> full disk encryption was always of dubious value
On my work laptop, I have the following (because it's simply harder to do development remotely than it is locally):
- Populated onboarding documents, containing everything you would need to steal my identity. These represent my copy of these contracts.
- A local checkout of our code
- Network passwords (encrypted in the repo, but decrypted locally since I need them to deploy). Working to remove these, but they exist now.
- Complete topology to the entire corporate network.
- Logged in email access with a jucy number of archived emails.
- Logged in to various corporate assets from bug trackers to CMS systems, to git frontends...
Now then, an attacker could certainly grab my open laptop out of my hands, and outrun me, all while keeping the laptop from going into screensaver mode. Not too hard for your average federal arrest, but a lot harder for your average opportunist.
If they get my laptop while the lid is closed, or screensaver active, they get nothing but the laptop. Without FDE, they get everything.
It's all about limiting your attack surface.
> since the connection dropped
SSH connections don't magically terminate, by the way: it requires the server to be configured with connection timeouts, and for your client to be inactive long enough to trigger the timeout.
Otherwise, you can change connections, your computer can go to sleep, you can run on mobile with a terrible connection... all while keeping the same open session.
This means your setup just as vulnerable to pickup-and-run attacks as one protected by FDE, with the added downside of their ability to capture data out of your application caches even if they go the with the opportunistic route.