Slashdot Mirror


Why Not Use Full Disk Encryption on Laptops?

Saqib Ali asks: "According to the 2006 Security Breaches Matrix, a large number of the data leaks were caused due to stolen/missing laptops. Mobile devices will be stolen or lost, but one way to easily mitigate the harm is to use Full Disk Encryption (FDE) on all mobile devices. So, why don't we encrypt all our HDDs?" "Cost, and performance impact are the usual arguments.

Analysis shows that the access time increases by 56%-85% after FDE. As HDDs fills up the fragmentation increases and so will the file access time. With FDE, the swap file (system's virtual memory) gets encrypted as well. This will impact the system's performance noticeably when the virtual memory is being used more often.

Encryption key & password management blues follow. What happens when the user forgets his/her new FDE password? How to manage the encryption key backup files? Who has possession of the backups of the encryption keys? What about when the users quits and does not hand over the password / encryption keys? Who can access the system and its encrypted files? How frequently does the password need to be changed? How to prevent the user from writing the passwords down? Using hardware token (RSA Token, smartcard etc) can alleviate many of the password management issues. But these hardware tokens are costly!

Cost for Full Disk Encryption solutions ranges from $0-$300.

Is it not worth using Full Disk Encryption on mobile devices after all the data leaks we have seen in the last few years?"

3 of 446 comments (clear)

  1. Oh yea, I can hear it now. by AltGrendel · · Score: 5, Insightful
    What do you mean, you can't reset my password for my hard drive. I need the data NOW!

    Really, we all know that people will forget/lose the password. Or they'll write it down and leave it in the laptop case.

    --
    The simple truth is that interstellar distances will not fit into the human imagination

    - Douglas Adams

  2. Security vs Convenience by Retardican · · Score: 5, Insightful

    Most of the key management problems have actually been solved. PGP disk for a long time had the ability to encrypt using multiple keys, fraction keys (eg. 3 out of 5 must have their keys to open), key expiration, etc.

    The real problem is convenience. People don't like to use secure passphrases each time they turn on their computer. How many people actually used the BIOS password feature? An easier thing would be to use some identification based (USB fob, fingerprint scanner) access, but the acceptance rate of those are very small.

    Unless security is important to them personally, people just don't care. (checking under my keyboard for the root password for all the machines at work)

    --
    Will the War in Iraq get better or worse in 2007? Vote here
  3. Re:Why Encrypt Everything? by TubeSteak · · Score: 5, Insightful
    Why not just encrypt the sensitive data if you want to avoid leaks of the sensitive data?
    Because it is not that simple.

    Sensitive data gets dumped to the swap file, Your word/spreadsheet/e-mail/other client will dump backup/temp copies in unencrypted places, etc etc etc.

    It isn't enough just to encrypt sensitive information, you have to make sure every application that touches the info will not compromise your efforts.
    --
    [Fuck Beta]
    o0t!