9 ms·
To me, it is a feature to have a password required at boot to unlock the drive. Relying on TPM for keymatter is convenient but comes with caveats I don't like.
by jchw 4d ago
To me, it is a feature to have a password required at boot to unlock the drive. Relying on TPM for keymatter is convenient but comes with caveats I don't like. I don't personally trust that the boot chain and OS on a modern system are secure enough for this model to be similarly secure to using a passphrase properly. And if I care enough to try to secure something in this way, I definitely care enough to pick something that I believe would be at least truly secure at rest with a decent degree of certainty.
TPM based unlock does at least still fulfill the goal of ensuring data stored to disk is encrypted so that it can't easily be recovered from a discarded drive.
- doubled112 4d agoI am using Tang and Clevis without a TPM on an Orange Pi 5. The key is stored on my Tang server. No TPM required. It is either on my LAN with that server available, or you will need to enter a key. It am only trying to prevent casual snooping if it goes missing from my garage though. Anybody more sophisticated can have my garage YouTube browsing history.
- irusensei 4d agoThis. I'm not fighting against a state level actor. My concern is some crackhead burglar stealing my stuff and then my personal data ending up in the hands of whoever buys the stolen goods.
- doubled112 4d agoExactly. Disk encryption simplifies a stolen device to a VISA problem. As in, no problem, I will just buy another one. At these RAM and storage prices, maybe not.