I mean, it's encrypted as a single continuous chunk, so there's not really a benefit to 3 keys for 3 partitions instead of one, no? Idk, this is why I ask, my threat models may be totally bogus.
-
-
This Tweet is unavailable.
-
Replying to @AbeSnowman
Yeah I think I'm going to do this. Encrypt the main block, and then lvm after encryption.
1 reply 0 retweets 2 likes -
Replying to @hedgeberg @AbeSnowman
If all the volumes are on the same platter then CPU usage won't go up. You're I/O limted anyway. You can always encrypt multiple volumes then store the volume keys in the root filesystem and have them automatically decrypt on boot. In the end it depends on what exactly you want.
1 reply 0 retweets 5 likes -
At one point I had a laptop with a... rather complex RAID/crypto/LVM setup. Still only typed one passphrase on boot (for a LUKS loopfile!). There were good reasons for this mess back then, but now I just have an LVM on LUKS SSD and an LVM on raw dm-crypt HDD w/keyfile on SSD.pic.twitter.com/3oa11BqO8B
3 replies 6 retweets 34 likes -
This Tweet is unavailable.
-
Replying to @AbeSnowman @marcan42
Yeah sorry i don't have anything nearly that nice to compare against. did get it working though, and a lot faster than the last time i went through this whole mess, so thats something
1 reply 0 retweets 1 like -
-
Replying to @marcan42 @AbeSnowman
Nicest thing is having enough of an understanding of linux at this point to be able to do it mostly without reading any guides and being able to dd over my old filesystem and just have it work. i really love the linux disk model.
0 replies 0 retweets 4 likes -
This Tweet is unavailable.
Yeah, this is what I like about Linux in general. You can *understand* it. Once you do, guides serve more of a purpose of documenting what work other people have already done that you may or may not want to use (or build off of). Same reason I like Gentoo for userspace too.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
