4 ms·
FDE is overrated, most leaks are not "someone stole my laptop" but "user clicked malicious links" ad other stupid stuff like that. And it is also entirely usel
by ilyt 3y ago
FDE is overrated, most leaks are not "someone stole my laptop" but "user clicked malicious links" ad other stupid stuff like that.
And it is also entirely useless for good amount of data volume-wise on machine.
I never need video game files to be encrypted for example. It's entirely waste of power and CPU time to do it.
- eli 3y agoIf an unencrypted laptop is lost or stolen you have to assume all the data on it is compromised, send breach notifications to affected customers, etc.
- mrsilencedogood 3y agoBut this is just Windows 11 Pro, though, not Enterprise. I guarantee you gamers (who are probably a big contingent of people who buy Pro but not Enterprise) are going to be turning this off so fast.
- k8sToGo 3y agoI’m a gamer and have it on.
- wutwutwat 3y agoEverything is unnecessary until you need it. Why pay cops if I’m not being murdered or robbed? Why keep nukes behind launch codes, nobody’s trying to launch them? Why eat every day, I don’t start to die until like 3 days in…
- olliej 3y ago> Why pay cops if I’m not being murdered or robbed? Why pay cops, they're already being bribed by criminals (batman, punisher, etc cops anyway :D ) > Why keep nukes behind launch codes, nobody’s trying to launch them? Because if you get rid of launch codes you'll decimate the Hollywood Political Thriller movie industry > Why eat every day, I don’t start to die until like 3 days in… Why do you hate farmers? :D
- whelp_24 3y agoYou've got closer to a month or more with no food. Starving takes a long time, halfway starving even longer. Water is what takes three days.
- wutwutwat 3y agoAh shit you’re right. I didn’t study biology because I didn’t need to operate on myself, so it was unnecessary.
- k8sToGo 3y agoIf someone breaks into my car and steals my laptop I can sleep better with bitlocker on. Has nothing to do with the clicking links or not.
- pcdevils 3y agoOnly if you shutdown. Otherwise tpm is still in memory and everything is unlocked. Going off how many people compliance have to chase to restart for updates, a lot of people think sleep is fine
- KennyBlanken 3y agoYour average thief has no idea how to get into a system which asleep but screen-locked. FDE means your machine gets wiped and resold, or sold for parts...but your data on the system remains private.
- elif 3y agoBetter maybe, but you'll never sleep well if you leave your laptop in your car. In fact, none of us can park in peace because people leave laptops in vehicles.
- ls612 3y agoCorrection: none of us can park in peace because the state does not punish those who break into cars to steal laptops severely enough. It’s a political problem not a technical one.
- JohnFen 3y agoWhy is your laptop in your car without you?
- keep_reading 3y agoFDE is not overrated and should have a 0% impact on performance if your CPU has AES instructions. Modern CPUs can do AES faster than your SSD, sometimes faster than an NVME can read/write
- delusional 3y agoThat's not how you asses performance at all. Maybe you can saturate the NVMe link with AES in idea circumstances, but you may be killing memory mapping and churning I$. To say anything interesting about performance on these modern machines, you would have to benchmark some real workload.
- auspiv 3y ago5 year old CPUs (Intel i7-6700, for example) do 2.6GB/s. https://calomel.org/aesni_ssl_performance.html https://calomel.org/aesni_ssl_performance.html First gen Ryzen (similar age) does 8.2GB/s, which is faster than PCIe 4 NVMe drives. https://www.vortez.net/articles_pages/amd_ryzen_7_1800x_review,9.html https://www.vortez.net/articles_pages/amd_ryzen_7_1800x_revi... Somewhat recent intel i7-12700H does 14.8GB/s, which is about the limit of PCIe 5 NVMe drives. https://www.notebookcheck.net/Intel-Core-i7-12700H-Processor-Benchmarks-and-Specs.589170.0.html https://www.notebookcheck.net/Intel-Core-i7-12700H-Processor... Edit: here's a list of AES speeds via truecrypt. top of the charts is the Ryzen 9 7950X at 32GB/s. https://www.notebookcheck.net/Benchmarks-and-Test-Results.142793.0.html?type=&sort=&max_results=500&archive=1&or=0&showBars=1&bench_93_363=1&model=1&cpu_name=1&gpu_name=1 https://www.notebookcheck.net/Benchmarks-and-Test-Results.14...
- keep_reading 3y agoThank you for looking up the most recent performance numbers. People have no idea how incredible they are and how "free" FDE has become.
- squeaky-clean 3y agoHow much does this affect other processes happening at the same time? If I'm playing an open world game that streams the environment off the ssd, how much is this going to contend with my cpu issuing draw calls, doing physics calculations, etc.
- mickelsen 3y agoIt's not if you do any meaningful work on it.
- kmeisthax 3y agoFDE's purpose isn't just to prevent you from pulling a disk out and imaging it to get all the data. It also makes it far quicker to do disk wipes. If someone yanks your laptop you can have the IT guy wipe it in a minute or two. Without FDE, whatever bossware is enforcing the device management would have to actually overwrite every sector of the disk, which can take hours and would be extremely noticeable to anyone extracting data off the machine.
- orbital-decay 3y agoMoreover, SSDs cannot be 100% erased, as not all capacity is user-addressable at any point in time.
- neodymiumphish 3y agoWhy would it need to wipe every sector of the disk? As ilyt stated, there's no need to encrypt game files. There's also no need to wipe them. Just the directories where important data resides.
- supertrope 3y agoFDE means you don't leak data to unencrypted parts of the file system. Temporary files and browser cache are areas sensitive information can be inadvertently left behind. With FDE you can check off the box "encrypted at rest" without having to qualify it with asking if the data is in the right folder or vault, if temp files are overwritten, etc.
- neodymiumphish 3y agoRight. But technically "every sector of the disk" isn't necessarily what bossware needs to wipe if an unencrypted laptop is taken. Only eelements which allow access to crown jevels, relevant credentials, etc. I'm an advocate for FDE across the board (literally all of my devices are on Windows 11 Pro, primarily so I at least have access to Bitlocker across the board), but it's disingenuous to claim that the only alternative to FDE when a device is taken would be to initiate a sector-by-sector wipe. He was responding to ilyt's comment about how only certain data is worth encrypting on pretty much every personal device (and we are talking about Win 11 Pro, not Enterprise).