1 |
On Wed, May 24, 2017 at 2:16 PM, Andrew Savchenko <bircoph@g.o> wrote: |
2 |
> |
3 |
> Apparently it is pointless to encrypt swap if unencrypted |
4 |
> hibernation image is used, because all memory is accessible through |
5 |
> that image (and even if it is deleted later, it can be restored |
6 |
> from hdd and in some cases from ssd). |
7 |
> |
8 |
|
9 |
Yeah, that was my main concern with an approach like that. I imagine |
10 |
you could use a non-random key and enter it on each boot and restore |
11 |
from the encrypted swap, though I haven't actually used hibernation on |
12 |
linux so I'd have to look into how to make that work. I imagine with |
13 |
an initramfs it should be possible. |
14 |
|
15 |
-- |
16 |
Rich |