5 ms·
You can achieve the same with bitlocker by enabling PIN and autologin
by k8sToGo 2y ago
You can achieve the same with bitlocker by enabling PIN and autologin
- wat10000 2y agoHaving a separate PIN isn’t the same thing. Unlocking the disk with your login password means it’s just as convenient to have an encrypted drive as not (for the typical user who doesn’t need the thing to be able to boot by itself) and it can be the default configuration.
- k8sToGo 2y agoYes I agree. It should be OOB like it is with MacOS. But you can set the PIN (they call it PIN, but you can enter any password) the same as your PW.
- wat10000 2y agoAh hah, terrible naming strikes again. I’m guessing that means you now have to change your password in two places if you ever change it? Not great, but then again people probably never change their passwords.
- p_ing 2y agomacOS has two things going on -- FDE (i.e., same as BL) which is auto-unlocked on boot up. What is protected by the user's password is FileVault encryption, but that's home directory protection only. https://support.apple.com/guide/mac-help/protect-data-on-your-mac-with-filevault-mh11785/mac https://support.apple.com/guide/mac-help/protect-data-on-you...
- wat10000 2y agoFileVault 1 was home directory encryption. That hasn’t been current in ages. The current FileVault 2 is FDE using the users’ passwords as the keys.
- dunham 2y agoNote in page that you linked: > When you turn on FileVault, you choose how you want to _unlock your startup disk_ if you ever forget your password: The password now locks the entire startup disk (as of FileVault2, which has been around a while) and needs to be entered into a pre-os screen. There is a place in the UI (once booted) to designate which users can do this. This is useful for securing lost devices (since they don't have enough key material to decrypt the disk), but probably still susceptible to evil maid attacks (hacking the login screen). You can read details on pages 119 and 120 of this document (in particular, page 120 has a diagram of how the volume encryption key is derived): https://help.apple.com/pdf/security/en_US/apple-platform-security-guide.pdf https://help.apple.com/pdf/security/en_US/apple-platform-sec...
- wat10000 2y agoBasic evil maid attacks are prevented by signing that login screen software (and everything leading up to it) so it can’t be altered. Of course there’s still the possibility of vulnerabilities in that software, hardware key loggers, etc.
- rhplus 2y agoAuto-unlock does exactly that, and its the default behavior for BitLocker encrypted OS disks.
- wat10000 2y agoGood. But why isn’t that the default? I get why the unattended-unlock mode would exist. Sometimes you have a computer that needs to be able to get started by itself. But it should be an advanced option, not be the default configuration! Especially on a laptop.