> if you use disk encryption like you should be doing
I've never found that I had a really good reason to encrypt a drive yet, I'm kind of surprised to see a suggestion that this is the way things are done.
The OP specifically mentioned a MPB, a laptop, which are pretty easy and high value targets for theft. If my laptop was stolen, I would be relieved to know that my personal data was safe.
There are additional reasons for full disk encryption too, like ensuring that important system files have not been tampered with. Whether or not you want to go that far depends entirely on your level of paranoia.
For a home desktop, the cost/benefit may be a bit different, because the computer is exposed to less places and people. As with many things in security, you would need to calculate what is an acceptable risk to you versus the cost of mitigating that risk.
If you ever have to wipe an SSD the wear-leveling will totally mess with your wipe process. It is always best practice to just do full disk encryption on SSDs, even if you aren't taking it out of the house/office.
If you work in financial,medical, government or with any employee data (ie, corporate HR systems) and use a laptop, it's often a good idea for the laptop-issuing organization to mandate full disk encryption to prevent unintentional sensitive data loss (an inside job will bypass this protection).
In addition to doing data recovery for people (sensitive documents, photos, etc.), I have a few clients I do work for and I'm exposed to client lists, password files, software license keys, etc.. If my home-office machine were ever stolen, I never need to worry since I use full-disk crypto.
I approach full disk encryption and how we "should be doing" it the same way I approach brushing my teeth 3x a day and flossing 1x a day. Yea, I should, but I brush my teeth 2.5x a day and floss 1x a week instead, and it's worked O.K. so far.
Comments
> if you use disk encryption like you should be doing
I've never found that I had a really good reason to encrypt a drive yet, I'm kind of surprised to see a suggestion that this is the way things are done.
Why should you be encrypting your disks?
The OP specifically mentioned a MPB, a laptop, which are pretty easy and high value targets for theft. If my laptop was stolen, I would be relieved to know that my personal data was safe.
There are additional reasons for full disk encryption too, like ensuring that important system files have not been tampered with. Whether or not you want to go that far depends entirely on your level of paranoia.
For a home desktop, the cost/benefit may be a bit different, because the computer is exposed to less places and people. As with many things in security, you would need to calculate what is an acceptable risk to you versus the cost of mitigating that risk.
If you ever have to wipe an SSD the wear-leveling will totally mess with your wipe process. It is always best practice to just do full disk encryption on SSDs, even if you aren't taking it out of the house/office.
Edit: Reference https://www.infosecisland.com/blogview/13722-SSDs-and-the-Im...
If you work in financial,medical, government or with any employee data (ie, corporate HR systems) and use a laptop, it's often a good idea for the laptop-issuing organization to mandate full disk encryption to prevent unintentional sensitive data loss (an inside job will bypass this protection).
Customer data.
In addition to doing data recovery for people (sensitive documents, photos, etc.), I have a few clients I do work for and I'm exposed to client lists, password files, software license keys, etc.. If my home-office machine were ever stolen, I never need to worry since I use full-disk crypto.
I approach full disk encryption and how we "should be doing" it the same way I approach brushing my teeth 3x a day and flossing 1x a day. Yea, I should, but I brush my teeth 2.5x a day and floss 1x a week instead, and it's worked O.K. so far.
Russian roulette is not a big deal. I've shot this revolver at my forehead 5 times now, and it's worked ok so far.
Perhaps he has data that he doesn't want people looking at if it's lost or stolen.