Security After Secure Boot

Question asked by Greg Davies on Oct 21, 2016
How do I secure the contents of the root filesystem after a secure boot?


I have an application built on Yocto 3.14.52 that's deployed on an SD card within the product. The root filesystem contains sensitive information, and I'm concerned that unlike with on-chip memory, an attacker can just pop out the SD card and access the contents, no matter how secure the boot process is.


Is there a recommended approach to this with Yocto?