| ▲ | whatevaa 2 hours ago | ||||||||||||||||||||||
Full disk encryption protects from somebody yanking a hard drive from running server (actually happens) or stealing a laptop. Calling it useless because it doesn't match your threat model... I hate todays security people, can't threat model for shit. | |||||||||||||||||||||||
| ▲ | AnthonyMouse an hour ago | parent [-] | ||||||||||||||||||||||
> Full disk encryption protects from somebody yanking a hard drive from running server (actually happens) or stealing a laptop. Both of these are super easy to solve without secure boot: The device uses FDE and the key is provided over the network during boot, in the laptop case after the user provides a password. Doing it this way is significantly more secure than using a TPM because the network can stop providing the key as soon as the device is stolen and then the key was never in non-volatile storage anywhere on the device and can't be extracted from a powered off device even with physical access and specialized equipment. | |||||||||||||||||||||||
| |||||||||||||||||||||||