Skip to content

Comment on So I lost my OpenBSD FDE password (2016)parent

Comments

No, you would use the recovery key in that scenario.

And we're back to the problem of having to store some rarely used credential somewhere.

So you... put it in USB drive then dig it out 5 years later and discover it's dead and you're fucked.

That is indeed a worst case event to be wary of and avoid, for any secret data that one may need to retrieve infrequently.

But my original point was that sealing the key to the TPM is better because it prevents adversaries from accessing the volume data by tampering with the boot chain, and provides a lockout where there are too many failed PIN attempts.

The bruteforce attack described by the author wouldn't have been possible on a BitLocker volume that was set up with TPM+PIN.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.