View Single Post
  #17 (permalink)  
Old 11-22-2006, 11:36 AM
paolo.digiacomo@gmail.com
Guest
 
Posts: n/a
Default Re: So why don't we use full disk encryption on all mobile devices?


Arthur T. ha scritto:

> When installing, CompuSec tells you to back up the file to
> external media in case something happens to the file on your hard
> disk. I don't think the program says that the information can be
> used *all*by*itself* to break into your machine. I had figured it
> was like the PGP keyring: You're sunk without it, but, even with
> it, you need your passphrase.


Unfortunately it is not like PGP keyring, because with the reset
password you can boot the encrypted PC using "help" as a login and the
reset password get from the plaintext Securityinfo.dat file. So it is
enough to have this file to gain access to the machine. Moreover you
can't be safe even if you keep this file well protected, because it can
be regenerated if a user manages to access your pc with administrative
privileges (and it sounds to me like a security vulnerability).


Reply With Quote