Christian Pietsch<p><span class="h-card" translate="no"><a href="https://framapiaf.org/@marczz" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>marczz</span></a></span></p><p><strong>Why you should use full-disk encryption</strong></p><p>If any of the arguments I make below apply to you, you should use full-disk encryption. I am pretty sure the first argument applies to everyone. The second argument applies at least to everyone in the EU and the US state of California. The third argument applies to everyone again.</p><p><strong>You will fail to delete drives properly</strong></p><p>Storage media get lost. Most people do not know how to properly delete hard disk content before selling them, or they forget it. In the case of flash drives, or SSDs, standard tools like <code>shred</code> don't work. <code>hdparm</code> may do the trick, but this is not well known. If you are lucky, the manufacturer of you SSH provides a Windows app that lets you delete it securely. Your server does not run on Windows of course.</p><p><strong>The law demands it</strong></p><p><a href="https://fedifreu.de/tags/GDPR" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GDPR</span></a> and similar data protection and privacy laws require you to store no <a href="https://fedifreu.de/tags/PII" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PII</span></a> (personal data) permanently. You have to anonymize PII or delete it after a few weeks. IP addresses are PII. All servers store IP addresses by default. The GDPR also demands that you use state-of-the-art technology to protect sensitive data. Full disk encryption is the state of the art.</p><p><strong>Law enforcement makes "mistakes"</strong></p><p>I'm a board member of <span class="h-card" translate="no"><a href="https://fedifreu.de/@Artikel5eV" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>Artikel5eV</span></a></span>, an organisation that runs relays on the Tor network, including exit relays. Running Tor relays is perfectly legal in Germany. Nevertheless, law enforcement agencies have raided the homes of Artikel 5 e.V. board members twice. Illegally so, as a court confirmed recently. I won't run Tor relays in my home, but there is a good chance that my home will be raided one day unless all police officers and prosecutors decide to obey the law.</p><p>There is also a possibility that the rule of law might collapse in your country sooner or later. We are just witnessing it in the USA.</p><p>You already mentioned that ordinary thieves can also be a problem.</p><p><strong>Encryption is available for free</strong></p><p>So what is your case against disk encryption? It is obvious that it alone does not solve all IT security issues, but it is an important building block. <a href="https://fedifreu.de/tags/LUKS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LUKS</span></a> is reliable free and open-source software for HD encryption. If you are not using Linux, check out <a href="https://fedifreu.de/tags/VeraCrypt" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VeraCrypt</span></a>. The Raspberry Pi 5 comes with hardware acceleration for AES, so there no longer is a noticeable performance penalty for encryption.</p><p><a href="https://fedifreu.de/tags/storageEncryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>storageEncryption</span></a> <a href="https://fedifreu.de/tags/hardDiskEncryption" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>hardDiskEncryption</span></a> <a href="https://fedifreu.de/tags/encryptAllTheThings" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>encryptAllTheThings</span></a></p>