Hacker News new | ask | show | jobs
by kijinbear 5477 days ago
Full-disk encryption. You enter the key whenever the system needs to be rebooted. I know at least one company that does this with all of their US-hosted servers.
2 comments

And not servers hosted in other countries? I'd be very curious to hear the thought process behind that decision.
Perhaps all their employees live in the US, so they consider it not worth the trouble to fly someone to Indonesia whenever a server in Jakarta needs rebooting.
It's not necessary that they have physical access in order to do that, though.
This would only be protection against thieves that steal your harddrives, if the US government had your drives they can legally compel you to divulge your password.
The company in question is actually located outside of the US, and so are all employees who have access to the key. It keeps its servers in the US only because of issues with cost and latency, I think.
There are systems you can use to defeat this. One password decrypts the drive, another wipes it.
If there was a court order for the decryption keys for your drive and you gave them a key that destroyed it, you would almost certainly be found guilty of deliberately destroying evidence.
If they could prove that that's what you did.