onlinepersona@programming.dev to Linux@programming.dev · 3 days agoWhy call it full-disk encryption when the EFI partition has to be unencrypted?message-squaremessage-square39fedilinkarrow-up118arrow-down15file-text
arrow-up113arrow-down1message-squareWhy call it full-disk encryption when the EFI partition has to be unencrypted?onlinepersona@programming.dev to Linux@programming.dev · 3 days agomessage-square39fedilinkfile-text
minus-squareUnfortunateShort@lemmy.worldlinkfedilinkEnglisharrow-up1·edit-22 days agoMy guess is because that idea became tied to secure boot respectively chassis intrusion quickly, which makes encrypting every last bit unnecessary. There is true FDE baked into SSDs tho - they can store their key in a TPM.
My guess is because that idea became tied to secure boot respectively chassis intrusion quickly, which makes encrypting every last bit unnecessary. There is true FDE baked into SSDs tho - they can store their key in a TPM.