:: Re: [DNG] booting security, encryp…
Top Page
Delete this message
Reply to this message
Author: g4sra
Date:  
To: dng@lists.dyne.org
Subject: Re: [DNG] booting security, encryption (Re: About making /boot a mount point)
-- snip --


> My home can contain secret stuff. The OS is public and can be
> dowloaded freely. I make backups of my home, not of the OS. Is there
> something wrong, or maybe stupid, in this habit?


That depends on what value you place on things.

There are plenty of 'personal to your setup' configuration files in the OS. Network connections, wifi passwords, certificates. /etc/shadow can be brute forced to reveal system passwords that you may use again or elsewhere, etc.

An OS binary (or anything in /boot including grub) can be compromised to allow access to your encrypted /home after you have logged in and unlocked it.

If you lock your front door the thief will move on to a softer target as long as there is one.