[Discuss] Full disk encryption

Richard Pieri richard.pieri at gmail.com
Tue Jan 3 19:48:39 EST 2012


On Jan 3, 2012, at 9:09 AM, Kyle Leslie wrote:
> 
> One of the huge benefits I think is that the encryption keys/recovery keys
> can be stored in AD.  So that if you need to unlock or change the drives
> around you don't need to have the user store that some place to get
> lost/stolen.  It stores in AD and can be recovered when we need it.

This is, of course, the singular benefit of key escrow.  Of course, if your AD is compromised then the attacker has access to *all* of your escrowed keys.

--Rich P.




More information about the Discuss mailing list