3 ms·
The latest round of controversy is probably because They're pushing the new 'homed' component, which is supposed to change up how home directories (and user acc
by NickNameNick 6y ago
The latest round of controversy is probably because They're pushing the new 'homed' component, which is supposed to change up how home directories (and user accounts) are managed.
It's supposed to enable easier encryption of home directories, but breaks ssh logins.
Therefore it's probably only suitable for multi-user systems (which need to protect home directoried from other users) that are also never accessed remotely - a subset consisting of approximately 0 systems.
- m4rtink 6y agoActually AFAIK the main usecase is single user client systems (say a laptop). Homed makes it easier to encrypt the home directory at any time (without the need to reformat with LUKS) and handles stuff like suspend better (can drop encryption keys before going to suspend and then requesting them on resume).
- jdmg94 6y agothat's such a small sliver of linux users that the vast majority of linux users (who actually need SSH) are taking the overhead for nothing in return...
- fsh 6y agoDon't use it if you don't need it. The developers made it very clear that systemd-homed is only meant for single-user laptops.
- hedora 6y agoHome directory encryption is a terrible security mode for single user laptops (an attacker with disk access can simply modify the unprotected root file system and exfiltrate data after the fact). Whole disk encryption (and encrypted suspend to disk for bonus points) is simpler, more secure, and doesn’t break ssh (and all sorts of other things, like batch jobs).