Skip to content

Comment on So I lost my OpenBSD FDE password (2016)

Comments

With encryption, you always have to balance the risk of having others access to your data to that of you also potentially losing access to your data forever. In other words, is it more important that no one, not even myself, can gain access, or is it more important that I can always have access, even if that means everyone else could? I suspect for much of the data people have, they'll categorise it as the latter instead of the former.

If you're looking for something in between, then deliberately weaker encryption might be what you want, although almost no one seems to mention that much.

If you're worried about something like what happens to your FDE volumes after you die, and you don't want to write down a passphrase somewhere, you could do something like pick three extremely trustworthy family members, swear them to secrecy, and give each of them one third of the passphrase.

Guaranteed one of them will lose a piece

Shard it with Shamir Secret Sharing and give out shards to more trusted friends?

Or be in the tragic accident with you

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.