Thumbdrive products are a good step in the right direction, but by far not
long enough. Another approach is needed.
I think of them as actually a large step in a silly direction.
Having a USB drive with a convenient on/off drive for times that
it's physically awkward to unplug/replug is usually good enough.
Leave the thing attached to your keyring, and only turn it on
when you need it.  The security functions come from protecting the device,
and from using a password for a crypto file system to mount the drive,
which is what makes using the stolen one impractical.
If your threat model doesn't involve NSA-quality cops, you're fine,
and if it does involve them, the device is nowhere near strong enough
to add value beyond what your well-chosen passphrase does.

If your threat model includes modified software on the PC,
then it needs to include having the PC suck down everything
it finds there when you do put your thumb on it,
so it's not really much extra protection there.

Reply via email to