4 ms·
I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to p
by Perseids 12y ago
I can't really see the usage scenario. If you want to transmit data securely between A and B, use public key cryptography and the internet [1]. If you want to protect data at rest, use full disk encryption. If you want protect the data on a running PC against theft, then you also have to consider all the data in the RAM (caches etc.). And if you, somehow, can prevent the attackers from getting that, then you can again use full disk encryption.
[1] If you are really paranoid and don't want to connect the devices to the internet, or if you don't have an internet connection at the target location, send a messenger with a random symmetric key first. If he/she arrives safely, send the hard drive with full disc encryption using the symmetric key next. Via any means. You can even FedEx it.
- joshvm 12y agoYour Fedex scenario wouldn't work if both the disk or key were compromised mid-transit. You might not know that someone sneaked a glance at the key or if they managed to clone the drive, but if they're sniffing all your mail then you've just given them the keys and the data.
- Buge 12y agoIsn't this SSD also vulnerable if the key is compromised?
- Perseids 12y agoThat's why I was writing about a "messenger" specifically. I was thinking about someone you can trust, if need be, yourself. If this messenger assures you the key wasn't spied upon, you can use the key. If you can't even get a courier with a sealed envelope to the location, then you probably won't get any encrypted or otherwise protected data in there, anyway. This level of security is ridiculous for almost everyone, of course. But we are talking about a self destructing SSD, which you want to send via courier to initiate the destruct, as an alternative. So I think this is a fair comparison.
- deleted 12y ago[deleted]
- desdiv 12y agoSome jurisdictions force people to decrypt their drives under pain of contempt of court. Some jurisdictions use rubber-hose cryptanalysis. Full disk encryption protects against neither. This protects against both.
- AlyssaRowan 12y agoNo more than zeroizing the key would.
- ObviousScience 12y agoHow does this protect me from them not touching my computer at all, walking me in to a different room, tying me to a chair, and... uh... "asking politely while showing me a warrant" for me to decrypt the device and disable any security features?
- cmdrfred 12y agoI'm not sure but there might be a destruct key. Give them that, and have them nuke the drive for you :)
- nickodell 12y ago>I can't really see the usage scenario. ... If you want to protect data at rest, use full disk encryption. It's pretty easy to think of scenarios that FDE does not protect against but this product could. 1) While cloning, modify the bootloader to load a software keylogger when the computer starts. 2) After cloning, install a hardware keylogger.