|
|
|
|
|
by lolc
2799 days ago
|
|
How many people have access to drives in us-east-2a? Do you know? Can you verify? Assuming the software works flawlessly (if it doesn't, it doesn't matter where it runs) you'll need RAM and storage access to recover the keys and the data. If you're in the cloud, you won't notice when insiders or state agencies take a peek. If the device is in your home, you can set it up so you notice. It all depends on the threat model. |
|
AWS, like every non-clownshoes provider, is transparent about the security controls on its datacenters. It has those verified by independent third parties and auditors (for relevant compliance standards). They have published whitepapers and compliance/audit reports, and continue to.
The odds that someone compromises a Helm update and the odds that someone walks out of us-east2a with a drive are not in the same ballpark.
To reiterate, because somehow I'm in the "FDE is an important threat model!" corner: it is not. Walking away with a Helm is not the easiest way to read e-mail on that thing, especially not for an organization capable of dragnet surveillance in general.