Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It once occurred to me that it's possible to encrypt the disk completely and put bootloader/kernel/etc on a flash drive attached to your keyring (the physical kind).

Then it all boils down to BIOS security. With physical WP pins on flash chips it ought to be possible to make BIOS reflashing a reasonable PITA, especially for someone who wasn't prepared for such surprise.



This wouldn't prevent the computer from booting into a new key-stealing bootloader newly installed on the hard disk. You probably wouldn't even notice that the computer wasn't actually booting from the USB drive.


Put the computer in transparent case and replace HDD top cover with glass :)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: