← Back to context

Comment by ryandrake

3 days ago

It's unexpected to anyone with intuition about how a computer traditionally is supposed to work. As a general principle, as a user, I expect a file on one computer to be usable on another computer. Or, at the very least, if I need to obtain some other thing from the original computer to "unlock" that file, I should be able to do it. The idea of a file that is only usable on a particular computer feels weird.

> As a general principle, as a user, I expect a file on one computer to be usable on another computer.

As a general rule, I expect a file on an encrypted disk to be unreadable for anyone who lacks the encryption key(s).

> if I need to obtain some other thing from the original computer to "unlock" that file, I should be able to do it.

You can export your passwords to a plain text CSV from the original computer.

  • As a general rule, I expect a file on an encrypted disk to be encrypted with a key derived from a password I provide.

    • I think it's time to update your expectations. Hardware security modules have been around for quite a while. You shouldn't assume that your chosen password is the only input to the key derivation, or even that the raw key itself will always be obtainable.

      6 replies →

  • As a general rule, if I'm the user of both disks I expect to have the encryption key(s).

  • > You can export your passwords to a plain text CSV from the original computer.

    Exporting a private key from a keychain is hard to automate (the password of the keychain is asked for all exports, and HAS to be typed manually IIRC).

  • The right way to do that is FDE, where you can't even mount the filesystem to see the files without having the decryption key.