Apparently LUKS is a tool focused on encrypting hard drive partitions and it works great. It can encrypt any partitions and You can use it as another layer on top encrypted archives to hide your bullshit from the world, recently I have discovered that I can use LUKS to encrypt my root partition and I can put the password on boot up and it boots manually. I have failed to follow tutorials for this and I think I know why. when it comes to encrypting root partitions LUKS prefers ext4 above all filesystem partitions and I have been using Btrfs all my life so I really want to know.Is encrypting the root partition important?I mean I don't want any bastard who steals my laptop find out my bullshit on my hard drive
>>109645567>laptopencrypt it but be diligent about backups to external drive>desktopdon’t bother, it complicates backups and tends to make data recovery difficult-to-impossible if shtf
>>109645595I think in the case of the desktop, it would be better if I set up an encrypted separate basic data partition, correct?
>>109645636What use is encrypting a computer you keep at home? Is tyrone breaking into your house a realistic worry?Unless you have a meth lab in your basement there’s just no reason to do so. You’re vastly more likely cause yourself some trouble due to encryption than get any benefit from it
>>109645656I am going to be honest, I am very paranoid about privacy and anonymity so much I degoogled my phone and using GNU/LinuxWell... In my defense, I want to hide stuff from my family since the laptop is communal
https://wiki.archlinux.org/title/Btrfs>Users can however encrypt the partition before running mkfs.btrfs, see dm-crypt/Encrypting an entire system. Another approach is stacked filesystem encryption.Apparently this should just work. Have you tried following this tutorial?https://wiki.archlinux.org/title/Dm-crypt/Encrypting_an_entire_system
>I mean I don't want any bastard who steals my laptop find out my bullshit on my hard driveThen encrypt it. In the Fedora installer check the box. It's simple. Stop being an indecisive little fuck.
>>109645924I didn't mention I use Fedora, in fact I use btw
>>109645567It just works with btrfs
>>109646066Why the empty space? You don't have to use Fedora, it's general advice. You seem pretty indecisive so I took the liberty of picking your OS for you.
>>109645913Will use this next time I reinstall, thanks!
>>109646109I have been distro hopping the last 3 years and just settled on Arch Linux, it's flexible and lightweight contrary to Ubuntu based distros
>>109646105I didn't see any tutorial using Btrfs as the filesystem partition, but I will attempt it again sometime
>>109645567>>109645878Boot from a flashdrive and use an external HDD if you're actually paranoid.
>>109647064Won't that decrease performance?Since a SATA SSD is faster than a USB drive and add to that my laptop supporting only up to USB 2.0
>>109645656You do know, if youre SUSPECTED of a crime (regardless of formal charges) which even loosely touches a computer, they can seize your devices. If you really did commit a crime with them, they will compel you one way or the other to decrypt them, but if your actually innocent like theyre just fishing (aka investigating) that encryption at rest may be the only thing to protect your privacy. In addition, if you want to resell your computers later, especially the drives, you can do it with reasonable security if everything previously written to it was encrypted. Then you throw away the keys and attempt full overwrites. Corps dont do this because its hard to manage across hundreds or thousands of systems, theres also old regulations, and its usually just more cost effect to rip out the drive and shred them before reselling the computers to the peasants downstream. However for an individual with only a few systems/drives, and given the hyperinflation of computer parts today, the bottom 90% of people would find it much more profitable to be able to resale the most valuable parts.
>>109645595I have all my (linux) systems full disk encrypted and all my backup drives veracrypt paritions. Windows is absolute shit, and the only option is bitlocker to protect boot, then veracrypt your important parts. Or disable secure boot and veracrypt the whole thing. Never rely on bitlocker, its compromised.
>>109645567If they have physical access to your computer you are already fucked.
>>109645656Having to take it for repair for those who don't know how to do it themselves is a realistic worry I would say.
>>109647752Completely wrong as the whole point of disk encryption is for when someone has physical access.
If you’re talking about an ssd, it’s probably already encrypting the data. You have to check ifm`it supports setting a passphrase to control decryption (retardedly, not all self encrypting drives do this which makes the encryption pretty useless. Look into your uefi storage options for setting passphrases for these drives, which will then require the passphrases to unlock the drives during boot. Also set uefi password so no one can change your uefi settings without knowing the password.Be sure your ssd firmware is up to date and also search to make sure your ssd is not known for having any vulnerabilities wrt sed