Comment by ryandrake
3 days ago
It's unexpected to anyone with intuition about how a computer traditionally is supposed to work. As a general principle, as a user, I expect a file on one computer to be usable on another computer. Or, at the very least, if I need to obtain some other thing from the original computer to "unlock" that file, I should be able to do it. The idea of a file that is only usable on a particular computer feels weird.
> As a general principle, as a user, I expect a file on one computer to be usable on another computer.
As a general rule, I expect a file on an encrypted disk to be unreadable for anyone who lacks the encryption key(s).
> if I need to obtain some other thing from the original computer to "unlock" that file, I should be able to do it.
You can export your passwords to a plain text CSV from the original computer.
As a general rule, I expect a file on an encrypted disk to be encrypted with a key derived from a password I provide.
I think it's time to update your expectations. Hardware security modules have been around for quite a while. You shouldn't assume that your chosen password is the only input to the key derivation, or even that the raw key itself will always be obtainable.
6 replies →
As a general rule, if I'm the user of both disks I expect to have the encryption key(s).
> You can export your passwords to a plain text CSV from the original computer.
Exporting a private key from a keychain is hard to automate (the password of the keychain is asked for all exports, and HAS to be typed manually IIRC).
The right way to do that is FDE, where you can't even mount the filesystem to see the files without having the decryption key.