Btw, I migrated it now. Thank you for noticing my dumb mistake.
I have different systems implemented on my server(s) and doing this would destroy them. I found a safe way that also works.
Every file getting their own encryption is more useful for me.
Every file getting their own encryption is more useful for me.
Doesn't make sense you need to expand.
You should be able to restart the system. You should too by default have added LUKS.
You should be able to restart the system. You should too by default have added LUKS.
I'm sorry, but I still have physical protection against getting into the server, without the power being cut. This is my method and you don't have to like it. Restarting will always work, but I will have to inject the key, as I already said for the website to decrypt the files.
I would appreciate if you could approve the main post again. :)
I would appreciate if you could approve the main post again. :)
You're hosting this at your own place? It's highly unadvised for public service.
Every time you make changes to the post it goes back to queue automatically as something seems to be triggering it.
Users should be made aware your service isn't under LUKS encryption and it's self hosted not in a data center.
Every time you make changes to the post it goes back to queue automatically as something seems to be triggering it.
Users should be made aware your service isn't under LUKS encryption and it's self hosted not in a data center.
Who said, I have no access to a data center. :) I will add the notice with the LUKS encryption in the red box, I'm trying to be as transparent as I can without harming myself.
Colocation has a physical element to it increasing the risk. While it isn't on the level of a DNM, it's something to be considered.
You can achieve a lot more than whats set out with LUKS, couple scripts and some firmware modifications. Post is approved but users should be aware of these caveats.
You can achieve a lot more than whats set out with LUKS, couple scripts and some firmware modifications. Post is approved but users should be aware of these caveats.
I advocate for a strict Zero Trust mindset where users should exercise caution with sensitive data regardless of the host (dump.li, Eternal or mine for example).
Regarding the physical threat vector, my infrastructure is configured to ensure that physical access can be only resulted after the power is cut. This highlights the specific tactical advantage of my architecture over standard LUKS, which offers no protection once the volume is mounted and the server is running.
Regarding the physical threat vector, my infrastructure is configured to ensure that physical access can be only resulted after the power is cut. This highlights the specific tactical advantage of my architecture over standard LUKS, which offers no protection once the volume is mounted and the server is running.
[removed]
They ain’t gettin’ into that server, fam. Not unless the whole ting shuts down. Trust me, I got this.
Members-only continuation
This discussion contains more posts.
Create an account or sign in to continue reading the full conversation. 14 additional posts await inside.