Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

To: Swordmaker; taxcontrol; cymbeline
Equivalent security at rest is possible on windows with TPM. The bitlocker decryption key is stored in hardware with a simple short PIN to secure it since the hash is not accessible and guessing is hardware limited. If you fail (e.g. exceed the guess limit) you need your bitlocker recovery key to get to your hard disk content. That will be probably be printed on paper locked in a drawer.

I don't think anyone really should have issues with security at rest (e.g. leave your laptop or phone on the train) but certainly having recent apple products or windows with TPM will keep your data safe. The problem is more about how to stay safe while the computer is active and you are running programs. In that case the cluttered kernel on Windows is a detriment, still processing attacker-controlled data. In particular windows systems support all kinds of third party hardware with crappy drivers.

That's not the case with Apple or Linux, in Apple's case it's Apple's hardware and drivers, and in Linux there is not much support except open source which can be vetted. Further as Swordmaker pointed out Apple now has System Integrity Protection so critical files cannot be altered by root. (one minor point, generally most Linuxes also disable root by default, but that's obviously not enough).

38 posted on 02/08/2018 12:59:12 PM PST by palmer (...if we do not have strong families and strong values, then we will be weak and we will not survive)
[ Post Reply | Private Reply | To 31 | View Replies ]


To: palmer

TPM is no stronger than the underlying security library.

https://thehackernews.com/2017/10/rsa-encryption-keys.html


41 posted on 02/08/2018 2:13:52 PM PST by taxcontrol (SStupid should hurt)
[ Post Reply | Private Reply | To 38 | View Replies ]

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson