Crossposted from https://thebrainbin.org/m/[email protected]/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
Crossposted from https://thebrainbin.org/m/[email protected]/t/1840283
Which approach do you think is better, and why?
Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.
The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.
Some people are fine with down time/inconvenience in exchange for security.
I have my boot drive on a secured USB and LUKS keyfile with the rest of the partitions on an encrypted SSD and data on encrypted HDDs.
In a smash and grab (or fascist government gestapo smash and grab), the server is pretty impossible to steal information from (inject illegal content to in order to fabricate evidence) without the USB and they can’t simply inject boot malware either. A network device is almost always findable either by cables or WiFi broadcast analyzing.
Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.
tang
Thanks. TIL about Clevis/Tang.