this post was submitted on 27 Nov 2023
6 points (100.0% liked)
Security
5010 readers
1 users here now
Confidentiality Integrity Availability
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Nice try, FBI.
I usually use LUKS2 and a password manager with a keyfile (on the LUKS encrypted partition). The passwords for them are in my head.
Remote LUKS systems are set up with dropbear in the initramfs so I can enter passwords without being present or having access to IPMI. After a few tries the system nukes the LUKS header and I have to manually recover it from backup.
I also have an emergency password DB without a keyfile, where the password is the beginning of a chapter of a readily available book. I won't tell you which book or which chapter though ๐