2 ms·
They did a little threat modeling: Practical & real Example: "Some Robber invade a home, and steal the server (containing IMPORTANT business backups, and own
by marcusb 1y ago
They did a little threat modeling:
Practical & real Example: "Some Robber invade a home, and steal the server (containing IMPORTANT business backups, and ownlife memories and blablabla). Not exist any disk/boot encryption. Robber have start the server on their 'safe zone' and start an bruteforce attack. He have cracked the local password by SSH with from sudoer user 'admin' success, yeah a dummy password, not THE Strong one/primary. He starts SSH session/or physical session with that cracked dummy/panic password with 'admin' sudoer. He starts feeling the server seems too much busy in less than 2 minutes until to freeze.. 'wtf!?! lets reboot and continue steal info..'.. sorry friend. all data and system was destroyed.". Conclusion, the robber cracked the dummy/panic/secondary password, and with this password its associated a script will do delete all files, config, system, boot and after than start charge the RAM and CPU to force robber reboot system.
That's...not a scenario I've focused on for my personal assets, and I'd be more worried about the duress password getting triggered by a random over- the-network brute force and losing my data, but to each his/her own.
- CableNinja 1y agoNo disk encryption, server stolen. The end. They have your data, everything else is too late. Who would ssh into a box they stole and have physical unencrypted access, no one.