logoalt Hacker News

dummydummy1234yesterday at 11:03 PM2 repliesview on HN

What is the benefit of having full disk encryption pinned to a machine?


Replies

vbezhenaryesterday at 11:12 PM

The benefit is to not type encryption password on every boot. TPM stores the encryption key and Secure Boot ensures that the system is not tampered.

That said, I think that it's better to use alternative approach. Use unencrypted signed system partition which presents login screen. After user typed their username and password, only user home gets decrypted. This scheme does not require TPM and only uses secure boot to ensure that system partition has not been altered. I think that macOS uses similar approach.

show 3 replies
hparadizyesterday at 11:06 PM

Anti theft