3 ms·
> FDE handles almost exclusively a single threat: the physical threat of your unattended computer. For most FDE solutions, doesn't the computer have to be off
by hackuser 10y ago
> FDE handles almost exclusively a single threat: the physical threat of your unattended computer.
For most FDE solutions, doesn't the computer have to be off or possibly in hibernation (suspend to disk)? Does sleep mode (effectively suspend to memory?) activate the FDE? IME, most people's computers are almost always on or asleep.
EDIT: File-level encryption seems better: All files are encrypted except when open. But I don't know if there are any solutions that implement it securely and useably.
- tptacek 10y agoA decent middle ground is encrypted disk images. You're getting inferior encryption (it'll be sector-level wide-block unauthenticated encryption), but at least you'll have to unlock and lock things as you use them. There used to be an OS X tool called Vault that managed these with a simple, pretty UI. Unfortunately, it was discontinued. We may put something like it together, but we suck at UI. Stuff like this, by the way, is why I get so aggravated by UI/UX/Frontend developers who build new encrypted messengers --- the world doesn't need more encrypted messengers, but badly needs more UI/UX help with existing tools (I'd be happy to build the backend for such a thing and sign the IP over to an effective front-end developer).