I call this "The Pawn Shop Threat Model" ;)
And, IME it is likely to happen.
I call this "The Pawn Shop Threat Model" ;)
And, IME it is likely to happen.
All of these drives had Pii and personal photos. Some of the estate sale drives included pii of children and grandchildren.
They're usually formatted but not wiped, so even recuva was typically able to claw back all of the missing data and restore the whole drive.
Family photos, nudes, sex videos (homemade and professional), downloaded movies, pirated games, I've found them all.
If you're dumping a drive and you don't DBAN it first, other people getting to see your shit is 100% on you.
"What about unhappy exes?" Well if they really care about the kid and know the exact spouse is techy enough, they'll put their ego aside for the kid and ask their ex to do it.
Likely? How likely is it? I've never had a computer stolen, nor has anybody I personally know. So it doesn't seem to me like it's all that likely.
Personally, I find whole disk encryption to be more risky than it's worth. I much prefer encrypting things on a file-level instead.
I'm with you. If someone wanted to steal any of my computers, they'd have to break into my house. Possible, but also statistically unlikely, as I live in a reasonably safe community and lock my doors. I don't see the benefit of full disk encryption on a bunch of computers I keep in my home. For the special case of a laptop that is frequently taken out of the home and used in public, where thieves might be? Sure, encrypt it.
Personally I used LUKS encryption on a system76 laptop for 7 years and it worked fine - still going in fact. I was always worried about it failing especially after an update, but that never happened.
For backups to offline media I still do use file-level encryption though.
In about 300 person-years, we've had two laptops stolen. Both were stolen while the staff were on trips abroad, and the staff were both rather careless IMO.
There is a very real security vs. availability trade-off though. Is the average person more concerned with others reading their emails, viewing their pictures, seeing their tax returns, or are they more concerned with losing access to those things themselves?
Losing access to an encrypted drive is a very real possibility (people often forget their passwords, and are used to that being recoverable), and is the data loss is probably more impactful than privacy loss for many people.
That way I know what I'm signing up for.
Just put "encrypt? Yes no" in the on-boarding flow and let people know what the risks are and what they may be protecting against. I'd probably default to off because people don't read wizards and the last thing someone wants is to lose their entire HDD because they accidentally made a decision they didn't understand.
And maybe for a certain period of time they can nudge users to read about encryption and decide if it's right for them, or just easily disable that nudge. Maybe even basic education like "if you find yourself forgetting your password often then maybe encryption is not for you" or something like that.
Windows is already optimized for extracting as much value from customers as possible, may as well help them make at least one informed decision.
For business users with notebooks who fly around a lot or spend time in coffee shops, it's possible.
Quite a stretch. In almost 50 years of using computers every day, never had one stolen.
Defaults should be safe for most users. Power users are exactly the people who can deal with changing a setting. It’s constantly surprising to me when technical people insist that defaults should be optimized for technical people.
The main question is: What is the biggest risk: theft or data corruption.
In my experience, corruption and ransomware is more common so FDE should be off for households desktops or laptops, as these rarely leave the house. A business tends to have managed devices and data loss is a legal nightmare, so FDE should be on. The main thing is: people should be able to choose.
No, it’s not.