toad.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon server operated by David Troy, a tech pioneer and investigative journalist addressing threats to democracy. Thoughtful participation and discussion welcome.

Administered by:

Server stats:

240
active users

#luks

0 posts0 participants0 posts today
Droppiea bit of a digital flap
Rainer<p><a href="https://norden.social/tags/LUKS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LUKS</span></a> Passwort vergessen. <a href="https://norden.social/tags/Urlaub" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Urlaub</span></a> war wohl erholsam. 🤪</p>
LUKS Krefeld<p>Wofür tritt LUKS eigentlich konkret ein?</p><p>Ganz knapp: Für ein lebenswertes, sozial gerechtes und zukunftstaugliches <a href="https://mastodon.social/tags/Krefeld" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Krefeld</span></a>!</p><p>Dafür haben wir ein langes Programm geschrieben, das natürlich nicht zu den knappen SocialMedia-Inhalten passt. Daher hier für euch einfach mal die absolute Kurzvariante.</p><p>Ihr habt Fragen? Ihr habt Anregungen? ➡️📬</p><p>Ihr habt auch keinen Bock auf Materialschlacht im Wahlkampf? Schickt das Programm gern digital weiter! 1/2 <a href="https://mastodon.social/tags/luks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>luks</span></a> <a href="https://mastodon.social/tags/neuhier" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>neuhier</span></a> <a href="https://mastodon.social/tags/Surfpark" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Surfpark</span></a> <a href="https://mastodon.social/tags/niederrhein" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>niederrhein</span></a> <a href="https://mastodon.social/tags/Umweltschutz" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Umweltschutz</span></a></p>
George E. 🇺🇸♥🇺🇦🇵🇸🏳️‍🌈🏳️‍⚧️<p>Huge <a href="https://bofh.social/tags/security" rel="nofollow noopener" target="_blank">#security</a> <a href="https://bofh.social/tags/vulnerability" rel="nofollow noopener" target="_blank">#vulnerability</a> in <a href="https://bofh.social/tags/Linux" rel="nofollow noopener" target="_blank">#Linux</a> systems allows an <a href="https://bofh.social/tags/attacker" rel="nofollow noopener" target="_blank">#attacker</a> with <a href="https://bofh.social/tags/PhysicalAccess" rel="nofollow noopener" target="_blank">#PhysicalAccess</a> to <a href="https://bofh.social/tags/bypass" rel="nofollow noopener" target="_blank">#bypass</a> <a href="https://bofh.social/tags/SecureBoot" rel="nofollow noopener" target="_blank">#SecureBoot</a> and inject <a href="https://bofh.social/tags/malware" rel="nofollow noopener" target="_blank">#malware</a> onto a system even with <a href="https://bofh.social/tags/LUKS" rel="nofollow noopener" target="_blank">#LUKS</a> <a href="https://bofh.social/tags/FDE" rel="nofollow noopener" target="_blank">#FDE</a><span>.<br><br>The mitigation is pretty straight-forward.<br><br>For </span><a href="https://bofh.social/tags/Ubuntu" rel="nofollow noopener" target="_blank">#Ubuntu</a><span> at-least (I don't run RedHat/ Fedora):<br><br>Edit </span><code>/etc/default/grub</code> as <code>root</code><span>.<br><br>In the line that says </span><code>GRUB_CMDLINE_LINUX="..."</code>, add (or append) <code>panic=0</code><span>.<br><br>Followed by: </span><code>sudo update-grub</code><span>. (Takes effect on reboot).<br><br>This will prevent your Linux system from launching a </span><a href="https://bofh.social/tags/DebugShell" rel="nofollow noopener" target="_blank">#DebugShell</a> if an attacker repeatedly enters a wrong passphrase for decrypting your Luks <a href="https://bofh.social/tags/boot" rel="nofollow noopener" target="_blank">#boot</a> <a href="https://bofh.social/tags/volume" rel="nofollow noopener" target="_blank">#volume</a><span>.<br><br>The linked article has more information.<br><br></span><a href="https://cybernews.com/security/hackers-can-bypass-linux-secure-boot/" rel="nofollow noopener" target="_blank">https://cybernews.com/security/hackers-can-bypass-linux-secure-boot/</a></p>
Jonathan Kamens 86 47<p>Notes from migrating Linux to a new hard&nbsp;drive</p><p>Migrating a Linux install to a new drive can be easy (Clonezilla) or hard. I chose hard. It was a learning experience.</p><p><a href="https://blog.kamens.us/2025/07/06/notes-from-migrating-linux-to-a-new-hard-drive/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">blog.kamens.us/2025/07/06/note</span><span class="invisible">s-from-migrating-linux-to-a-new-hard-drive/</span></a><br><a href="https://federate.social/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://federate.social/tags/UEFI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>UEFI</span></a> <a href="https://federate.social/tags/SysAdmin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SysAdmin</span></a> <a href="https://federate.social/tags/LUKS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LUKS</span></a> <a href="https://federate.social/tags/LVM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LVM</span></a></p>
Pedro J. Hdez<p>Pequeño gran acertijo para usuarios de <a href="https://mstdn.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a>.</p><p>Tenemos un segundo SSD interno en el equipo formateado con btrfs y cifrado con <a href="https://mstdn.social/tags/LUKS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LUKS</span></a> para guardar datos y queremos hacer un <a href="https://mstdn.social/tags/backup" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>backup</span></a> incremental del directorio home digamos todos los días. Para automatizar el proceso tenemos que :</p><p>1. Montar ese segundo SSD<br>2. Programar el backup considerando que si se produce mientras alguna aplicación como el navegador está cambiando los archivos de home podría producirse algún tipo de corrupción o error.</p><p>¿Ideas?</p>
The Grue<p>I have an old <a href="https://digitalcourage.social/tags/debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>debian</span></a> server with an unencrypted root disc. Now I'm setting up a new hardware with the same software. Normally, dd would suit me well, but I'd like to use the opportunity to encrypt the root drive. How do I set up the <a href="https://digitalcourage.social/tags/initrd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>initrd</span></a> to decrypt a <a href="https://digitalcourage.social/tags/luks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>luks</span></a> <a href="https://digitalcourage.social/tags/encrypted" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>encrypted</span></a> root from scratch on the new hardware? Usually, the fine Debian <a href="https://digitalcourage.social/tags/installer" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>installer</span></a> does that for me...</p><p><a href="https://digitalcourage.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a></p>
Crazy-to-Bike<p>Ich brauche nochmal <a href="https://fediworld.de/tags/Brainpower" rel="nofollow noopener" target="_blank">#Brainpower</a> der <a href="https://fediworld.de/tags/EDV" rel="nofollow noopener" target="_blank">#EDV</a> <a href="https://fediworld.de/tags/Bubble" rel="nofollow noopener" target="_blank">#Bubble</a> 🤣<span><br><br>Da mein bisheriges, betagtes, leistungsschwaches 1-Bay </span><a href="https://fediworld.de/tags/QNAP" rel="nofollow noopener" target="_blank">#QNAP</a> <a href="https://fediworld.de/tags/NAS" rel="nofollow noopener" target="_blank">#NAS</a> sehr langsam ist, z.B. beim <a href="https://fediworld.de/tags/rsync" rel="nofollow noopener" target="_blank">#rsync</a>, habe ich inzwischen das <a href="https://fediworld.de/tags/Ugreen" rel="nofollow noopener" target="_blank">#Ugreen</a> <a href="https://fediworld.de/tags/NAS" rel="nofollow noopener" target="_blank">#NAS</a> <a href="https://fediworld.de/tags/DPX2800" rel="nofollow noopener" target="_blank">#DPX2800</a> gekauft, mit 32 GB <a href="https://fediworld.de/tags/RAM" rel="nofollow noopener" target="_blank">#RAM</a> aufgerüstet und 2 <a href="https://fediworld.de/tags/NVNE" rel="nofollow noopener" target="_blank">#NVNE</a><span> mit je 2 TB eingebaut.<br><br>Azf den beiden M.2 ist </span><a href="https://fediworld.de/tags/Proxmox" rel="nofollow noopener" target="_blank">#Proxmox</a> im <a href="https://fediworld.de/tags/ZFS" rel="nofollow noopener" target="_blank">#ZFS</a> <a href="https://fediworld.de/tags/RAID1" rel="nofollow noopener" target="_blank">#RAID1</a> installiert. <a href="https://fediworld.de/tags/Homeassistant" rel="nofollow noopener" target="_blank">#Homeassistant</a> und <a href="https://fediworld.de/tags/TrueNAS" rel="nofollow noopener" target="_blank">#TrueNAS</a> laufen je in einer <a href="https://fediworld.de/tags/VM" rel="nofollow noopener" target="_blank">#VM</a><span>.<br><br>TrueNAS soll nun einen </span><a href="https://fediworld.de/tags/Datenpool" rel="nofollow noopener" target="_blank">#Datenpool</a><span> in Form eines verschlüsselten ZFS RAID 1 auf 2 16 TB Festplatten bekommen. So weit so gut.<br><br>Nur: Wie bekomme ich die </span><a href="https://fediworld.de/tags/Daten" rel="nofollow noopener" target="_blank">#Daten</a> vom alten NAS, die in einer verschlüsselten <a href="https://fediworld.de/tags/LUKS" rel="nofollow noopener" target="_blank">#LUKS</a> <a href="https://fediworld.de/tags/Partition" rel="nofollow noopener" target="_blank">#Partition</a><span> liegen, in den Datenpool?<br><br>Über </span><a href="https://fediworld.de/tags/Netzwerk" rel="nofollow noopener" target="_blank">#Netzwerk</a><span> kopieren ist keine wirkliche Option. Das ist für ~ 10 TB Nutzdaten viel zu langsam.<br><br>Bitte </span><a href="https://fediworld.de/tags/Boost" rel="nofollow noopener" target="_blank">#Boost</a> für mehr Reichweite. 🙏</p>
Blue Ghost<p>Consider encrypting storage devices with LUKS.</p><p>Applications such as GNOME Disks support formatting and encrypting devices with LUKS.</p><p>LUKS: <a href="https://wikipedia.org/wiki/Linux_Unified_Key_Setup" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">wikipedia.org/wiki/Linux_Unifi</span><span class="invisible">ed_Key_Setup</span></a></p><p>Devices such as USB flash drives can be lost or stolen.</p><p>Example: <a href="https://www.cbc.ca/news/politics/rcmp-lost-usb-key-privacy-commissioner-1.7554332" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">cbc.ca/news/politics/rcmp-lost</span><span class="invisible">-usb-key-privacy-commissioner-1.7554332</span></a></p><p>GNOME DISKS INSTRUCTIONS<br>Select Disks &gt; Device &gt; Volumes (additional partition options) &gt; Format Partition &gt; Format Volume (Ext4 + LUKS) &gt; Next &gt; Set Password &gt; Next &gt; Format.</p><p><a href="https://mastodon.online/tags/LUKS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LUKS</span></a> <a href="https://mastodon.online/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> <a href="https://mastodon.online/tags/Encryption" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Encryption</span></a> <a href="https://mastodon.online/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.online/tags/InfoSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>InfoSec</span></a> <a href="https://mastodon.online/tags/Privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Privacy</span></a> <a href="https://mastodon.online/tags/GNOME" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GNOME</span></a></p>
House Panther :verified_paw:<p>As y'all know, I am fully on <a href="https://goblackcat.social/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a>. My desktop and server systems use <a href="https://goblackcat.social/tags/luks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>luks</span></a> which is a full disk encryption system. Since I am pretty verbose in my criticism of government, I need to make it as difficult as possible for the fascist state to get any hard evidence of said criticisms.</p><p>AFAIK, LUKS still has not been broken and is considered very secure. These days security needs to be taken seriously. It's not just for the tin-foil-hat-wearing conspiracy theorists. Security is for everyone's digital footprint nowadays. </p><p>These days law enforcement actively seeks to incriminate people so it is naive to think that simply having nothing to hide is enough to keep one safe.</p>
🎅 SantaOS 🎅<p><a href="https://mastodon.social/tags/SantaOS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SantaOS</span></a> <a href="https://mastodon.social/tags/OS" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OS</span></a> <a href="https://mastodon.social/tags/tor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tor</span></a> <a href="https://mastodon.social/tags/onion" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>onion</span></a> <a href="https://mastodon.social/tags/i2p" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>i2p</span></a> <a href="https://mastodon.social/tags/hyphanet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>hyphanet</span></a> <a href="https://mastodon.social/tags/freenet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freenet</span></a> <a href="https://mastodon.social/tags/kali" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kali</span></a> <a href="https://mastodon.social/tags/ubuntu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ubuntu</span></a> <a href="https://mastodon.social/tags/kalilinux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kalilinux</span></a> <a href="https://mastodon.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a> <a href="https://mastodon.social/tags/tails" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tails</span></a> <a href="https://mastodon.social/tags/usb" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>usb</span></a> <a href="https://mastodon.social/tags/boot" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>boot</span></a> <a href="https://mastodon.social/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://mastodon.social/tags/operatingsystem" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>operatingsystem</span></a> <a href="https://mastodon.social/tags/firefox" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>firefox</span></a> <a href="https://mastodon.social/tags/VPN" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>VPN</span></a> <a href="https://mastodon.social/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/veracrypt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>veracrypt</span></a> <a href="https://mastodon.social/tags/truecrypt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>truecrypt</span></a> <a href="https://mastodon.social/tags/luks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>luks</span></a> <a href="https://mastodon.social/tags/anonymous" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>anonymous</span></a> <a href="https://mastodon.social/tags/distro" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>distro</span></a> <a href="https://mastodon.social/tags/youtube" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>youtube</span></a> <a href="https://mastodon.social/tags/free" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>free</span></a> <a href="https://mastodon.social/tags/freesoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freesoftware</span></a> <a href="https://mastodon.social/tags/download" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>download</span></a> <a href="https://mastodon.social/tags/torrent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>torrent</span></a> <a href="https://mastodon.social/tags/bitcoin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>bitcoin</span></a> <a href="https://mastodon.social/tags/monero" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>monero</span></a> <a href="https://mastodon.social/tags/crypto" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crypto</span></a> <a href="https://mastodon.social/tags/cryptocurrency" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptocurrency</span></a> <a href="https://mastodon.social/tags/gaming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gaming</span></a> <a href="https://mastodon.social/tags/cryptocurrency" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptocurrency</span></a> <a href="https://mastodon.social/tags/fast" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>fast</span></a> <a href="https://mastodon.social/tags/santa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>santa</span></a> <a href="https://mastodon.social/tags/christmas" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>christmas</span></a> <a href="https://mastodon.social/tags/xmas" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>xmas</span></a> <a href="https://mastodon.social/tags/music" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>music</span></a> <a href="https://mastodon.social/tags/movies" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>movies</span></a> <a href="https://mastodon.social/tags/development" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>development</span></a> <a href="https://mastodon.social/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://mastodon.social/tags/education" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>education</span></a> <a href="https://mastodon.social/tags/windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>windows</span></a> <a href="https://mastodon.social/tags/invidious" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>invidious</span></a> <a href="https://mastodon.social/tags/nsa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nsa</span></a> <a href="https://mastodon.social/tags/nasa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>nasa</span></a> <a href="https://mastodon.social/tags/mp3" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mp3</span></a> <a href="https://mastodon.social/tags/recover" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>recover</span></a> <a href="https://mastodon.social/tags/files" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>files</span></a> <a href="https://mastodon.social/tags/storage" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>storage</span></a> <a href="https://mastodon.social/tags/chess" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>chess</span></a> <a href="https://mastodon.social/tags/kde" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kde</span></a> <a href="https://mastodon.social/tags/live" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>live</span></a> <a href="https://mastodon.social/tags/iso" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>iso</span></a> <a href="https://mastodon.social/tags/browser" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>browser</span></a> <a href="https://mastodon.social/tags/ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ai</span></a></p>
📡 RightToPrivacy & Tech Tips<p>BusKill Tutorial: Self Destructing Laptop Storage</p><p><a href="https://fosstodon.org/tags/buskill" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>buskill</span></a> <a href="https://fosstodon.org/tags/encryption" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>encryption</span></a> <a href="https://fosstodon.org/tags/crypto" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crypto</span></a> <a href="https://fosstodon.org/tags/storage" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>storage</span></a> <a href="https://fosstodon.org/tags/forensics" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>forensics</span></a> <a href="https://fosstodon.org/tags/antiforensics" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>antiforensics</span></a> <a href="https://fosstodon.org/tags/HDD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HDD</span></a> <a href="https://fosstodon.org/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> <a href="https://fosstodon.org/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://fosstodon.org/tags/datarecovery" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>datarecovery</span></a> <a href="https://fosstodon.org/tags/luks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>luks</span></a> <a href="https://fosstodon.org/tags/encrypted" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>encrypted</span></a> <a href="https://fosstodon.org/tags/harddrive" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>harddrive</span></a> <a href="https://fosstodon.org/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> <a href="https://fosstodon.org/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://fosstodon.org/tags/educational" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>educational</span></a></p><p>Watch On <a href="https://fosstodon.org/tags/Peertube" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Peertube</span></a>:</p><p><a href="https://tube.tchncs.de/w/q8X2JyxYH26tqYi2VisTHb" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">tube.tchncs.de/w/q8X2JyxYH26tq</span><span class="invisible">Yi2VisTHb</span></a></p>
Replied to marczz

@marczz

Why you should use full-disk encryption

If any of the arguments I make below apply to you, you should use full-disk encryption. I am pretty sure the first argument applies to everyone. The second argument applies at least to everyone in the EU and the US state of California. The third argument applies to everyone again.

You will fail to delete drives properly

Storage media get lost. Most people do not know how to properly delete hard disk content before selling them, or they forget it. In the case of flash drives, or SSDs, standard tools like shred don't work. hdparm may do the trick, but this is not well known. If you are lucky, the manufacturer of you SSH provides a Windows app that lets you delete it securely. Your server does not run on Windows of course.

The law demands it

#GDPR and similar data protection and privacy laws require you to store no #PII (personal data) permanently. You have to anonymize PII or delete it after a few weeks. IP addresses are PII. All servers store IP addresses by default. The GDPR also demands that you use state-of-the-art technology to protect sensitive data. Full disk encryption is the state of the art.

Law enforcement makes "mistakes"

I'm a board member of @Artikel5eV, an organisation that runs relays on the Tor network, including exit relays. Running Tor relays is perfectly legal in Germany. Nevertheless, law enforcement agencies have raided the homes of Artikel 5 e.V. board members twice. Illegally so, as a court confirmed recently. I won't run Tor relays in my home, but there is a good chance that my home will be raided one day unless all police officers and prosecutors decide to obey the law.

There is also a possibility that the rule of law might collapse in your country sooner or later. We are just witnessing it in the USA.

You already mentioned that ordinary thieves can also be a problem.

Encryption is available for free

So what is your case against disk encryption? It is obvious that it alone does not solve all IT security issues, but it is an important building block. #LUKS is reliable free and open-source software for HD encryption. If you are not using Linux, check out #VeraCrypt. The Raspberry Pi 5 comes with hardware acceleration for AES, so there no longer is a noticeable performance penalty for encryption.

@chpietsch I was wondering if enabling #LUKS on a running server has really a benefit. Of course if thieves enter your place, unplug the server and take it the disk is protected. But this scenario is not so usual. Most often the attacker get access to your live server. Once the server is booted and the disk is unlocked, all data on the encrypted volume is accessible to anyone with access to the system. This makes encryption ineffective against attackers who compromise a running server.

Lately I've been doing more #SelfHosting again due to the current situation. Of course, I'm paying particular attention to power consumption and noise. After good experiences with the #ARM64 architecture, even with power-hungry applications such as Mastodon, I'm now using the smartphone technology for my homeservers, too.

There are #SBCs with more open hardware, but the #RaspberryPi is widely available, well documented, powerful and inexpensive. And it is available with up to 16 GB of RAM.

Anyone operating a server on the Internet must install #security updates quickly. However, many people forget to restart running software so that the new version runs instead of the old one. The #needrestart tool helps with this on Debian-based Linux systems, which unfortunately is usually not pre-installed.

On my Raspberry Pi 4, needrestart always runs correctly (automatically after apt upgrade). On my Raspberry Pi 5, however, I first had to create a configuration file as described by the main developer here:
github.com/liske/needrestart/b
Previously, the tool always claimed that a reboot was necessary because it thought an outdated Linux kernel was running.

Next, I want to activate #LUKS hard drive encryption on both raspis. Unfortunately, this is not as easy under #Raspbian or #RaspberryPiOS as on other Debian systems. If you have managed this: Please let me know how you did it!

Mastodon, gehostet auf fedifreu.deFedifreudeDiese Mastodon-Instanz wird vom überregionalen netzaktivistischen Zusammenhang Datenfreude <https://datenfreu.de> betrieben. Dazu zählen https://datenpunks.de und https://kleindatenverein.org.
#rpi#rpi5#raspi

My experience with #FlashDrives recently has been mixed. I have no problem in encrypting them with #LUKS, using #cryptsetup or with formatting a partition with #Btrfs, for instance, using #gparted and doing other tinkering with #Gnome #disks. But the problem has been with the actual drives themselves. The cheaper ones seem to have quite a few bad sectors, etc. and so they’re not really reliable for medium term storage.

1/2

#Corona Infektionen sind ein Problem für MS Patienten.

Case Report vin 2024 aus #Luzern

#SRF: Das ist nicht relevant für die Öffentlichkeit, da chronisch Erkrankte irrelevant sind. Geht ins Restaurant! Das Plexiglas war teuer!

cureus.com/articles/334436-hig

www.cureus.comHighly Aggressive Multiple Sclerosis Relapse During Pregnancy Following SARS-CoV-2 Infection: A Case Report and Literature ReviewWe report a challenging case of a 32-year-old previously healthy pregnant woman at 17+2 weeks gestation with a new diagnosis of exceptional highly active relapsing-remitting multiple sclerosis (RRMS) triggered by a severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2) infection. Remarkable clinical characteristics were the rapid clinical deterioration, the severity and the nature of the symptoms, including spastic tetraplegia, dyspnea, dysphagia, anarthria, and a severe pain syndrome, which resulted in the need for intensive care and mechanical ventilation within 24 hours. Relapse treatment, as well as symptomatic treatment, was challenging and complicated by pregnancy. Early diagnosis, consistent and persistent interdisciplinary management including six weeks stay in the intensive care unit and 3.5 months in neurorehabilitation, led to a full recovery of the patient and a healthy born child. In addition to the remarkable clinical characteristics, we report the challenging therapeutic measures throughout the hospitalization. This case report could, therefore, assist others who may be confronted with a similar situation.