At the time of writing, there are already other replies to this comment how "it's mandatory today to encrypt drives" without any qualifiers. I am growing more and more frustrated by people who try to force security measures like this "because it is more secure that way" without first taking a look at the risks, impacts and associated costs. I think they simply force these security measures on others to feel good about their choices.
It was a breath of fresh reasonability when I found out that apt intentionally uses only HTTP instead of blanket HTTPS everywhere because the packages are signed, therefore they can be verified by the client, and using HTTP allows easier caching with cache proxies and such.