>> The downside is that they keyfile sits on an unencrypted disk every
>> time the machine is shutdown correctly.
>>
>> Not sure if this exactly answers your scenario but it is a start.
>
> The problem with having it written to disk is that it is easily recovered.
> All an attacker would have to do is find where it was written and recover
> it. Is there a way to avoid that? Too bad I can't keep a RAM drive
> active when the system is off. That would be the best solution. That
> way, if they unplugged it, it's gone...
The Gigabyte i-RAM might come in handy in this scenario.
--
Lukasz
Received on Jan 13 2009