Hacker News new | ask | show | jobs
by eikenberry 3300 days ago
Once "they" have your machine you have to assume it is compromised. If they have the ability to install kernel patches or custom binaries, they most certainly have the ability to install monitoring hardware and/or modify your bios. That is, no matter what you encrypt your machine is compromised and your only recourse is to recover the encrypted data and move on to a new system. Here "they" is someone who would take your machine, modify it, and get it back to you maybe without your knowing.

If you are just concerned with identity thieves and basic asset protection then as long as that stuff is encrypted you are fine, whether that is whole system, home directory, ~/Private directory, or just those specific files.