you are viewing a single comment's thread
view the rest of the comments
[–] 11 points 2 years ago

Storing the encryption keys in the Credentials Manager (Windows) or the Keychain (macOS, Linux) would be a better choice than a plaintext file.

And using Bitlocker / VeraCrypt / Filevault / LUKS will at least protect the data at rest.

But as you said, it's game over if the machine is compromised.

  • source
  • parent