defanor, to random

It is the "world #backup day", at least according to WorldBackupDay.com. I like the idea of having such a day, to serve as another nudge and a reminder to make and check backups, though WorldBackupDay.com is awkward, does not mention rsync in its software section. The "com" TLD looks suspicious, too, but it is better than nothing (except for potential private data leaks with online backup services).

I use primarily encrypted external HDDs (#ZFS or #LUKS with #ext4) and #rsync for personal backups, including rsync with "--dry-run --checksum" for scrubbing and checking before synchronization; quite happy that such tools are available, even though they are usually taken for granted, as are many other neat FLOSS tools we use regularly. Planning to add a USB stick to the list of storage devices, since it should be less fragile mechanically (even though less reliable otherwise).

talesofaprinny, to linux
@talesofaprinny@mastodon.social avatar

How do I properly resize my LVM partitions when it is inside LUKS?

Do I have to boot in a USB to do it or can it be done while the crypt is open/being used? I need to resize my root partition.

#linux #lvm #luks @linux

ghose, to archlinux
@ghose@gts.xmgz.eu avatar

Tales from the LUKS

do you have a handy or you usually travel with? they are small, light, cheap... convenient.

it's not that you store there Top Secrets (maybe!) but in case it was lost or stolen you will feel more relaxed if the drive was securely encrypted. LUKS

implements a platform-independent standard on-disk format for use in various tools. This facilitates compatibility and interoperability among different programs and operating systems[...]

I was to write a blogpost about it, but there are plenty of them available to use LUKS encryption in any platform. Just three here:

My usb-luks are automatically detected and mounted (after pass-phrase prompt) in both :archLinux: and :debian: 🥳

governa, to linux
@governa@fosstodon.org avatar
madargon, to privacy
@madargon@is-a.cat avatar

After more thinking related to my previous post (https://is-a.cat/@madargon/111845765590354051) I decided to add some kind of dead man's switch to my main laptop (to ensure disk would fully protect it in case of emergency). I read it could be possible to configure systemd-logind to shut down my computer automatically after long inactivity. So I tried to do it and now I have laptop shutting down in random moments, mostly after I open its lid after being long closed when turned on (as I understand it makes it suspended and systemd-logind doesn't work then), use it and then leave idle for 20-30 mins. And my goal was shutting it down after full 10+ h inactivity :blobfoxfacepalm:​
I am not sure WHAT I am doing wrong :blobcatfearful2:​

linuxiac, to linux
@linuxiac@mastodon.social avatar

Cryptsetup 2.7.0 Unveils Advanced OPAL Hardware Encryption Support
https://linuxiac.com/cryptsetup-2-7-0-unveils-advanced-opal-hardware-encryption-support/

#linux #security #luks

amadeus, to linux
@amadeus@mstdn.social avatar

On no! 😳

  1. "File structure needs cleaning."
  2. boot from USB
  3. run fsck
  4. "file system damaged"
  5. "repair successful"
  6. reboot normal
  7. Firefox and Thunderbird profiles gone. 😏
    #ext4 #luks #linux #nvme #unneccesary
abcdw, to guix
@abcdw@fosstodon.org avatar

@krevedkokun shared a cool thread about uki-bootloader implementation for guix, which brings alternative to grub and better encrypted root support. The solution has some drawbacks, but still very nice to see this work done!

https://yhetil.org/guix-patches/cover.1705465384.git.lilah@lunabee.space/

Fnargoy, to linux German

Spaß mit #Linux, heute mal wieder #grub2:

Nach Systemupdate (Lubuntu 23.04 → 23.10) bootet Grub nach Eingabe des Plattenkryptokeys ins … BIOS?! WTF?!??

Keine Fehlermeldung, keine Busybox, direkt kommentarlos ins BIOS. o_O

Also Livestick rausgekramt und erstmal rumgesucht, aber alle beantworteten Fragen trafen mein Problem nicht, und DenverCoder9 hat seine Lösung mal wieder nicht gepostet … narf
(https://xkcd.com/979/ ^_^)

1/2

kkarhan,
@kkarhan@mstdn.social avatar

@Fnargoy ja, das ist nicht so wie #LUKS genutzt werden sollte!!!

kkarhan, to android German
@kkarhan@mstdn.social avatar

:
A or rather [ - ] that natively integrates @torproject ( & ) as well as @fdroidorg and is -focussed like @tails in that it stores all & personal files on a -encrypted card.

Basically a "" or "" because it provides -alike functionality for and -.
https://www.youtube.com/watch?v=qYcErJc9N3o

JustineSmithies, (edited ) to linux
@JustineSmithies@fosstodon.org avatar

Ok I'm interested to find out how many of you #Linux laptop users that use an encrypted root partition of some description actually use hibernate aka suspend to disk ?
Feel free to leave your reasons for using or not below.

#LUKS #ZFS

Please boost for a larger response.

iMeddles, to selfhosted

After a request on the community on Lemmy, I wrote up how I use LUKS, Clevis, and Tang to give me network-bound encryption. This means that I can restart my servers as long as they're on my home network without worrying about having to log in to decrypt the drive, but if someone breaks in and steals my servers and turns them on anywhere else, the data on them is safe. https://i.am.eddmil.es/clevistang/

chpietsch, to GNOME German
@chpietsch@digitalcourage.social avatar

Auf einem 10 Jahre alten Desktop-Computer für Bürozwecke mit 8 GB RAM und einer 4-Kern-CPU ohne Hyperthreading habe ich einige Linux-Distributionen ausprobiert, um zu testen, ob man damit noch gut arbeiten kann.

Wie erwartet, liefen und nicht ganz flüssig (getestet unter ).

Aber: (mit ) und (mit ) laufen sehr flott.

An MX Linux hat mich anfangs gestört, dass die von XFCE gewohnten Tastenkürzel (wie z.B. Alt-F10 zum Maximieren eines Fensters) nicht funktionierten. Die Lösung dafür war schnell gefunden:
Startmenü → Einstellungen → Fensterverwaltung → Tastatur → Klick auf [Auf Standardwerte zurückstellen].

Jetzt bin ich mit MX Linux sehr zufrieden:

  • stabiler -Unterbau
  • vorinstallierte Firewall mit Oberfläche
  • einsteigerfreundliche Programm- und Updateverwaltung, die Debian-Pakete und unter eine Haube bringt.

Darf bleiben.

/

chpietsch,
@chpietsch@digitalcourage.social avatar

Was mir an und auch gefällt: Im Installer ist es total einfach, die zu aktivieren. Im aktuellen Debian-Installer ist das z.Z. komplizierter als vor ein paar Jahren.

MX Linux verwendet dabei im Unterschied zu Linux Mint und Debian komischerweise nicht + , sondern nur LUKS.

feudjais, to linux French
@feudjais@eldritch.cafe avatar

Can anyone help with #Linux ?

I am stuck on reinstalling my work machine. I wanted to try either #Manjaro or #Garuda.

I follow the simplest install possible (I erase the disk, etc.). The only thing I do is I encrypt my / partition with #Luks

When I reboot, I am prompted to enter a decrypt password and then it says :

error: access denied
error: disk cryptouuid/... not found
Entering rescue mode....
grub rescue >

Without encrypting, it works. But I need to encrypt it.

I could really use some help.

#Arch

alexanderadam, to linux
@alexanderadam@ruby.social avatar

Does anyone who's proficient with and on know how possibly to rescue data? 🥺

https://serverfault.com/questions/1146929/how-to-rescue-an-encrypted-luks-partition-that-was-partially-modified-by-a-windo

The underlying system is @ubuntu but I don't think that it's specific to that.

Please share for a higher chance of getting help. 🙏🏻

GenghisKen, to fedora

So I'm rebuilding my main home dev system. I want everything except /𝚋𝚘𝚘𝚝 and 𝚜𝚠𝚊𝚙 to be encrypted and mirrored. I'm not really interested in getting into the mix; I don't see any added value. So what's the best path? Boot from a dist and set up RAID1 sets, and then install onto them? Or what?

I've typically used , but keeping current/upgrading has always been iffy or a pain. Maybe I should use ? users scared ne off years ago..

nixCraft, to linux
@nixCraft@mastodon.social avatar

filesystem comparison

kkarhan,
@kkarhan@mstdn.social avatar

@ernstdemoor @nixCraft that's because on basically all , and is handled by dedicaded subsystems like and / respectably, thus not on filesystem but OS level...

This allows extra cursed shit like a an encrypted & RAID-5 running NTFS - Tho that won't be useable by anything but Linix and I disrecommend it almost as hard as mixing hardware RAID controllers and/or dmraid with ZFS.

Remember: NEVER EVER LIE TO ZFS!!!

dwarmstrong, to gentoo
@dwarmstrong@fosstodon.org avatar

Stuck close to the Handbook and finished my first Gentoo Linux install in a VM. It boots! It lives! 🙂

Now to figure out LUKS encryption for the second install.

rewarp, to linux

Every few weeks I meet a system I set up with full disk encryption on luks1, sendiri cari pasal, upgrade it to luks2, then :akasad: when the system doesn't boot.

In an hour of troubleshooting where I get to the verge of reinstalling the system but still myself because that's ludicrously inefficient, I remember luks2 doesn't work with grub and revert all my upgrades. System then merrily boots.

This has happened twice.

I expect my brain to forget about this again in a few weeks so this time I'm reminding myself by writing it down.

dsoft, to ubuntu
@dsoft@techhub.social avatar

23.10 adds based Full Disk Encryption. I think this is a step in the right direction. LUKS password based encryption is not ideal for many non geeky Desktop users.

However, I personally use with USB-stick/SD-card key based authentication so far.

dsoft,
@dsoft@techhub.social avatar

@Mawoka requires an extra password step before the user login is again so users are promoted to enter two different logins before they can access their system. Also changing the user password via settings will not change LUKS password which might lead to confusion. Also there is no simple way to change LUKS password with a few mouse clicks on most desktops. I am talking about when my parents and other elderly or non tech savvy people are using Linux. TPM based encryption eliminates some of these usability issues and provides similar experience they are used to on Windows or Macs.

There are however TPM based vulnerabilities that one needs to keep in mind if you are trying to host any sensitive data on those systems.

So TPM based may not be the most secure but provides reasonable security without adding any usability overhead.

neurovagrant, to random
@neurovagrant@masto.deoan.org avatar

deleted_by_author

  • Loading...
  • kkarhan,
    @kkarhan@mstdn.social avatar

    @neurovagrant same...

    I did the ardurous process of migrating all my stuff from #NTFS to #LUKS-encrypted #ext4 on all drives and it just works so flawlessly on every Linux machine...

    In fact, there are even Apps for those, but they can only deal file containers, not encrypted drives...
    https://f-droid.org/de/packages/com.sovworks.edslite/

    But to shove just media around, #ext4 will work just fine...

    alex_02, to linux

    Anyone know if I can clone a luks encrypted ssd onto a new nvm ssd of same size? It is so I can transfer linux over to a new drive.

    beebles, to random
    @beebles@beebl.es avatar

    I've mentioned this but I'm gonna make a real post.

    If you are setting up Windows 11, select "English (World)" as your language (English Europe also works), and you will have NONE of the third party bloatware installed.

    No Candy Crush, no Netflix, just the first party apps

    Please do share this info with anyone who may be setting up Windows soon

    https://www.ctrl.blog/entry/windows-ooberegion-bloatware.html

    kkarhan,
    @kkarhan@mstdn.social avatar

    @Theholypumpkin @toby @bunsenlabs

    Also one major "can't use" for me - regardless of and - is the lack of a convenient setup in both and @ubuntu / for @Raspberry_Pi / .

    Not gonna argue the lack of @tails or official @torproject but to make viable and useable, it just can't be restricted to external media or having to manually fiddle around, cuz that's a pain in the rear.

    kkarhan,
    @kkarhan@mstdn.social avatar

    @Theholypumpkin @toby well, unlike @bunsenlabs and @ubuntu on , @Raspberry_Pi & on doesn't support or setting up at all.
    Which IMHO is not excuseable since even if the -made didn't have any Cryptograpy-Acceleration integrated whatsoever, the performance of is still faster than any microSD or eMMC on the market.
    Espechally since that feature predates the Raspberry Pi by over half a decade: even @opensuse 10.2 offered it.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • InstantRegret
  • rosin
  • modclub
  • Youngstown
  • khanakhh
  • Durango
  • slotface
  • mdbf
  • cubers
  • GTA5RPClips
  • kavyap
  • DreamBathrooms
  • ngwrru68w68
  • JUstTest
  • magazineikmin
  • osvaldo12
  • tester
  • tacticalgear
  • ethstaker
  • Leos
  • thenastyranch
  • everett
  • normalnudes
  • anitta
  • provamag3
  • cisconetworking
  • lostlight
  • All magazines