Worth mentioning that this probably silly misconception is what makes me to always set a password for Bitlocker that I have to type manually which is what I've always done on LUKS.
Am I totally wrong?
Worth mentioning that this probably silly misconception is what makes me to always set a password for Bitlocker that I have to type manually which is what I've always done on LUKS.
Am I totally wrong?
Personally I mostly use FDE on personal machines so I don't have to care much about physical destruction when I need to get rid of storage devices. If a hard drive fails I don't need to actually tear it apart to make sure my data is gone. My device is usually in sleep mode when I'm out and about so if they were going to do a cold boot attack they could do it anyways.
As you mention decryption key is provided automatically to the system. This means it's in RAM ready for export and re-use by bad actor against your encrypted disk. Cold boot attacks[1] are one of the attack vectors you'd want to read more on to figure out if this is valid for your threat model.