#FDE

2025-09-23

Rogue disk plugged into your #Linux? #openSUSE’s advanced #FDE setup uses #TPM PCRs to detect fake rootfs and halt booting. Bonus: automatic policy updates after updates. #SecureBoot news.opensuse.org/2025/07/18/f

2025-09-21
2025-08-21

Curious about what the future holds for Tumbleweed & #MicroOS? In this #oSC25 talk, explore advancements like #FDE with TPM/FIDO2, transactional-update tweaks, BLS in #GRUB2, systemd‑sysext, #sndiff, and so much more! youtu.be/MPMrlUj1sVA?si=6KA153

2025-08-20

Worried about rogue devices compromising your encrypted #Linux system? Discover how #openSUSE combines #TPM2, #FIDO2, and measured boot to fortify #FDE installation. news.opensuse.org/2025/07/18/f

2025-08-19

Boot-time trust, #TPM2 sealing, and stopping fake rootfs attacks; #openSUSE’s new Full Disk Encryption defenses are wild. Read the #tech deep-dive. #infosec #openSUSE #TPM2, #PCR #FDE #sysadmins #security #opensource news.opensuse.org/2025/07/18/f

2025-08-18

If you use #LUKS for #FDE and have fast disks, you should read my last blog post.
The default settings cut the performance 90% vs unencrypted in synthetic testing. Real world would probably not be as bad but still, with some quick settings we got it back up to 50%, which probably means 90% in real world.

This was for a big RAID10 array with 10 really fast NVME disks, I have not looked at if this happens also on single disks. Defaults might also have changed since I did the testing early last year.

blog.nyman.re/2025/08/18/luks-

It's a really long #blaugust2025 post to make up for the recent micro blogging :-)

🚀 Несерьёзный Выдумщик 👨‍🔬grumb@shitpost.poridge.club
2025-08-08

Наиболее весёлое из полнодискового шифрования через #LUKS? Что на многих ноутбуках используются AT-клавиатуры и ввести пароль для доступа к диску можно лишь при наличии активного atkbd модуля в образе initramfs.
Или же подключив usb-клавиатуру, если слетело что-то в системе из-за обновлений и некорректно собрался initramfs.
Т.е. на десктопах с этим проще, а вот на ноутах народ часто забывает о такой вещи. И не важно с каким загрузчиком EFI-шным — systemd-boot или же GRUB.

На некоторых ноутах приходится ещё и
atkbd.reset=1 использовать, из-за определённых заморочек\багов в EFI\UEFI от производителя материнской платы.
Поскольку могут возникать проблемы, когда при перезагрузке ноутбука клавиатура просто не работает. И надо его тупо выключить и подождать секунд 30 если работает с батареи или же пару минут, если работает от сети. Только после этого получится будет работать клавиатура при запросе пароля для доступа к шифрованным разделам NVMe/SSD/HDD.
Например, было такое лично у меня на выданном Asus ZenBook в районе 2022-2023 годов.

А так, в целом, за последние пять лет
#LUKSv2 лишь радовал, если понимаешь что нужно и делаешь изначально всё c #Argon2 и потому приходится разобраться с тем, каким должен быть initramfs и загрузчик в системе.

#linux #crypto #fde #криптография

2025-08-06

How secure is your Full Disk Encryption? #openSUSE digs deep into mitigating rogue device attacks using #TPM2, #PCR extensions, and custom #initrd validation. A must-read #FDE for #sysadmins & #security pros. #opensource news.opensuse.org/2025/07/18/f

2025-07-21

Think your encrypted #Linux drive is safe? Think again. Dive into how #openSUSE tackles rogue device attacks with #TPM-backed Full Disk Encryption. #FDE. #Security #opensource news.opensuse.org/2025/07/18/f

2025-07-15

What's next for #openSUSE Tumbleweed and #MicroOS? Catch this #oSC25 talk covering the latest work from the Future Technology team to include #FDE with TPM/Fido2, YaST2 improvements & more. See how security & flexibility are being taken to the next level! youtu.be/MPMrlUj1sVA?si=bMjxsJ

2025-06-18

🔗 Expand your faith network, & connect with other Christian entrepreneurs through the Faith Driven Entrepreneur Study. 📝 🎓
It's completely FREE! 👉 Join me at ianmayer.com/fde #FaithDriven #FDE

2025-05-31

What’s next for #Tumbleweed & #MicroOS? From #FDE to #TPM and more. Join us at this year's #openSUSE Conference. #Endof10 events.opensuse.org/

R.L. Dane :Debian: :OpenBSD: 🍵 :MiraLovesYou:rl_dane@polymaths.social
2025-05-12

@alcinnz

That's ok, I think it's going to be a mystery in the #BSD world for years to come. ;)

#FreeBSD #GELI #FDE

Lucas de Senaseninha@bsd.network
2025-04-27

OpenBSD users, can you tell me your experience of full-disk encryption on a SSD?

Is the encryption overhead noticiable compared to plain SSD? Or is it as slow as HDD?
How often have you lost files due to a poweroff letting your partition on an inconsistent state?

#openbsd #ssd #fde #DiskEncryption

2025-04-24

#SteamDeck folks ... who has switched from #steamos to something like #bazzite so you can enable full disk encryption #fde ??

I cannot use this as a laptop replacement without #encryption and it doesn't seem to be a priority for Valve.

R.L. Dane :Debian: :OpenBSD: 🍵 :MiraLovesYou:rl_dane@polymaths.social
2025-04-15

I was thinking of buying a new-to-me #Thinkpad next month, but I think what I'll do instead is try to spruce up my #PinebookPro:

  • Get new rubber feet
  • Get a bigger SSD
  • Install #pmOS and finally have #FDE on the thing
  • Put some proper locktite on the screws so it's not falling apart all the time

I need to look up some videos on applying threadlocker to screws. It's much looser stuff than the typical locktite and it tends to make a mess.

I'm debating just dribbling locktite (regular CA) on top of the screws as well to try to make them a little more permanent. Not a great solution, but the thing just loves to fall apart.

It's always best to try to #reuse! <3

#UpgradeTreadmill #PermaComputing

R.L. Dane :Debian: :OpenBSD: 🍵 :MiraLovesYou:rl_dane@polymaths.social
2025-04-12

Thinking of trying #postmarketOS on my #PinebookPro.

I didn't even know you could run it as a desktop OS.

Supposedly the installer supports #FullDiskEncryption, which is... "poggers," I think the kids say.

#pmOS #FDE

2025-03-07

🔗 Expand your faith network, & connect with other Christian entrepreneurs through the Faith Driven Entrepreneur Study. 📝 🎓
It's completely FREE! 👉 Join me at ianmayer.com/fde #FaithDriven #FDE

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst