Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Assuming of course that all the data that you wish to protect is on your data partition, and that no protected data is, was, or ever will be on any other partition. Full disk encryption removes the possibility of exposure of protected data showing up on non-encrypted partitions.

With most operating systems, I don't think that there is a way to ensure that no protected data will ever end up on a non-protected partition. Presumably - if there is any writable directory on an unencrypted partition, there is a reasonable chance that protected data will end up on that partition.



I highly doubt an OS or an application would be writing to the unencrypted boot sector or an unencrypted boot partition. First off, the OS should disallow that operation without elevated privileges. I don't know if Windows or OSX follow that guidance.

I'm not advocating against "full" disk encryption. That's what I use. I just wanted to say that the OP doesn't need boot volume verification and that Bitlocker is sufficient for his needs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: