onlinepersona@programming.dev to Linux@programming.dev · 1 day agoWhy call it full-disk encryption when the EFI partition has to be unencrypted?message-squaremessage-square26fedilinkarrow-up113arrow-down14file-text
arrow-up19arrow-down1message-squareWhy call it full-disk encryption when the EFI partition has to be unencrypted?onlinepersona@programming.dev to Linux@programming.dev · 1 day agomessage-square26fedilinkfile-text
minus-squareUnfortunateShort@lemmy.worldlinkfedilinkEnglisharrow-up1·edit-27 hours agoMy guess is because that idea became tied to secure boot respectively chassis intrusion quickly, which makes encrypting every last bit unnecessary. There is true FDE baked into SSDs tho - they can store their key in a TPM.
My guess is because that idea became tied to secure boot respectively chassis intrusion quickly, which makes encrypting every last bit unnecessary. There is true FDE baked into SSDs tho - they can store their key in a TPM.