4 ms·
I used to have a custom NAS with full disk encryption, whose bootloader would spin up a tiny SSH server with very few features, mainly only access to an unlock
by SomeoneOnTheWeb 3y ago
I used to have a custom NAS with full disk encryption, whose bootloader would spin up a tiny SSH server with very few features, mainly only access to an unlock function that would allow to transmit the encryption passphrase over the said SSH tunnel. Then the SSH connection would be closed by the server and it would startup with the decryption key.
That way, it was impossible to access the data physically, but I was still able to reboot the box whenever I wanted without any problem.
- alexvitkov 3y agoThat's sensible, unlike trusting that TPM+GRUB+dracut+systemd+getty+logind+whatever all work fine and won't leak your key. Rebooting a box is often the easiest way to get something done if you can't be bothered with exotic configs, I just don't believe that remotely rebooting a encrypted box for which you dont have the key is ever a reasonable thing to do, and that's the assumptuon this article is based on.
- teddyh 3y agoMight I suggest that Mandos might be a slightly easier version of a solution to that problem? (Disclosure: I am a co-author of Mandos.)