4 ms·
If someone manages to access the running raspberry pi though, FDE doesn't protect against that, while the Syncthing's untrusted device encryption does.
by ephbit 3y ago
If someone manages to access the running raspberry pi though, FDE doesn't protect against that, while the Syncthing's untrusted device encryption does.
- hamandcheese 3y agoIf your threat model includes someone willing to break into your house, then, well, good luck. [0] [0]: https://xkcd.com/538/ https://xkcd.com/538/
- jsiepkes 3y agoThe threat model described by the post above you is actually not about physical access. It's about the PI getting hacked remotely. If you use Syncthing's encryption then at no point is the decrypted content available to the PI. It gets decrypted locally by other Syncthing peers after they have downloaded it.
- hiq 3y agoBesides, there's still a difference between physical accesses: plain and non-targeted (besides how profitable they're expected) burglaries are way more common than violent targeted attacks meant to extract a secret from an individual.
- hamandcheese 3y agoAre you aware of any non-targeted burglaries where the burglar extracted secrets from a running computers memory?
- hamandcheese 3y agoAn attacker with a wrench will get the information they want from you, regardless of where it's located.
- grotorea 3y agoMaybe a better example might be wanting to use a smartphone as the always on sync endpoint. The phone can easily be stolen but with this feature it won't contain the valuable data.
- kevincox 3y agoIncluding if some other service on your Pi gets compromised. They still won't get access to your synced data.