BitLocker does this much better. With TPM+PIN mode, the TPM will only decrypt the volume master key if all the right hashes are in the platform configuration registers for the BIOS, option ROMs, MBR, filesystem headers and bootloader, and the user-specified PIN is correct. Or if you enter the 128-bit recovery key. The BSDs and Linux have a lot of catching up to do.
So I lost my OpenBSD FDE password (2016)
21–30 of 77 posts
Re: So I lost my OpenBSD FDE password (2016)
#22Earlier quoted context omitted.
If you're worried about something like what happens to your FDE volumes after you die, and you don't want to write down a passphrase somewhere, you could do something like pick three extremely trustworthy family members, swear them to secrecy, and give each of them one third of the passphrase.
Guaranteed one of them will lose a piece
Re: So I lost my OpenBSD FDE password (2016)
#23BitLocker does this much better. With TPM+PIN mode, the TPM will only decrypt the volume master key if all the right hashes are in the platform configuration registers for the BIOS, option ROMs, MBR, filesystem headers and bootloader, and the user-specified PIN is correct. Or if you enter the 128-bit recovery key. The BSDs and Linux have a lot of catching up to do.
So if your motherboard needs to be replaced you can't recover your data? Nice!
Re: So I lost my OpenBSD FDE password (2016)
#24Earlier quoted context omitted.
If you're worried about something like what happens to your FDE volumes after you die, and you don't want to write down a passphrase somewhere, you could do something like pick three extremely trustworthy family members, swear them to secrecy, and give each of them one third of the passphrase.
Guaranteed one of them will lose a piece
Re: So I lost my OpenBSD FDE password (2016)
#25Earlier quoted context omitted.
I legitimately didn't, and still don't, see how this solves the problem of less technical users losing their encryption keys.
Because it gives you a longer period of time to learn the keys without consequences if you forget. If you encrypt your HD, you’re suddenly in a position where forgetting your key will lose all your data. It’s like walking off a cliff and hoping you can fly. If you start by making backups and doing test restores, there’s a period of time where you are still forced to remember the key (to do the restore), but the conse…
Re: So I lost my OpenBSD FDE password (2016)
#26correct horse battery staple something something
Re: So I lost my OpenBSD FDE password (2016)
#27Earlier quoted context omitted.
Because it gives you a longer period of time to learn the keys without consequences if you forget. If you encrypt your HD, you’re suddenly in a position where forgetting your key will lose all your data. It’s like walking off a cliff and hoping you can fly. If you start by making backups and doing test restores, there’s a period of time where you are still forced to remember the key (to do the restore), but the conse…
Yeah I don't think this would help my mother.
Encryption is designed to make data difficult to access, so it makes sense to consider backups and encryption jointly. I don’t understand why someone would consider this controversial.
Re: So I lost my OpenBSD FDE password (2016)
#28BitLocker does this much better. With TPM+PIN mode, the TPM will only decrypt the volume master key if all the right hashes are in the platform configuration registers for the BIOS, option ROMs, MBR, filesystem headers and bootloader, and the user-specified PIN is correct. Or if you enter the 128-bit recovery key. The BSDs and Linux have a lot of catching up to do.
Stop putting every BSD in the same basket.
Also, this is Unix, you can put encrypted slices/partitions with ease. You can omit to encrypt the system files and encrypt the data and config partitions.
But FDE avoids tampering.
Re: So I lost my OpenBSD FDE password (2016)
#29This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…
>trying to encourage less technical users to be secure The threat of “losing the keys to all the data” is considerably larger than the threat of having your computer and data stolen for an average home user. It can’t just be a matter of more secure is better… you have to have an idea of what you’re trying to prevent. All of our shit has been lost in one leak or another so at this point it seems like it barely matters…
If you're already in my bedroom, I've got bigger problems than my family photos.
If I leave my laptop on the bus, it's a VISA problem.
This isn't for everybody, but it's probably the safest my family can be.
Re: So I lost my OpenBSD FDE password (2016)
#30BitLocker does this much better. With TPM+PIN mode, the TPM will only decrypt the volume master key if all the right hashes are in the platform configuration registers for the BIOS, option ROMs, MBR, filesystem headers and bootloader, and the user-specified PIN is correct. Or if you enter the 128-bit recovery key. The BSDs and Linux have a lot of catching up to do.
So if your motherboard needs to be replaced you can't recover your data? Nice!