Hacker News new | ask | show | jobs
by dijit 26 days ago
If you use your key every day you tend not to forget it.

If I as an admin give you your key: it is “leaked” effectively.

3 comments

>If you use your key every day you tend not to forget it.

hoping users don’t forget their password is a very weak policy.

specifically, the policy and admin points you brought up above, how does veracrypt solve them?

We're sort of talking about two things and conflating them.

I'm sort of talking about my user experience of the system, and I'm getting it in the neck from helpdesk.

Enterprise rollouts are different from anything I actually deliver, despite pushing out thousands of windows servers: I have complete control over those.

Same as my local PC.

But as a user on a PC I'd buy from a store, I'm not going to forget my password without expecting to lose access to my system.

>We're sort of talking about two things and conflating them. [...] But as a user on a PC I'd buy from a store

i said multiple times that i was talking about a managed fleet in an enterprise environment, and even specifically said that i dont typically recommend bitlocker for personal use, so i am not really sure what to say here. i was really clear.

Yes, but I still think we've been talking passed each other.

I doubled down on "it's fine but not excellent" when I should have pulled away and explained that the main issues I have are about bitlocker as a user.

You don't have remote back ups enabled?
veracrypt does not include a remote backup system
Of the work, not of the encryption.
we're talking about veracrypt vs. bitlocker in a managed enterprise environment.

whether there are backups or whatever else is irrelevant because it would be true in both the veracrypt and the bitlocker scenario.

We are talking about IT policies. I don't know what YOU think we're talking about.
Our helpdesk deals with 2-300 users per day that logon every single day yet forgot their password.

This type of thinking doesn't work in large enough orgs dealing with end users.

Have you never gone on vacation and forgotten your daily-use password upon return?
Nop.