Sounds like a misnomer to me.

  • Nawor3565@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    26
    ·
    26 days ago

    Cause there’s no user data stored on EFI, and saying “almost-full-disk-except-for-the-EFI-partition-encryption” is a bit cumbersome and, obviously, pedantic.

    • onlinepersona@programming.devOP
      link
      fedilink
      arrow-up
      1
      ·
      26 days ago

      Sure, but unencrypted means it can be tampered with. The bootloader can be modified to write your password to disk and once you boot, submit that to a server somewhere - or worse.

      • dgdft@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        26 days ago

        There’s also PXE boot, secure boot, carrying around a live image on a flash drive, etc.

        But any attacker advanced enough to tamper with your EFI partition in an evil-maid scenario has plenty of other options to log and steal your encryption passphrase, so it’s generally a moot point.

          • dgdft@lemmy.world
            link
            fedilink
            English
            arrow-up
            10
            ·
            26 days ago

            Absolutely not — the skill level needed to tamper with a bashrc, pull credentials + keys, or generally hunt for sensitive info on an unencrypted disk is worlds apart from the skill level needed to modify an EFI binary.

          • spiffpitt@lemmy.world
            link
            fedilink
            English
            arrow-up
            7
            ·
            26 days ago

            security isn’t real, just increasing deterrence for attackers.

            if you can access something, they can access it, it’s just a matter of effort needed to get there.

      • HubertManne@piefed.social
        link
        fedilink
        English
        arrow-up
        1
        ·
        26 days ago

        wait wait. the concern here is the unencrypted partition rather than the password to the encrypted disk being known???