This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…
So I lost my OpenBSD FDE password (2016)
11–20 of 77 posts
Re: So I lost my OpenBSD FDE password (2016)
#12Re: So I lost my OpenBSD FDE password (2016)
#13The BSDs and Linux have a lot of catching up to do.
Re: So I lost my OpenBSD FDE password (2016)
#14Earlier quoted context omitted.
> Solutions, that don't involve someone being an unpaid 24/7 infrastructure support tech, on a postcard please! One step at a time! 1. Back up your data. 2. Test restoring your data. 3. Automate your backups. 4. Automate your test restores. 5. Now you are ready for full-disk encryption. It is okay if you do not complete all steps. More steps is better. Do not skip ahead.
So as long as you keep your data unencrypted next to your encrypted data, you're fine. Checks out.
I may have assumed that your backups were encrypted, just because so many backup tools do it automatically. And I didn’t put that in the post. Predictably, I get some kind of jerk replying to the comment with a sarcastic jab, rather than any kind of interesting discussion.
Accidental data loss is the big risk, and for most people, it’s a bigger risk than any risk of someone reading your unencrypted data. It makes sense to start with the most serious risks (data loss), and work your way down to the minor risks (compromise).
It makes not sense to start by encrypting your data, because it significantly increases your risk of data loss, in the absence of good backups. That’s what the article is talking about.
Re: So I lost my OpenBSD FDE password (2016)
#15If you're looking for something in between, then deliberately weaker encryption might be what you want, although almost no one seems to mention that much.
Re: So I lost my OpenBSD FDE password (2016)
#16Earlier quoted context omitted.
So as long as you keep your data unencrypted next to your encrypted data, you're fine. Checks out.
I get it, it’s fun to make jabs at posts on HN. You don’t need to lean so hard into the trope. I may have assumed that your backups were encrypted, just because so many backup tools do it automatically. And I didn’t put that in the post. Predictably, I get some kind of jerk replying to the comment with a sarcastic jab, rather than any kind of interesting discussion. Accidental data loss is the big risk, and for most…
Re: So I lost my OpenBSD FDE password (2016)
#17With encryption, you always have to balance the risk of having others access to your data to that of you also potentially losing access to your data forever. In other words, is it more important that no one, not even myself, can gain access, or is it more important that I can always have access, even if that means everyone else could? I suspect for much of the data people have, they'll categorise it as the latter ins…
Re: So I lost my OpenBSD FDE password (2016)
#18This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…
Telling users that forgot their password that not only do they need to reinstall Windows, but that every single document, photo, video of their grandkids, etc. is now lost forever is untenable. At the same time, FDE is important for security, so what is a reasonable compromise? Allow some form of online recovery options (secured by the full expertise of MS security folks) by linking an account to serve as your 'IT-guy managed AD in the cloud'
Re: So I lost my OpenBSD FDE password (2016)
#19With encryption, you always have to balance the risk of having others access to your data to that of you also potentially losing access to your data forever. In other words, is it more important that no one, not even myself, can gain access, or is it more important that I can always have access, even if that means everyone else could? I suspect for much of the data people have, they'll categorise it as the latter ins…
If you're worried about something like what happens to your FDE volumes after you die, and you don't want to write down a passphrase somewhere, you could do something like pick three extremely trustworthy family members, swear them to secrecy, and give each of them one third of the passphrase.
Re: So I lost my OpenBSD FDE password (2016)
#20Earlier quoted context omitted.
I get it, it’s fun to make jabs at posts on HN. You don’t need to lean so hard into the trope. I may have assumed that your backups were encrypted, just because so many backup tools do it automatically. And I didn’t put that in the post. Predictably, I get some kind of jerk replying to the comment with a sarcastic jab, rather than any kind of interesting discussion. Accidental data loss is the big risk, and for most…
I legitimately didn't, and still don't, see how this solves the problem of less technical users losing their encryption keys.
If you encrypt your HD, you’re suddenly in a position where forgetting your key will lose all your data. It’s like walking off a cliff and hoping you can fly.
If you start by making backups and doing test restores, there’s a period of time where you are still forced to remember the key (to do the restore), but the consequences for losing it are low.