Earlier quoted context omitted.
I am too, not sure why you are being downvoted. I'm interested in finding out what a "landmark style" influenced by using gimp instead of photoshop looks like exactly.
He is being down voted because the first comment of this throwaway account is a boorish redditism asked to someone who just said they value client confidentiality.
Ask HN: Do you encrypt your laptop's hard disk?
101–110 of 135 posts
Re: Ask HN: Do you encrypt your laptop's hard disk?
#102First off, I'd like to throw Bitlocker back in the ring and tell you that boot volume encryption is relatively unimportant for the threat model you propose, specifically untargeted data at rest. Boot volume encryption/verification is designed to protect you against attackers who would replace your boot image with a one that contains a rootkit or keylogger. This threat model requires serious forethought and planning o…
I don't agree with the above. If we're talking about Windows, it's not "boot volume encryption" but the "C: disk encryption" that you have to worry about even if the attack scenario is data at rest. If you don't encrypt C: disk every forensic worker will trivially recover a lot of material that you'd believe was encrypted on another partition. If we're talking about Linux where you configured /boot unencrypted and ev…
I'm not advocating against "full" disk encryption. That's what I use. I just wanted to say that the OP doesn't need boot volume verification and that Bitlocker is sufficient for his needs.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#103First off, I'd like to throw Bitlocker back in the ring and tell you that boot volume encryption is relatively unimportant for the threat model you propose, specifically untargeted data at rest. Boot volume encryption/verification is designed to protect you against attackers who would replace your boot image with a one that contains a rootkit or keylogger. This threat model requires serious forethought and planning o…
> boot volume encryption is relatively unimportant for the threat model you propose, specifically untargeted data at rest. I'll have to respectfully disagree here. Windows has heaps of different ways of caching all kinds of information outside of your home folder. Individual applications can also cache stuff wherever permissions allow (and often do). Realistically with Windows if you're going to encrypt you want to e…
At some point, some partition somewhere will need to be unencrypted, otherwise the system cannot boot, since the decryption programs are typically too large for a single boot sector.
I'm not advocating against "full" disk encryption. That's what I use. I just wanted to say that the OP doesn't need boot volume verification and that Bitlocker is sufficient for his needs.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#104First off, I'd like to throw Bitlocker back in the ring and tell you that boot volume encryption is relatively unimportant for the threat model you propose, specifically untargeted data at rest. Boot volume encryption/verification is designed to protect you against attackers who would replace your boot image with a one that contains a rootkit or keylogger. This threat model requires serious forethought and planning o…
Assuming of course that all the data that you wish to protect is on your data partition, and that no protected data is, was, or ever will be on any other partition. Full disk encryption removes the possibility of exposure of protected data showing up on non-encrypted partitions. With most operating systems, I don't think that there is a way to ensure that no protected data will ever end up on a non-protected partitio…
I'm not advocating against "full" disk encryption. That's what I use. I just wanted to say that the OP doesn't need boot volume verification and that Bitlocker is sufficient for his needs.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#105I would be much more concerned about laptop being arbitrarily seized at an airport by customs or TSA personnel, or by law enforcement otherwise, than it being stolen per se. e.g. http://www.daniweb.com/news/story218174.html http://ezinearticles.com/?Business-Travel-Tip---Avoid-Having... http://www.businesstravelnews.com/Business-Travel/Travel-Man... You can lose a lot to thieves, but you can lose even more to state t…
You know, if you disagree, you can reply instead of downvoting.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#106First off, I'd like to throw Bitlocker back in the ring and tell you that boot volume encryption is relatively unimportant for the threat model you propose, specifically untargeted data at rest. Boot volume encryption/verification is designed to protect you against attackers who would replace your boot image with a one that contains a rootkit or keylogger. This threat model requires serious forethought and planning o…
There is no such thing as full disk encryption, at least in the "full" sense of the term. There will be some unencrypted partition somewhere that boots the OS. TPM is designed to verify that this partition has not changed from a trusted configuration. I wanted to say that OP does not need this level of security, which is why Bitlocker is a viable and free and fast solution for him to use. (And the security current implementations of TPM provide are questionable right now.)
Applications should not be allowed to write to this partition without elevated privileges. The OS shouldn't be writing to this during normal operation either. Sensitive data should not be put on this partition, and as far as I have heard, Windows has not done anything like this.
When I say "data", what I refer to is the C: drive. With Bitlocker and Truecrypt, the C: drive is encrypted. The Users folder should be encrypted. All the bazillions of temp directories should be encrypted. The hibernation file is encrypted. Even Program Files is encrypted.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#107Earlier quoted context omitted.
Regarding the NSA, "who knows", it's not worth any time to speculate. I tend to think the answer here is "no", but not because of any fundamental problem with the algorithms TC uses; rather, I assume there's a small battery of implementation errors NSA can exploit that private industry hasn't yet independently discovered. Fortunately for our collective sanity, if it is the case that NSA has (several times over) the m…
Regarding the FBI, "almost certainly yes" You need to add "assuming you are willing to go to jail" because a warrant can compel you to disclose your password, and if you refuse you'll be jailed for contempt of court.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#108Not meaning to be a jackass but realize that maybe if you downloaded (and maybe already deleted!) that porn video with that girl that might or not might be 18 you could be in big troubles if you don't have your full disk encrypted. Edit: or other things that would be ok but can be used against you by law enforcement, for example what about your collection of pirated MP3s or DivX? Is this more acceptable than accident…
Also, I remember I have read an article about some guy that had some pics of their little childrens sometimes naked in an "innocent" way on a trip. They had their children taken away because they went to a photo shop to have the film developed and the clerk called the police.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#109Before you dive too far into full-disk encryption, you might want to contemplate the consequences of this research: http://news.cnet.com/8301-13578_3-9876060-38.html The paper referenced is available at: http://citp.princeton.edu/pub/coldboot.pdf From that paper, the most salient sentence for this discussion is: "On all of our sample DRAMs, the decay rates were low enough that an attacker who cut power for 60 seconds…
Remanence isn't a realistic attack in his threat model; attackers have mere minutes to get the RAM out of his system, cool it, and siphon the data off. If he's worried about losing the Plans to the Empire when his ship is captured, sure. But if he leaves his bag in the back of a cab, he'll be fine. The notion that any "reasonably good tech thief" could pull this off is also hard to take seriously. So far as I know, t…
But, for the sake of argument, let's say that they don't crack it on the first go. So what? The password has to be in RAM every time the machine starts. AFAIK (and I would be pleased to be wrong about this), nobody shreds data on the hard drive because the user gets their password wrong. So, said bad guys can try to their heart's content.
As far as I'm concerned, it is a major hole in any argument for full-disk encryption.
Re: Ask HN: Do you encrypt your laptop's hard disk?
#110I don't encrypt a bit — I even got no login password. I've got all my stuff on a 50GB Dropbox, so if I lose my MBP I'll just sync a new machine. Don't have anything of particular importance on my drive: design PSDs (could be secret), stock resources (icon packs, graphical elements), my music and a inspirational folder.
I do the same (happy 50GB Dropbox user). I haven't researched this, but is it possible to remotely delete a Dropbox drive? I.e. if my laptop is stolen, to use the site to wipe the data from the laptop? I assume it's possible.
From https://www.dropbox.com/account#manage (pressing "unlink"): "[The unlinked] computer will no longer stay in sync, but it will keep a copy of any file it currently has."