And which user would you put in charge of decrypting the drive?
I vote for Bob from QA, he's always around.
I vote for Bob from QA, he's always around.
This also allows you to set up other keys, so that for example a company IT department can have a recovery key for the computer without needing to know your password.
This means your disk encryption security is now the limited by the worst password of any user, but that’s still a million times better than having the key be available to the system with no password at all.
it's not perfect and it's a lanky chain to keep maintaining, but it's not un-doable.