4 ms·
Keeping it on a seperate blockdevice allows dm-verity to authentice the device. This value would be signed and secured, so injecting a signed+known library woul
by Foxboron 5y ago
Keeping it on a seperate blockdevice allows dm-verity to authentice the device. This value would be signed and secured, so injecting a signed+known library wouldn't work. It would refuse to mount.
It should be noted that keeping it unencrypted is only for the traditional linux package manager usecase.