Hacker News new | past | comments | ask | show | jobs | submit login

Which is why if you care about sensitive data not being recoverable from failed media (eq. banking database, PII, mediacal records, etc.) you should always use full disk encryption (LUKS, bitkeeper, veracrypt, etc.).

That way anything one could recover from that device afterwards would be effectively random noise to them without the decryption key, regardless how the firmware of the device actually wrote the individual data blocks.




Or run from tmpfs without swap.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: