Gerrit :linux: · @gerrit
9 followers · 160 posts · Server social.olchis.net
SPdeValk 🐘️ ☑️ · @sjosjo
38 followers · 235 posts · Server mas.to

Now I tried to achieve the same (including encrypted /boot) with a Standard 12 NetInstall.

This time using having one Volume Group with separate Logical Volumes for root, swap and home

Pure hell!

This involved switching to a different TTY during install and booting into Rescue Mode after install.

When will get an official patch to *fully* support ? This was the biggest hurdle to overcome. Eventually got it working, albeit using LUKS1

#luks2 #grub #lvm #debian

Last updated 1 year ago

ricardo :mastodon: · @governa
1078 followers · 7329 posts · Server fosstodon.org

5.14 Ships with Automatic Migration to :linux: 🔒

linuxiac.com/tails-5-14-ships-

#tails #luks2

Last updated 1 year ago

lave 💙💛 · @lave
12 followers · 471 posts · Server mstdn.social

@gnulinux Danke für die Artikelreihe!
Mittlerweile ist es dank überraschend einfach, - zu installieren. Nach vielen Installationstests scheint mir tatsächlich aber nur Gnome eine brauchbare Oberfläche out of the box zu bieten. KDE und Cinnamon brauchen einige Nacharbeit, sway wird gar nicht erst gestartet.
Top: -Verschlüsselung ( ist leider immer noch auf (1)) und default bei Gnome und sogar bei KDE 😊

#wayland #luks #manjaro #luks2 #Linux #arch #Archinstall

Last updated 1 year ago

yajas · @yajas
9 followers · 47 posts · Server mastodontech.de

Die Maintainer des -Projekts haben in Version 5.13 neu das Tool curl ergänzt und setzen standardmäßig auf für verschlüsselte Laufwerke.
heise.de/news/Anonymisierendes

#tails #luks2 #linux

Last updated 1 year ago

ricardo :mastodon: · @governa
1026 followers · 6655 posts · Server fosstodon.org

5.13 Enables by Default for Persistent Storage and Encrypted Volumes. :linux: 🔒

9to5linux.com/tails-5-13-enabl

#tails #luks2

Last updated 1 year ago

Cyril Brulebois · @CyrilBrulebois
217 followers · 501 posts · Server mamot.fr

It seems my understands both argon2i and argon2id now…

#grub #cryptodisk #luks2

Last updated 1 year ago

Christian Pietsch 🍑 · @chpietsch
3659 followers · 12076 posts · Server digitalcourage.social

@mjg59

Thank you for sounding the alert!

I identified a minor issue with your otherwise nice explanation: According to my sources (man cryptsetup, ), all varieties are memory-hard. RFC 9106 is even titled “Argon2 Memory-Hard Function for Password Hashing and Proof-of-Work Applications”.

However, given that there are known attacks against , it seems wise to use instead. It is also what is recommended in the RFC.

As a user, I just checked the state of affairs there:

The cryptsetup that comes with QubesOS 3.x used , and those who did an in-place upgrade to 4.x still have that unless they converted to manually (as detailed in the migration guide).

The cryptsetup in QubesOS 4.x uses , but it still defaults to unfortunately.

#luks2 #luks1 #qubesos #Argon2id #argon2i #argon2 #rfc9106

Last updated 1 year ago

Daniel · @dad
593 followers · 8884 posts · Server mastodon.eole.education

Now that I made some changes to build image with root filesystem over volume, my librem5 now became my day to day device 👍

salsa.debian.org/Mobian-team/m

Thanks my , you did a good job even if you are quite slow.
If I find the way to repair the microphone, I'll give you to someone 👋

(cc @mobian)

#mobian #librem5 #luks2 #pinephone

Last updated 1 year ago

Andrei G. :unverified: · @ndrei
44 followers · 281 posts · Server fosstodon.org

had a couple of good talks around and their applicability beyond web - login, authentication, unlocking, etc.

has a good article about these talks[1] and you can find the full presentations on 's website[2].

[1] lwn.net/Articles/923656/
[2] fosdem.org/2023

fosdem.org/2023/schedule/event
fosdem.org/2023/schedule/event

#Fosdem2023 #fido2 #ssh #luks2 #lwn #fosdem

Last updated 1 year ago

moji · @moji
80 followers · 867 posts · Server dresden.network

If you plan to use Grub 2.06 with LUKS2 note that:
> - Argon2id (cryptsetup default) and Argon2i PBKDFs are not supported (GRUB bug #59409), only PBKDF2 is.
> - grub-install does not support creating a core image that could be used for unlocking LUKS2.
(wiki.archlinux.org/title/GRUB#)

Just had a hard long time debugging because I assumed full support which is not the case yet.

Also `grub-mkconfig` or `grub-install` do not bother to warn you about any incompatibility. The crypto commands are just silently omitted. 😑

#grub #grub206 #luks #luks2 #linux #bootchain

Last updated 2 years ago

lave 💙💛 · @lave
9 followers · 266 posts · Server mstdn.social

@Cheatha Da stellen sich mehrere Fragen: Soll eine Festplatte oder eine SSD verschlüsselt werden? Komplett oder nur eine Partition? Mit oder ohne Swap-Speicher? LUKS1 (geht mit GRUB, 8 Schlüssel) oder (32 Schlüssel)? Und muss es unbedingt sein? Ob BIOS oder EFI ist glaub ich eher egal, außer dass EFI grundsätzlich eine eigene Boot-Partition braucht. Und auf LVM würde ich auch verzichten, wenn man es nicht wirklich braucht.
Ich bin eher bei zu Hause, hab aber wegen 32 Bit ein Netbook mit am Laufen, dessen Installer Verschlüsselung mustergültig beherrscht, auch LUKS2 (noch sehr selten). Deswegen hab ich das reine Debian da wieder runtergeworfen…

#mxlinux #manjaro #Debian #luks2

Last updated 2 years ago