LUKS also only protects an online system. So why are you using it?
Oh, I think I know, if you are on Windows it's bad to use BitLocker because it's made by Microsoft and it doesn't protect against malware, but if you're on Linux of course you use LUKS, it's a sensible thing to do. Got it.
Same with MS's recall feature.
A Windows PC is just C but not P anymore.
To that customer, Bitlocker itself was a threat.
In my small sample size, I’ve seen that more often than lost laptops. I’ve also seen many more malware infections.
Tying encryption to the TPM, which is the default, makes it easier to lose those keys. With LUKS I choose my own password.
It’s an important implementation difference, especially if it is going to do it by default. Warning a person “you will lose all data if you don’t write this down” in big bold red text is sometimes not enough.
Does tying those keys to your MS account fix that failure method?
Yes. Bitlocker recovery keys are escrowed to the Microsoft account. I've relied on this recover data from a family member's PC when it failed and they had unknowingly opted-in to Bitlocker (a Microsoft Surface Laptop running Windows 10 S Mode).
Which then opens the door to other attack vectors, even government.
I’m vulnerable to the $8 wrench attack, but enjoy knowing it is only a VISA problem if I leave it a laptop the bus.
So one scenario, everyone can access the data if they get the drive. The other, the government might get Microsoft to release the encryption keys.
You are presenting a false dilemma where either Bitlocker is in use or the drive is entirely unencrypted; there are other ways to ensure data integrity in the face of physical compromise.
2. Bitlocker can totally be used without a MS account and without sending keys anywhere and without TPM... But seeing how most people fail to RTFM we're back to point 1.