check out GRUB_ENABLE_CRYPTODISK; in short, you can encrypt everything but grub and it's more practical than /boot-on-stick
-
This Tweet is unavailable.
-
This Tweet is unavailable.
-
-
Replying to @allgebrah @stribika
an attacker with write access can still edit my grub, but it requires more knowledge and has a smaller attack surface
1 reply 0 retweets 0 likes -
Replying to @allgebrah @stribika
I've had trouble with boot sticks in the past because I forgot to put them in during initramfs updates, too many moving parts
1 reply 0 retweets 1 like -
Replying to @allgebrah @stribika
but with only grub on the stick, it only breaks if I don't take care during incompatible grub updates, of which there are few
1 reply 0 retweets 1 like -
Replying to @allgebrah
how could I persuade you to write down how to set that up? cc
@stribika1 reply 0 retweets 0 likes
just google GRUB_ENABLE_CRYPTODISK I think - my only twist on it is that I put a keyfile in the initramfs
9:49 AM - 16 Nov 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.