Coupled with encrypted Time Machine backups and Arq[0] I feel relatively ok about losing my machine.
Coupled with encrypted Time Machine backups and Arq[0] I feel relatively ok about losing my machine.
So, it will keep the honest out, but for someone who knows what they're doing, it will only prove a mild inconvenience.
This obviously doesn't help them bypass FDE, but in case they want to steal the laptop and not have a brick, the SPI writer works a treat.
Besides any potential thief wont even know whether you're running FDE or not on the laptop they steal, or whether it would be bricked or not. They can always sell it for its parts (screen, etc) anyway.
Whereas, if someone straight-up steals it, they have no chance of recovering data if the encryption is strong and key isn't in memory (eg cold boot). You can also transmit media through untrusted channels that way. Even NSA's Inline Media Encryptor, which my inspired my designs, has that use case.
Sure, but that's different from anti-stealing (and I mean stealing the machine of course, not the data).
I had a TimeMachine backup too but hadn't synced recently and ended up doing a bunch of hackery to recover the un-synced data :(
I much prefer 2FA & revocable certificates on remote accounts so I'm not worried about unauthorized access, and anything else important is encrypted independently.