Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Full-disk encryption is primarily used to protect offline volumes. If no one can boot your disk, it doesn't matter if Microsoft can upload its entire contents to the NSA once Windows is started. The concern is that a flaw in BitLocker's FDE would make it vulnerable to attacks while the volume is offline.

FDE doesn't really protect online volumes. Yes, the disk is still encrypted, but the OS transparently decrypts any requested sector, so other security measures are necessary to protect mounted volumes.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: