Gentoo Archives: gentoo-user

From: Frank Steinmetzger <Warp_7@×××.de>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Demise of Truecrypt - surprised I haven't seen t his discussed here yet?
Date: Wed, 04 Jun 2014 19:59:24
Message-Id: 20140604195917.GA18027@asp
In Reply to: Re: [gentoo-user] Demise of Truecrypt - surprised I haven't seen t his discussed here yet? by Neil Bothwick
1 On Mon, Jun 02, 2014 at 11:54:52AM +0100, Neil Bothwick wrote:
2 > On Mon, 02 Jun 2014 12:06:18 +0200, Alan McKinnon wrote:
3 >
4 > > If you encrypt your home directory then you unlock it when you log in so
5 > > logging out of your DE safely locks things again.
6
7 I encrypt my home partition with LUKS and enter a passphrase
8 during boot. But I always wanted to get decryption upon login running,
9 especially because it would require me to enter one less password. But
10 haven’t gotten around to that yet.
11
12 > > You most likely want the second option, the odds that you have a valid
13 > > need to protect /usr and /opt are not good. As a regular user out there,
14 > > the stuff you want to protect is in /home (or you could easily move it
15 > > to /home).
16 >
17 > With one notable exception. There is sometimes sensitive information
18 > in /etc, like wireless passwords.
19
20 For that reason I put this stuff into /home/etc/$hostname/ (I back up my
21 machines’ /etc on all other machines, also to have a reference if I need
22 to know “How did I do this on $other_host?”). And then I symlink to
23 that from the real location, i.e.:
24
25 $ ls -ld /etc/wpa_supplicant
26 lrwxrwxrwx 1 root root 29 28. Mär 21:02 /etc/wpa_supplicant -> /home/etc/hostname/wpa_supplicant/
27
28 Cryptsetup comes early enough in the boot process for this to work (both
29 with OpenRC and systemd).
30 --
31 Gruß | Greetings | Qapla’
32 Please do not share anything from, with or about me on any social network.
33
34 I just took an IQ test. The results were negative.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] Demise of Truecrypt - surprised I haven't seen t his discussed here yet? Neil Bothwick <neil@××××××××××.uk>