But yes, if the author drops all security thread related to encryption at rest, then encryption at rest is useless. I agree.
But yes, if the author drops all security thread related to encryption at rest, then encryption at rest is useless. I agree.
The point of my article was not "Encryption-At-Rest Is Bad" as you seem to have taken it to mean.
Rather, the point is that other techniques, when you sit down and actually think them through, do not provide any significant value over just phoning it in with Full Disk Encryption.
How you get from "software libraries that encrypt-at-rest routinely fail to provide value on top of full disk encryption" to "Scott says FDE is bad" is unclear.
Additionally: From a software perspective, the risks you all outlined are morally equivalent to the hard drives grew legs and walked because they are the same risk; namely, loss of control of the actual hard drives.
The article in question is focused on threats when those drives are plugged in and the keys are being used to encrypt/decrypt data. As several others have pointed out already, I explicitly state this, repeatedly. I don't know how to make it more clear.
So not only are you not adding anything to the article. You actively try to dismiss that the author has thought the cases you bring up through (and calling them out as narrow minded on false grounds).
I think we all would love to see a risk that is mitigated by encryption at rest and is not already being mitigated by disk encryption.