←back to thread

189 points arjvik | 4 comments | | HN request time: 0.001s | source
Show context
acheong08 ◴[] No.42733994[source]
I don't understand why anyone would use passwordless disk encryption. It just seems inherently vulnerable, especially with the threat model of physical compromise.

Entering a password on boot isn't even that much work

replies(19): >>42734012 #>>42734073 #>>42734132 #>>42734171 #>>42734304 #>>42734370 #>>42734375 #>>42734397 #>>42734516 #>>42734734 #>>42734841 #>>42734892 #>>42734925 #>>42735445 #>>42736160 #>>42739068 #>>42740673 #>>42741392 #>>42742256 #
1. logifail ◴[] No.42734925[source]
> I don't understand why anyone would use passwordless disk encryption

You want to install and operate a device at a remote site with restricted (or no) VPN access and where you don't trust the local staff?

replies(1): >>42735194 #
2. artiscode ◴[] No.42735194[source]
A remote KVM, i.e TinyPilot will help avoid dealing with lack of trust in local staff. Additionally connection to the KVM can be done over LTE/Cellular if you don't trust the local connection too.
replies(2): >>42735321 #>>42736713 #
3. logifail ◴[] No.42735321[source]
I set up a server last year which is at a remote site which is completely air-gapped from the Internet, it's allowed to see one local LAN and that's all. For any kind of admin task someone has to drive to site.

There is precisely zero chance that the relevant IT security goons would allow any kind of remote KVM/LTE connection.

4. nh2 ◴[] No.42736713[source]
How does this make sense?

Any change the untrusted local staff could make to the server, they could also make to the KVM machine (e.g. turn it into a keylogger).

Now you have the same problem but with a smaller computer.

You cannot turn untrusted systems into trusted systems by adding more untrusted systems.