3 ms·
Those servers -- do they have Firewire Ports? USB3? Other externally accessible DMA ports? Drive encryption prevents offline data at rest, they keys will be i
by throwaway123534 11y ago
Those servers -- do they have Firewire Ports? USB3?
Other externally accessible DMA ports?
Drive encryption prevents offline data at rest, they keys will be in memory for a running server. If LEA is going to grab your servers, your keys are going to go with them.
- brongondwana 11y agoYeah, it's true - same for anyone. The main benefit of encrypting the drives (indeed, the only reason I was willing to do the tradeoff for something which is mostly theatre) is that we can RMA failed drives and discard old drives with no risk to customer data. That alone is worth paying the slight overhead on modern CPUs for full disk encryption of all user-data partitions (the OS isn't encrypted - it's Debian with some open source packages on it, and we throw it away anytime - http://blog.fastmail.com/2014/12/07/automated-installation/ http://blog.fastmail.com/2014/12/07/automated-installation/)