5 ms·
What's to stop someone with a live cd from reading it by mounting the file system?
by zeth___ 8y ago
What's to stop someone with a live cd from reading it by mounting the file system?
- lgunsch 8y ago/boot is also fully encrypted on my system - which includes the initramfs, the backup initramfs, kernel, grub config, etc. /boot/efi is not encrypted, but only has the EFI modules. The first stage of Grub (not sure one terminology here) knows about LUKS encrypted partitions and how to decrypt them. Only version 1 of the header though - found that out the hard way.
- mmirate 8y agoThen - since you aren't claiming to be Mike Cardwell - how do you know that your unencrypted LUKS drivers and EFI modules haven't been tampered-with?
- CBLT 8y agoNot the person you're asking, but see this reddit comment[0] >If you are using a proper private secure boot setup (not the Microsoft keys, signing keys not accessible to an attacker that remotely compromises your system), you trust that your motherboard implements it correctly, you can safely assume nobody is physically tampering with your motherboard and you're using a variant of GRUB that fully implements secure boot, ESP access gives your attacker nothing. They can't change anything there without breaking the system. [0] https://www.reddit.com/r/linux/comments/7n92ip/linux_boot_partition_encryption/ds0epw3/ https://www.reddit.com/r/linux/comments/7n92ip/linux_boot_pa...
- deleted 8y ago[deleted]