BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Server/laptop full-disk encryption
- Subject: [Discuss] Server/laptop full-disk encryption
- From: bogstad at pobox.com (Bill Bogstad)
- Date: Wed, 1 Oct 2014 23:32:28 +0200
- In-reply-to: <20141001184430.GC14633@dragontoe.org>
- References: <fb73f4b8a491577a02de5fcaf7779293.squirrel@webmail.ci.net> <de529929c36240babe4229ad818da975@CO2PR04MB684.namprd04.prod.outlook.com> <542B5DBC.2090805@horne.net> <9c6cf155f2b6480985a30ea427dae562@CO2PR04MB684.namprd04.prod.outlook.com> <CAJFsZ=rK+pys68ysVGw5Hs4gxv2oQhjh+_y271bxSsdc_n=bvA@mail.gmail.com> <20141001184430.GC14633@dragontoe.org>
On Wed, Oct 1, 2014 at 8:44 PM, Derek Martin <invalid at pizzashack.org> wrote: > On Wed, Oct 01, 2014 at 01:41:43PM +0200, Bill Bogstad wrote: >> Unlike on-line data thieves who can automate their data collection >> to attack thousands, actually retrieving data from you stolen laptop >> will take significant human effort on their part. > > Unless it doesn't. If the attacker knows you and knows you have "a > lot" of money in the bank and/or your banking habits, or knows that > you are someone who has access to, say, a large number of people's > credit card info, and has reason to believe that data is on your > laptop, you may be specifically targeted. The latter is unlikely for > most of us, but I suspect most of us could fall into the former > category. And we are back to what is your threat model and potentially "rubber hose" key retrieval. Or for that matter, if you have a "lot of money" do you have paper copies of your financial statements and if so do you keep them in a locked safe? And what about someone setting up a spy camera in your home/favorite coffeee shop, so they can record you typing your password/key before they steal your laptop. Where does it all end? While I agree that there are cases where maximal security is warranted;once you are being explicitly targeted, so many other possibilities are opened up for the attacker that it isn't obvious that better encryption is the best way to reduce your risk. Perhaps you should take self defense classes instead... Bill Bogstad
- References:
- [Discuss] Server/laptop full-disk encryption
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] Server/laptop full-disk encryption
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] Server/laptop full-disk encryption
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] Server/laptop full-disk encryption
- Prev by Date: [Discuss] Need speaker and topic for October BLU meeting
- Next by Date: [Discuss] Shellshock
- Previous by thread: [Discuss] Server/laptop full-disk encryption
- Next by thread: [Discuss] Server/laptop full-disk encryption
- Index(es):