|
|
|
|
|
by tedunangst
2613 days ago
|
|
Doesn't seem that weird. The enclave has your secret in it, and comes attached to the storage it's protecting. Steal storage, extract key, done. My software FDE does not keep my password in it. There is nothing to extract after stealing. I will happily stipulate though that this requires a solid password and key stretching. |
|
A DIY mitigation might be to convert a phone to having only an external battery on a long cable, which stays in your other pocket.
Philosophically I do agree with where you're coming from with contemporary devices insisting on baking in privileged keys. It's unfortunate that we're forced to choose between the two models.