Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

2024 audit - SEC-01-017 WP3: Lack of Full Disk Encryption #7296

Open
zenmonkeykstop opened this issue Oct 29, 2024 · 0 comments
Open

2024 audit - SEC-01-017 WP3: Lack of Full Disk Encryption #7296

zenmonkeykstop opened this issue Oct 29, 2024 · 0 comments

Comments

@zenmonkeykstop
Copy link
Contributor

Servers lack full disk encryption, risking data theft via physical access to hard drives.
Attackers may dump server content or recover data from damaged hardware. While
daily automatic reboots make physical access harder to exploit, using full disk encryption
can easily address the risk from hardware replacement scenarios

This is a known issue that is currently mitigated by having all source data and messages encrypted at rest. See #816 for details. We will consider further work on this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant