Live data from Hacker News

So I lost my OpenBSD FDE password (2016)

words.filippo.io

1–10 of 77 posts

Re: So I lost my OpenBSD FDE password (2016)

#2
This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something.

In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especially after the first time someone comes to you to hack their stuff because they've lost their keys & they never did do that backup thing you good then about³ and you tell them it simply isn't possible.

Even those of us with experience in the field sometimes make mistakes that we can't revert, so people without that experience can be forgiven to an extent for trading security for what they think is safety (but is really just convenience).

Solutions, that don't involve someone being an unpaid 24/7 infrastructure support tech, on a postcard please!

----

[1] if procedures are properly followed² code is in source control and documents are in equivalent storage, the most you should be able to lose is today's work

[2] yeah, I know…

[3] or that uses the same, now lost, credentials

Re: So I lost my OpenBSD FDE password (2016)

#5

This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…

> Solutions, that don't involve someone being an unpaid 24/7 infrastructure support tech, on a postcard please!

One step at a time!

1. Back up your data.

2. Test restoring your data.

3. Automate your backups.

4. Automate your test restores.

5. Now you are ready for full-disk encryption.

It is okay if you do not complete all steps. More steps is better. Do not skip ahead.

Re: So I lost my OpenBSD FDE password (2016)

#6

This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…

I am sitting on a 12TB array after my move I just can't come up with the combination...

However, there are better options for users - how about Smartcards? You know, like yubikey / U2F before the web?

You can even use it with LUKS

Re: So I lost my OpenBSD FDE password (2016)

#9

This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…

>trying to encourage less technical users to be secure

The threat of “losing the keys to all the data” is considerably larger than the threat of having your computer and data stolen for an average home user. It can’t just be a matter of more secure is better… you have to have an idea of what you’re trying to prevent.

All of our shit has been lost in one leak or another so at this point it seems like it barely matters.

Re: So I lost my OpenBSD FDE password (2016)

#10
post #5

This is something that is difficult when trying to encourage less technical users to be secure. Once you convince them to do things right, they've heard of circumstances like this and are petrified of accidentally losing something. In a commercial environment there are ways and means¹ but getting a non-technical user to securely and safely manage access credentials is can be a time consuming education process. Especi…

> Solutions, that don't involve someone being an unpaid 24/7 infrastructure support tech, on a postcard please! One step at a time! 1. Back up your data. 2. Test restoring your data. 3. Automate your backups. 4. Automate your test restores. 5. Now you are ready for full-disk encryption. It is okay if you do not complete all steps. More steps is better. Do not skip ahead.

So as long as you keep your data unencrypted next to your encrypted data, you're fine. Checks out.
Post reply on HN