Live data from Hacker News

So I lost my OpenBSD FDE password (2016)

words.filippo.io

41–50 of 77 posts

Re: So I lost my OpenBSD FDE password (2016)

#41
post #36
post #31

Earlier quoted context omitted.

As much as I adore my Yuibikey, my girlfriend thinks I’m decidedly weird because I have two: one on my actual keys, and a backup that’s in my safe at home. Which is annoying because not every system lets me setup two Yubikeys (though TOTP is fine at least). I’m not using it for FDE, but I am using it for securing my password manager (which does support both keys) which holds the backup keys for said FDE and so on.

Name and shame sites that don't support using multiple Yubikeys! I'm pretty sure they're violating the guidelines in the standard if they do that.

I think AWS is still the only one I know of doing that, or did they finally fix that?

Yup, just checked, they still are.

Re: So I lost my OpenBSD FDE password (2016)

#42
post #39
post #37

This is one the main problems with our approach to information security: we disproportionately prioritize protection of our data against theft/law enforcement/rogue bigtech employee over losing it in any other way. That's why many have lost their thousands of bitcoins, because they secured their keys so hard against theft that their data has eventually become unrecoverable despite that there'd be no thief, officer, r…

I skimmed back the article after reading this comment, and I'm still not really sure how this follows. Of course you should always make redundant backups with parameters suitable for however much assurances you want to have that you will not lose data. However, I dunno if there's any particular evidence to suggest that data loss is the main concern here. I mean, I have a backup strategy for most of my data, but I'd c…

Yeah my comment's tangential to the article. The problem there is that there is an FDE password in the process of securing your data that you can't backup reliably (Filippo misspelled the password). This would have caused the loss of an entire RAID drive for anyone, not for Filippo in this case obviously. Such a basic UX problem causes catastrophes.

Microsoft avoids that by backing up your key (not password) to a USB drive or even cloud first. There's no typo issue. There's no forgotten password issue.

Re: So I lost my OpenBSD FDE password (2016)

#43
post #31

Earlier quoted context omitted.

I am sitting on a 12TB array after my move I just can't come up with the combination... However, there are better options for users - how about Smartcards? You know, like yubikey / U2F before the web? You can even use it with LUKS

As much as I adore my Yuibikey, my girlfriend thinks I’m decidedly weird because I have two: one on my actual keys, and a backup that’s in my safe at home. Which is annoying because not every system lets me setup two Yubikeys (though TOTP is fine at least). I’m not using it for FDE, but I am using it for securing my password manager (which does support both keys) which holds the backup keys for said FDE and so on.

The issue I have is that the second key can't really sit in the safe all the time because everytime you setup new service, it needs to be taken out and added.

Re: So I lost my OpenBSD FDE password (2016)

#44

Earlier quoted context omitted.

>trying to encourage less technical users to be secure The threat of “losing the keys to all the data” is considerably larger than the threat of having your computer and data stolen for an average home user. It can’t just be a matter of more secure is better… you have to have an idea of what you’re trying to prevent. All of our shit has been lost in one leak or another so at this point it seems like it barely matters…

My happy medium is encrypted PCs that sync everything onto my unencrypted home server. If you're already in my bedroom, I've got bigger problems than my family photos. If I leave my laptop on the bus, it's a VISA problem. This isn't for everybody, but it's probably the safest my family can be.

This is not great from a robbery point of view or a disposal point of view.

Syncing to a cloud service would be better.

Re: So I lost my OpenBSD FDE password (2016)

#45
post #37

This is one the main problems with our approach to information security: we disproportionately prioritize protection of our data against theft/law enforcement/rogue bigtech employee over losing it in any other way. That's why many have lost their thousands of bitcoins, because they secured their keys so hard against theft that their data has eventually become unrecoverable despite that there'd be no thief, officer, r…

Having encrypted data I wouldn't say is disproportionately prioritising protection over losing it in another way. The person simply forget what was a long password, something that most security conscious people would have figured out by storing it in a password vault.

However I do agree that "going alone" with security can make us the victim of our own fragility. I can see this happening in the new blockchain world of decentralisation. If I lose my Bitcoin wallet or lose the password, who can I speak with to validate my identity? Nobody. Currently, I can go to the Bank and validate myself with other forms of ID to access my account, but with Bitcoin it's all on me. Imagine losing your entire life savings because you forgot your password or access to your email account.

This is where centralising certain things works for the overwhelming majority of the population. That's not to say that those systems work perfectly, but they are vetted and have laws and regulations to protect us.

Re: So I lost my OpenBSD FDE password (2016)

#46
post #42
post #39

Earlier quoted context omitted.

I skimmed back the article after reading this comment, and I'm still not really sure how this follows. Of course you should always make redundant backups with parameters suitable for however much assurances you want to have that you will not lose data. However, I dunno if there's any particular evidence to suggest that data loss is the main concern here. I mean, I have a backup strategy for most of my data, but I'd c…

Yeah my comment's tangential to the article. The problem there is that there is an FDE password in the process of securing your data that you can't backup reliably (Filippo misspelled the password). This would have caused the loss of an entire RAID drive for anyone, not for Filippo in this case obviously. Such a basic UX problem causes catastrophes. Microsoft avoids that by backing up your key (not password) to a USB…

> Microsoft avoids that by backing up your key (not password) to a USB drive or even cloud first. There's no typo issue. There's no forgotten password issue.

The issue is that now the forgotten password moves to the cloud, especially since Bitlocker is activated automatically, without notifying the user, when an MS account is used. So regular Joe probably has no idea his drive is encrypted.

And since MS also push for authenticating to the account by using the TPM combined with a fingerprint / webcam / PIN, if you can't use your laptop (which is likely the case if you can't remember the unlock password – which you've probably never knwon was even a thing to begin with) you're pretty much SoL if you can't remember the cloud password – which you haven't used in months, possibly.

I think the old, manual way of activating BitLocker was best, where they tried to coax you into backing up that key someplace.

Re: So I lost my OpenBSD FDE password (2016)

#47
post #33
post #18

Earlier quoted context omitted.

This is why Microsoft Windows is so adamant about having you create an online account as your means of sign-in on modern Windows versions. FDE requires it on some versions. Telling users that forgot their password that not only do they need to reinstall Windows, but that every single document, photo, video of their grandkids, etc. is now lost forever is untenable. At the same time, FDE is important for security, so w…

FDE with someone "in the cloud" having the key is defeating the purpose of FDE. Windows used to offer printing a very long key on paper.

It's actually a really elegant solution as there is nil correlation of risk: the key is useless without physical access and physical access is useless without knowing the login.

Your government might be able to get the key - if that's part of your threat model - but they probably have easier ways to force you to give it up.

Anyway, FDE is often on by default. Do you really believe the average user is going to print out the backup key?! Do even tech savvy users have printouts of all their eg 2FA codes? Anyway, that would have worse correlation of risk as users would probably keep the printout next to their computer.

Re: So I lost my OpenBSD FDE password (2016)

#48
post #42

Earlier quoted context omitted.

Yeah my comment's tangential to the article. The problem there is that there is an FDE password in the process of securing your data that you can't backup reliably (Filippo misspelled the password). This would have caused the loss of an entire RAID drive for anyone, not for Filippo in this case obviously. Such a basic UX problem causes catastrophes. Microsoft avoids that by backing up your key (not password) to a USB…

> Microsoft avoids that by backing up your key (not password) to a USB drive or even cloud first. There's no typo issue. There's no forgotten password issue. The issue is that now the forgotten password moves to the cloud, especially since Bitlocker is activated automatically, without notifying the user , when an MS account is used. So regular Joe probably has no idea his drive is encrypted. And since MS also push fo…

> manual way of activating BitLocker

That method lead to tons of people not using it. It also lead to tons of drive lockouts due to people not knowing the password and not backing up the key. Good security is transparent to the user, making the user do things makes them insecure.

There are a ton of authentication options for a Microsoft account that aren’t passwords (they are the “passwordless” people after all). You can set up as many as you want (and will be nagged about it until you do!). Install Authenticator, configure whatever your phone offers for biometrics to unlock it, and get on with your day.

Re: So I lost my OpenBSD FDE password (2016)

#49
post #38

I’ve just been using the same password for my FDE forever, and only for that purpose. I figure it keeps my data safe from theft, but probably not from the feds or my wife if she wanted in there, because they could either compel me to unlock it or have access to put some keyboard sniffer in my boot loader. The password is quite a few random characters that I memorized when I first used FDE decades ago and I’ve never h…

> I’ll never forget it

I used to think that, too. Narrator: He did forget it... Lesson learned. As always, YMMV.

Re: So I lost my OpenBSD FDE password (2016)

#50
post #33

Earlier quoted context omitted.

FDE with someone "in the cloud" having the key is defeating the purpose of FDE. Windows used to offer printing a very long key on paper.

It's actually a really elegant solution as there is nil correlation of risk: the key is useless without physical access and physical access is useless without knowing the login. Your government might be able to get the key - if that's part of your threat model - but they probably have easier ways to force you to give it up. Anyway, FDE is often on by default. Do you really believe the average user is going to print o…

> It's actually a really elegant solution as there is nil correlation of risk: the key is useless without physical access and physical access is useless without knowing the login.

That is assuming you somehow forget your encryption key but remember the login to your microsoft account... that you used once 2 years ago when you were installing the machine.

It also means anyone that does get the login for your MS stuff can decrypt your laptop

Post reply on HN