3 ms·
It's primarily targeting offline attacks ie: I've stolen your laptop or I am accessing it when you haven't decrypted it. But there are also niche situations wh
by staticassertion 5y ago
It's primarily targeting offline attacks ie: I've stolen your laptop or I am accessing it when you haven't decrypted it.
But there are also niche situations where an attacker has read permissions for files but not memory. It's atypical, but in cases where you have 'confused deputies' it happens - for example, if I have a service that attempts to safely broker reads to files but that service has a logic bug where a client can trick it into reading sensitive files.
The classic example of this is a path traversal in a web service.
Also, while there's no boundary, attackers are a lot happier reading files than memory. They're only human.
In general I find that, when you can, you should just encrypt your data. It can protect you in some surprising ways.