Hacker News new | ask | show | jobs
by db48x 3808 days ago
To protect all the files on his computer(s), including the public/private key pairs that allow him access to remote machines.
1 comments

I feel like I'm stating the obvious so perhaps I'm missing something, but FDE only protects anything when a computer is off or a volume is otherwise not mounted.

Eg. your average shoulder surfing/xscreensaver unlock bypassing jerk, hacker or piece of malware isn't going to bother checking if an already mounted filesystem happens to be on an encrypted block device and voluntarily decide not to copy all your private keyfiles.