Surely you turn on disk encryption on your drive then if an attacker yanks the drive and tries to read your database without your password they fail?
Surely you turn on disk encryption on your drive then if an attacker yanks the drive and tries to read your database without your password they fail?
Userspace encryption of user data has been almost universally rejected because there's no reasonable attack on it - Any attacker that has access to the data also has access to the encryption key.
It depends on the use case. Typing a password to unlock the database when the app is started is a popular approach (e.g., keepassx does this), but you can also hardcode/obfuscate it, fetch it remotely, etc.
> Userspace encryption of user data has been almost universally rejected
Any kind of encryption is better than none. However, an encrypted drive will add zero value if your data and OS can be accessed remotely.
So don't you mean there's no reasonable defense against an attack on it? If the "attack" is to just decrypt it with the decryption key the attacker also finds, that seems very reasonable. :-)
Of course if they share their computer, someone could install a keylogger and wait for them to type their passwords, but I guess that's an extra layer of security that may help a bit.