectly healthy machines, inaccessible to their owner. Encrypting without securing your recovery key is like locking the safe and throwing away the spare keys.

The full scope: externals, USB keys, phones, cloud

An encrypted internal disk isn’t enough if copies leak elsewhere: external disks and USB keys — the classic weak link: a full backup that roams unencrypted in a drawer or bag cancels out the computer’s encryption (Mac: format/configure the disk as encrypted; Windows: BitLocker To Go) — always encrypt any storage containing a backup or sensitive documents; phones and tablets — good news: iPhones, iPads, and modern Android devices are encrypted by default as soon as a code is set (the code IS the protection: a device without a lock code is an unprotected device); the cloud — your synced documents are encrypted by major providers, but protected by… your account password: the strength of this password and its two-factor authentication are part of the scope; and the NAS or home server, often forgotten — recent models offer volume encryption: enable it at creation. The overall logic: think in copies — every place where your data lives deserves the same level of protection as the original.

A person inserts a USB drive into a laptop displaying a French-language encryption guide.
Encrypting data prevents leaks and theft.
Encrypting your computer: the forgotten protection

Warning. Encryption protects against hardware thieves — not the rest: malware running in your open session reads files like you (encryption is transparent to running programs), ransomware encrypts on top, phishing steals your cloud accounts. Encryption is a layer — essential, not sufficient: it complements backups (including one offline), updates, and vigilance, it doesn’t replace them. And solemn reminder: without password AND without recovery key, encrypted data is definitely lost — that’s the whole point of the mechanism. The backup key isn’t an administrative option: it’s half the system.

Frequently asked questions

Will encryption slow down my computer?

On machines from the last ten years, no — encryption is hardware-accelerated and runs alongside the processor: the impact is imperceptible in use. Only very old machines without acceleration might feel a difference — and even then, the trade-off heavily favors protection.

Encrypting your computer: the forgotten protection

What happens if the encrypted disk fails?

The same as with an unencrypted disk: physical failure threatens data, encrypted or not — and recovery in a lab remains possible with your keys. The real answer is upstream: backup (also encrypted) makes the question painless. Encryption and backup are the two legs — one without the other limps.

Should I encrypt the family computer that never leaves the house?

Yes — burglaries take computers, and reselling or discarding an unencrypted disk exposes everything just as much. Modern encryption costing nothing in use, the question isn’t “why” but “why not” — there’s simply no good reason to skip it anymore.

Encrypting your computer: the forgotten protection

What to remember

The session password is a door; encryption is a safe — and only the safe protects your files when the machine changes hands: theft, loss, resale, disposal. The steps: check the status (two minutes — FileVault on Mac, device encryption/BitLocker on Windows), enable if needed, and above all secure the recovery key (cloud account + printed copy in a safe place) — it will be requested one day, for sure. Then extend the scope: encrypted external disks and backups, code on all mobile devices, cloud accounts with two-factor authentication. And keep your wits about you: encryption secures lost hardware, not your open session — it adds to backups and vigilance. One hour of setup for a definitive certainty: wherever your computer ends up, your data won’t be there.

Encrypting your computer: the forgotten protection
Encrypting your computer: the forgotten protection

Doubts about your security, a device to check or clean up? Our support service guides you step by step.

Request assistance →

Commentaires

Leave a Reply

Découvrez nos autres services

ElpisIA, c’est tout un univers — explorez nos autres services.