Hi

On my server I have an unencrypted boot drive which decrypts an encrypted LUKS drive with my data on it.

I am aware that a skilled thief could access the encryption keys thatbare stored on the unencrypted boot drive and am looling for a chill and safe solution.

I know about dropbear to decrypt a luks boot drive and I was wondering about using proxmox and an encrypted VM.

What do you guys think are good ideas?

Thanks

  • Neverclear@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 months ago

    iPXE maybe? But there’s a lot of implementation details you would have to figure out. Two that come to mind are:

    1. A mobile device from which you can selectively provide an image for booting

    2. A physical intrusion detection system for your home machine that you can also read remotely