So, I'm going to do a bunch of reformatting etc on my laptop over the next 2 or 3 days to get it wiped and fde'd before I go to defcon, and getting it provisioned with all the ctf tooling I need. Any recs beyond just LUKS on the root partition? Should I do LUKS over swap too?
-
-
Replying to @hedgeberg
The right approach is to use ephemeral encryption for swap (assuming you don't care about hibernation). There should be a way to set up a dm-crypt mapping with a random key and automatically mkswap it on boot, on your distro (Gentoo has this). No need for LUKS.
1 reply 0 retweets 4 likes -
Replying to @marcan42 @hedgeberg
IIRC I have the same setup on my Arch box, I can double check the config if you use that.
1 reply 0 retweets 3 likes -
Replying to @marcan42
Yeah I would be using arch. Tbh I'm not worried that much about swap since I don't plan to have my laptop powered on between locations since sleep mode is wonky, though, so I might just, like, skip it?
2 replies 0 retweets 1 like -
Replying to @hedgeberg
If you have enough RAM not to need swap then just skip it. If you use swap at all then you need to encrypt it, otherwise it's a huge leak (stuff can and does stick around there).
1 reply 0 retweets 1 like -
Replying to @marcan42 @hedgeberg
Personally I haven't been using swap on most of my recent systems for some time now. Just dump more RAM in them.
1 reply 0 retweets 0 likes
Anyway this is how you do ephemeral encrypted swap on Arch if you choose to go that route: https://wiki.archlinux.org/index.php/Dm-crypt/Swap_encryption#Without_suspend-to-disk_support …
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.