That is so me sometimes.
You're somewhat right in the sense that the point of disk encryption is not to protect from remote attackers. However, physical access is a bigger problem in some cases (mostly laptops). I don't do it on my desktop because I neither want to reinstall nor do I think someone who randomly breaks in is going to put in the effort to lug it away to their vehicle.
Clevis pretty much does TPM encryption and is in most distros' repos. I use it on my Thinkpad. It would be nice if it had a GUI to set it up; more distros should have this as a default option.
You do have to have an unencrypted boot partition, but the issues with this can at least in be mitigated with PCR registers, which I need to set up.
It’s a smidge more difficult on Debian if you want to use a non-ext4 filesystem - granted for most people, ext4’s probably still fine. I use it on my desktop, which doesn’t have encryption.
No - so long as the Federation has transporters and warp drive (realspace FTL in Star Wars lingo), they can probably pull it off.
If they could beef up their runabouts, that might help too.
Yes, fellow OpenTTD player.
I know this topic has been beaten to death online and honestly discussion is pointless, but I’m convinced the Federation could beat the Empire solely based on these two things:
- Warp drive travels FTL through what Star Wars would call “realspace”; not only does this provide Federation starships extreme tactical maneuverability (Picard maneuver and the like), but if a starship warped away far enough, the Empire might struggle to pursue with hyperdrive.
- The Federation has transporters - I’m not sure imperial shield would be design to protect against e.g someone beaming a bomb (or in dire cases, the warp core) onto a Star Destroyer or whatever.
I’d say the major difficulties are 1) Starfleet has nothing like a tie fighter except runabouts, which aren’t (yet) designed for combat. 2) The Federation might try to negotiate while the Empire does some sort of secret operation.
I’m using LVM. The BIOS solution would be a bad idea because it would be more difficult to access the drive on other systems if you had to; LVM allows you to enter your password on other systems to decrypt.
Do your servers have TPM? Clevis might be the way to go; I use it on my Thinkpad and it makes my life easy. If the servers don’t have TPM, Clevis also supports this weird thing called Tang, which from what I can tell basically assures that the servers can only be automatically decrypted on your local network. If Clevis fails, you can have it fall back to letting you enter the LVM password.
Sent! Although I just realized it’s not like only one person has to send an e-mail; multiple would make it clearer that these images are important to some people.
Well, it was worth a shot.
JavaScript be like that sometimes…