4 ms·
FDE best practices are to encrypt the entire drive with a random key, and encrypt that random key with a derived key (key-encrypting key, or KEK) based on passw
by haikuginger 10y ago
FDE best practices are to encrypt the entire drive with a random key, and encrypt that random key with a derived key (key-encrypting key, or KEK) based on password. You don't have to nuke the whole drive; just the sector with the KEK-encrypted drive key.
- RUG3Y 10y agoThanks, that helps me understand.