User avatar
dmiException 💽 @domi@donotsta.re
10mo
just realized that all linux full-disk-encryption tutorials which suggest using GRUB and LUKS1 for /boot, then storing a binary key for rootfs on /boot so you only type a password once are effectively downgrading LUKS2 security back to LUKS1 levels.

that seems Bad. why was this ever recommended by
any distros?
3
0
0
0
User avatar
WeirdTreeThing @weirdtreething@donotsta.re
10mo
@domi is there even any good way to have an encrypted boot partition
2
0
0
0
User avatar
10mo
@weirdtreething @domi do you need encrypted boot if you have some way to make sure that everything you start is signed?
2
0
0
0
User avatar
walnut 🌱 @walnut@thesoftestpaws.net
10mo
@ellis @weirdtreething
No, you don't need encrypted boot. With encrypted boot you need to have grub signed (only grub is capable of encrypted boot, with the downsides that
@domi described).

For everything else you'll need to make a unified kernel image because it's not possible to sign the intramfs.
:neocat_heart@transfem.social:1
0
0
0
1