med-mastodon.com is one of the many independent Mastodon servers you can use to participate in the fediverse.
Medical community on Mastodon

Administered by:

Server stats:

413
active users

#dmcrypt

0 posts0 participants0 posts today

Frage an die datenschützenden SysAdmins und angewandten IT-Sicherheitsforschenden unter euch:

Bietet #Festplattenverschlüsselung in einem angemieteten #VPS auf #KVM-Basis einen wirkungsvollen #Datenschutz?

Dieser Text hat mich verunsichert: lowendbox.com/blog/how-private

Replied in thread

@ernstdemoor @nixCraft that's because on basically all #Linux #Filesystems, #RAID and #Encryption is handled by dedicaded subsystems like #dmraid and #dmcrypt / #LUKS respectably, thus not on filesystem but OS level...

This allows extra cursed shit like a an encrypted & RAID-5 running NTFS - Tho that won't be useable by anything but Linix and I disrecommend it almost as hard as mixing hardware RAID controllers and/or dmraid with ZFS.

Remember: NEVER EVER LIE TO ZFS!!!

Turns out, #LVM #RAID-1 with #dmintegrity over two separate physical disks and then putting a #dmcrypt device on top of the RAID is really slow. As in, it's estimating to take a week to do the initial sync on the two 12TB WD Red drives on SATA. (For comparison, zeroing out one of these disks should take 8 hours or something.)

Apparently it's a somewhat-known problem with dm-integrity, related to its journal.

How would you build something bitrot-safe & encrypted with that hardware? #Debian 12.

Replied in thread

@joepie91 Don't forget:
- #Mumble for #VoiceChats

- #Linphone as #SIP / #VoIP client

- #gparted and #ddrescue as well as #testdik & #photorec for halding storage and recovering data.

And ofc all the tools I need daily like #SSH (#OpenSSH), #OpenVPN, #WireGuard, #IPsec, #pfSense, #OPNsense, #ipFire, #LUKS/ #dmcrypt and the whole #toolchain needed for OS/1337 like #gcc, #musl, #toybox, #dropbear and so on.

#OS1337
os1337.com

os1337.comOS/1337

Is there a good way to have a #Linux server reboot unattended when the root partition is dm_crypt encrypted? I'm not super worried about bad guys being physically present. More just worried that a power outage might initiate a reboot while I am not present.

Is including the key file in the initramfs (correct terminology?) that horrible a thing if physical access to the machine is not a concern?

Thoughts or advice?