• mazzilius_marsti
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 hours ago

    i use a yubikey and still have the ability to type my LUKs password in. Yubikey is just more convenience: plug in and it auto type the password field. On Fedora this means it populates the field with asterisks. Still, i think using password is the best method.

    With that said, i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop. So far i know of only Dasharo boot and the stuff from Purism that can do these…

    So the layout is: Boot verification -> LUKs-> your data

    Or if you have the juices and powers: Boot verification -> LUKS -> QuebeOS dom0 -> choose your Quebess.

  • irmadlad
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    12 hours ago

    I just manually type the password in. Not quit as elegant, but does the job.

  • irmadlad
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    9 hours ago

    Is there a down vote bot loose on Lemmy? Weirdness.

    • modem_down@thebrainbin.orgOP
      link
      fedilink
      arrow-up
      6
      arrow-down
      2
      ·
      13 hours ago

      Yes. Here are some common self-hosting scenarios:

      • Home server containing family files: scans, photos, device backups, …
      • Office server containing business files: sensitive documents, device backups, …
      • Web or email server containing websites, Fediverse instances, emails, etc

      In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

      Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

      Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

      However, there is more than one way to do that. Hence the question in my OP.

      • talkingpumpkin
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

        There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.

        The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.