cukie · @cukie
47 followers · 131 posts · Server infosec.exchange

(1/2)

question for the masses. I want to check that I'm thinking about this the right way. Context is a laptop with a partition.

I see a lot of how-to articles floating around about using for LUKS decryption on device boot.
I understand that this gives convenience over a separate passphrase for decryption and still prevents:

  1. An adversary from removing the hard drive when your machine is off and decrypting it (because the adversary won't have the TPM to decrypt).

  2. An adversary from modifying anything in the secure boot chain and accessing a decrypted drive (because the device will then refuse to boot and decrypt the LUKS partition).

#linux #diskencryption #luks #tpm2

Last updated 3 years ago

The Hacker News · @thehackernews
402 followers · 2779 posts · Server social.tchncs.de