3 ms·
I have 4 of the old ones in service and they're great. Whenever I need to remotely reboot a server those come in handy just great, no more fear of what I'm goin
by mszcz 20d ago
I have 4 of the old ones in service and they're great. Whenever I need to remotely reboot a server those come in handy just great, no more fear of what I'm going to do if the server doesn't come back online.
It also solved the issue I had with entering a password on FDE (full disk encryption) systems. Previously I had to rely on a janky solution with booting into BusyBox so that the system can be accessed remotely and using that to enter the password. Now it's just plain FDE set up during Debian install - I reboot, use JetKVM to enter the password and that's it.
One note though - I don't use their online cloud service access thingy and connect to those using my Wireguard deployment. The hardware is nice, open source is nice, but I wouldn't trust that level of access to any cloud solution by any vendor.
- irusensei 20d ago>It also solved the issue I had with entering a password on FDE (full disk encryption) systems I've fixed that with secure boot (my own keys, not Microsoft's) and TPM2. From that host I can run a program named Tang, which operates in conjunction with another program named Clevis. On hosts without secure boot such as RPis and other ARM SBCs, Clevis will contact Tang at boot time and decrypt the disk. Incidentally my x86 with secure boot has intel vPro so the KVM is not needed. The remaining sisters have a piece of lost technology used for decades to solve the KVM problem: serial (UART specifically) connections. Some seasoned sysadmins might have memories of dialing their Sun servers serial ports for remote administration.
- jchw 20d agoTo me, it is a feature to have a password required at boot to unlock the drive. Relying on TPM for keymatter is convenient but comes with caveats I don't like. I don't personally trust that the boot chain and OS on a modern system are secure enough for this model to be similarly secure to using a passphrase properly. And if I care enough to try to secure something in this way, I definitely care enough to pick something that I believe would be at least truly secure at rest with a decent degree of certainty. TPM based unlock does at least still fulfill the goal of ensuring data stored to disk is encrypted so that it can't easily be recovered from a discarded drive.
- doubled112 20d agoI am using Tang and Clevis without a TPM on an Orange Pi 5. The key is stored on my Tang server. No TPM required. It is either on my LAN with that server available, or you will need to enter a key. It am only trying to prevent casual snooping if it goes missing from my garage though. Anybody more sophisticated can have my garage YouTube browsing history.
- irusensei 20d agoThis. I'm not fighting against a state level actor. My concern is some crackhead burglar stealing my stuff and then my personal data ending up in the hands of whoever buys the stolen goods.
- doubled112 20d agoExactly. Disk encryption simplifies a stolen device to a VISA problem. As in, no problem, I will just buy another one. At these RAM and storage prices, maybe not.
- Forgeties79 20d agoI like jetkvm a lot but the splitter with the dual USB-c’s is really, really finicky and will say it’s not connected for seemingly no reason. They don’t even send you all the cables you need (which I’m sorry, but jetkvm team if you’re reading this, that’s ridiculous) so you’re just kind of rotating through your pile until you find one that it arbitrarily accepts. Power in particular just refuses to work with many cables for some odd reason. Kind of annoying, I would rather just pay the extra cost and have all the exact cables I need out the box. At least the new ones dropped the splitter and put 2 separate ports it seems.
- hypercube33 19d agoYeah its a really poor decision - the things chonky, put two USB-C on there.
- atlaslandia 20d ago[dead]