Hacker News new | ask | show | jobs
by ryukafalz 3378 days ago
>You modify the bootloader to grab the password on next decryption. The bootloader is in cleartext on the disk, otherwise the machine couldn't boot.

Mine isn't - I have GRUB installed to my BIOS chip, and I decrypt the single encrypted partition from there.

>More advanced versions would involve modifying the BIOS to add a SMM-mode hook.

That one could still get me though, yeah.