4 ms·
What's the point of encrypting /boot exactly? From an Encrypt All The Things! perspective I get it, but practically... it seems overkill?
by voidfunc 4y ago
What's the point of encrypting /boot exactly? From an Encrypt All The Things! perspective I get it, but practically... it seems overkill?
- vladvasiliu 4y agoPresumably to avoid tampering of the kernel and initrd, since GP doesn't use secure boot.
- Nursie 4y agoAs the other poster mentioned, without secure boot, there are no guarantees about a kernel or initramfs that are sitting out there in plaintext (and yes, someone could mess with my grub install). It was mostly because "this should be possible, right?" So yeah - Encrypt all the things :)
- rhn_mk1 4y agoYou don't need to encrypt anything to verify those images, you just need to sign them. See how Heads does this. https://github.com/osresearch/heads https://github.com/osresearch/heads
- Nursie 4y agoSure, and you could do that with more or less your whole installed system. From the other angle - if it’s not a lot more difficult than encrypting the rest, why would I specifically exclude having these stored on an encrypted volume?