logoalt Hacker News

digiowntoday at 3:15 PM1 replyview on HN

> full-drive encryption

Note that these are not crackable only if you have a strong password (random one will work). Unlike on phones, there is nothing slowing down brute force attempts, only the comparatively much weaker PBKDFs if you use a password. You want at least about 64 bits of entropy, and you should never use that password anywhere else, since they would basically run "strings" on your stuff to attempt the brute force.


Replies

ddtaylortoday at 3:46 PM

Worse than that most phones are using smart enclave like chips protected by a 4 digit PIN that can be voltage drained to try every combo without a wipe.