defanor, to random

It is the "world #backup day", at least according to WorldBackupDay.com. I like the idea of having such a day, to serve as another nudge and a reminder to make and check backups, though WorldBackupDay.com is awkward, does not mention rsync in its software section. The "com" TLD looks suspicious, too, but it is better than nothing (except for potential private data leaks with online backup services).

I use primarily encrypted external HDDs (#ZFS or #LUKS with #ext4) and #rsync for personal backups, including rsync with "--dry-run --checksum" for scrubbing and checking before synchronization; quite happy that such tools are available, even though they are usually taken for granted, as are many other neat FLOSS tools we use regularly. Planning to add a USB stick to the list of storage devices, since it should be less fragile mechanically (even though less reliable otherwise).

RogerBW,
@RogerBW@emacs.ch avatar

@defanor GIven that my usual restoration use case is "I want that specific file/directory back", I'll particularly applaud backups that output as readable filesystems. It'll take a bit longer if I ever want to reset my entire machine to last Tuesday but it's much more useful until then.

talesofaprinny, to linux

How do I properly resize my LVM partitions when it is inside LUKS?

Do I have to boot in a USB to do it or can it be done while the crypt is open/being used? I need to resize my root partition.

@linux

talesofaprinny,

@atzanteol All's good. Yea, reason for the post was that even though I took the partitions offline it wouldn't still let me resize. So I think the best next move would be just booting into a USB and see if it lets me.

The whole disk well, only the boot is separated. The rest of the partition has the whole space controlled by LVM. Interestingly even though that may be the setup something was just rejecting my resize request.

Sadly have more to say but Mastodon limit is hitting haha. nutshell

atzanteol,

Did you already shrink the filesystem? I think lvresize will refuse to shrink if the FS is too big (not sure - I don’t shrink volumes often).

ghose, to archlinux
@ghose@gts.xmgz.eu avatar

Tales from the LUKS

do you have a handy or you usually travel with? they are small, light, cheap... convenient.

it's not that you store there Top Secrets (maybe!) but in case it was lost or stolen you will feel more relaxed if the drive was securely encrypted. LUKS

implements a platform-independent standard on-disk format for use in various tools. This facilitates compatibility and interoperability among different programs and operating systems[...]

I was to write a blogpost about it, but there are plenty of them available to use LUKS encryption in any platform. Just three here:

My usb-luks are automatically detected and mounted (after pass-phrase prompt) in both :archLinux: and :debian: 🥳

governa, to linux
@governa@fosstodon.org avatar
madargon, to privacy
@madargon@is-a.cat avatar

After more thinking related to my previous post (https://is-a.cat/@madargon/111845765590354051) I decided to add some kind of dead man's switch to my main laptop (to ensure disk #encryption would fully protect it in case of emergency). I read it could be possible to configure systemd-logind to shut down my computer automatically after long inactivity. So I tried to do it and now I have laptop shutting down in random moments, mostly after I open its lid after being long closed when turned on (as I understand it makes it suspended and systemd-logind doesn't work then), use it and then leave idle for 20-30 mins. And my goal was shutting it down after full 10+ h inactivity :blobfoxfacepalm:​
I am not sure WHAT I am doing wrong :blobcatfearful2:​

#privacy #security #Linux #systemd #LUKS

xgqt,
@xgqt@emacs.ch avatar

@madargon

10h+ is probably more than enough to have it drop to 0% battery.

So maybe you can just unplug it when you are gone :P

madargon,
@madargon@is-a.cat avatar

@xgqt it is much faster on "gaming" models. Very easy to achieve accidentally e.g. unplugging during room cleaning and not long time after laptop randomly shuts down :blobCat_happy:

linuxiac, to linux
@linuxiac@mastodon.social avatar

Cryptsetup 2.7.0 Unveils Advanced OPAL Hardware Encryption Support
https://linuxiac.com/cryptsetup-2-7-0-unveils-advanced-opal-hardware-encryption-support/

#linux #security #luks

amadeus, to linux
@amadeus@mstdn.social avatar

On no! 😳

  1. "File structure needs cleaning."
  2. boot from USB
  3. run fsck
  4. "file system damaged"
  5. "repair successful"
  6. reboot normal
  7. Firefox and Thunderbird profiles gone. 😏
    #ext4 #luks #linux #nvme #unneccesary
graves501,
@graves501@fosstodon.org avatar

@amadeus Weird stuff. I guess the actual problem is that you would use nano over vim/neovim :D :D

amadeus,
@amadeus@mstdn.social avatar

@graves501 😝🫣😅

abcdw, to guix
@abcdw@fosstodon.org avatar

@krevedkokun shared a cool thread about uki-bootloader implementation for guix, which brings alternative to grub and better encrypted root support. The solution has some drawbacks, but still very nice to see this work done!

https://yhetil.org/guix-patches/cover.1705465384.git.lilah@lunabee.space/

#guix #grub #uefi #grub2 #luks

graywolf,
@graywolf@emacs.ch avatar

@abcdw @krevedkokun

> and it's annoying to have to enter in the root password
twice

My patch was merged, so that is no longer necessary.

> The main drawback is lack of kernel generation rollback in the case
of a botched upgrade

Seems somewhat important caveat.

Nevertheless, it looks like an interesting approach. Not sure I will be brave enough to switch (soon) though.

abcdw,
@abcdw@fosstodon.org avatar

@graywolf @krevedkokun Haha, it's funny, a couple weeks ago we with @dgr were discussing 65002 patch series and planned to make a test qemu image to verify if it works.

Dominik created a repo for it: https://gitlab.com/slalomsk8er/rde-luks2-unlock-once

@graywolf Thank you very much for working on this!

kkarhan, to android German

:
A or rather [ - ] that natively integrates @torproject ( & ) as well as @fdroidorg and is -focussed like @tails in that it stores all & personal files on a -encrypted card.

Basically a "" or "" because it provides -alike functionality for and -.
https://www.youtube.com/watch?v=qYcErJc9N3o

kkarhan,

@torproject @fdroidorg @tails
I mean at worst one could use like a @Raspberry_Pi or if not a (lite) and make it a and brick like a or classic ...

Ideally with like a good thumb- and rugged case so it survives being flushed down the toilet...

if it takes standard 18650 / or even 21700 cells...
https://www.youtube.com/watch?v=sZWN65NqNOc
https://www.youtube.com/watch?v=Ad8CariVZ0M

kkarhan, (edited )

@torproject @fdroidorg @tails @Raspberry_Pi
But I guess a or port of that boots on and compatible would be a good start.

I'd even forego a fancy in exchange for a / like I do work towards in ...
https://www.youtube.com/watch?v=joJWOE2mn7Y

JustineSmithies, (edited ) to linux
@JustineSmithies@fosstodon.org avatar

Ok I'm interested to find out how many of you #Linux laptop users that use an encrypted root partition of some description actually use hibernate aka suspend to disk ?
Feel free to leave your reasons for using or not below.

#LUKS #ZFS

Please boost for a larger response.

Conan_Kudo,
@Conan_Kudo@fosstodon.org avatar

@JustineSmithies I don't because currently hibernation/S4 suspend is incompatible with Secure Boot and gets disabled when Secure Boot is in use.

JustineSmithies,
@JustineSmithies@fosstodon.org avatar

@hq1 @nowster Yes it could be compromised.

iMeddles, to selfhosted

After a request on the community on Lemmy, I wrote up how I use LUKS, Clevis, and Tang to give me network-bound encryption. This means that I can restart my servers as long as they're on my home network without worrying about having to log in to decrypt the drive, but if someone breaks in and steals my servers and turns them on anywhere else, the data on them is safe. https://i.am.eddmil.es/clevistang/

feudjais, to linux French
@feudjais@eldritch.cafe avatar

Can anyone help with #Linux ?

I am stuck on reinstalling my work machine. I wanted to try either #Manjaro or #Garuda.

I follow the simplest install possible (I erase the disk, etc.). The only thing I do is I encrypt my / partition with #Luks

When I reboot, I am prompted to enter a decrypt password and then it says :

error: access denied
error: disk cryptouuid/... not found
Entering rescue mode....
grub rescue >

Without encrypting, it works. But I need to encrypt it.

I could really use some help.

#Arch

milosz,
alexanderadam, to linux

Does anyone who's proficient with #LUKS and #LVM on #Linux know how possibly to rescue data? 🥺

https://serverfault.com/questions/1146929/how-to-rescue-an-encrypted-luks-partition-that-was-partially-modified-by-a-windo

The underlying system is @ubuntu but I don't think that it's specific to that.

Please share for a higher chance of getting help. 🙏🏻

alexanderadam,

I'm sorry for mentioning you @popey, but is there any chance that you know someone or that you have a resource that might help?

popey,

@alexanderadam Sorry, only the standard answer of "don't modify the disk, image it and work on the image"

GenghisKen, to fedora

So I'm rebuilding my main home dev system. I want everything except /𝚋𝚘𝚘𝚝 and 𝚜𝚠𝚊𝚙 to be encrypted and mirrored. I'm not really interested in getting into the mix; I don't see any added value. So what's the best path? Boot from a dist and set up RAID1 sets, and then install onto them? Or what?

I've typically used , but keeping current/upgrading has always been iffy or a pain. Maybe I should use ? users scared ne off years ago..

GenghisKen,

@frangdlt

Any opinion on a stable #Linux OS? #Fedora needs updating too frequently, and last I looked it didn't favour update-in-place, recommending complete new installs instead. Which is cool for cloud instances, but less so for home-grown organically-built personal home servers.. #Ubuntu maybe?

AdamBishop,
@AdamBishop@floss.social avatar

@GenghisKen Have updated Ubuntu in place on various machines for years without a hitch.

dwarmstrong, to gentoo
@dwarmstrong@fosstodon.org avatar

Stuck close to the Handbook and finished my first Gentoo Linux install in a VM. It boots! It lives! 🙂

Now to figure out LUKS encryption for the second install.

#gentoo #linux #luks

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • ngwrru68w68
  • tester
  • magazineikmin
  • thenastyranch
  • rosin
  • khanakhh
  • InstantRegret
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • tacticalgear
  • osvaldo12
  • normalnudes
  • cubers
  • cisconetworking
  • everett
  • GTA5RPClips
  • ethstaker
  • Leos
  • provamag3
  • anitta
  • modclub
  • lostlight
  • All magazines