4 ms·
I used to run this until I couldn't ignore that it was pointless because it offloads the attack vector to something I can easily lose, have taken or replaced.
by task_queue 11y ago
I used to run this until I couldn't ignore that it was pointless because it offloads the attack vector to something I can easily lose, have taken or replaced.
Or someone could come in an pop in a drive with their own kernel.
Nevermind the reality that I'd never completely follow through with the security measures needed on a personal machine. I'd just be giving myself an active role in my home's security theater.
I just encrypt my home folder and don't trust machines/networks for important things.
- jkot 11y agoThe card also contains certificate protected by password.
- e12e 11y agoYour initial comment was a bit brief; Now I realize you meant "just use full disk encryption/luks with the bootloader and boot-partion on a removable device -- to lessen the chances that the password prompt has been modified to capture your password (back-door bootloader, backdoor kernel/initrd)". Still somewhat vulnerable to a replaced BIOS and/or a hardware key logger (I gather the idea is: I can keep my usb key safe easier than my laptop. I'm not sure if that's true in a meaningful way).