Hacker News new | ask | show | jobs
by csirac2 3809 days ago
But he talks about GPG directories. And then says he uses drive encryption... To protect his passwords? No, these sentences don't make sense.
1 comments

To protect all the files on his computer(s), including the public/private key pairs that allow him access to remote machines.
I feel like I'm stating the obvious so perhaps I'm missing something, but FDE only protects anything when a computer is off or a volume is otherwise not mounted.

Eg. your average shoulder surfing/xscreensaver unlock bypassing jerk, hacker or piece of malware isn't going to bother checking if an already mounted filesystem happens to be on an encrypted block device and voluntarily decide not to copy all your private keyfiles.