mycodesucks@lemmy.world to linuxmemes@lemmy.world · 1 day agoSekyuriteelemmy.worldimagemessage-square63fedilinkarrow-up1850arrow-down111
arrow-up1839arrow-down1imageSekyuriteelemmy.worldmycodesucks@lemmy.world to linuxmemes@lemmy.world · 1 day agomessage-square63fedilink
minus-squaresrestegosaurio@lemmy.dbzer0.comlinkfedilinkEnglisharrow-up8·1 day agoYou can have FDE binded to the TMP and then inside that encrypted volume an encrypted home. By doing that you only need to input your login password and get better security than the meme setup and other suggestions. You would need, iirc (I am typing this from memory): A TPM. systemd-cryptenroll Some PAM config for fscrypt or similar. I know the steps but for NixOS only lmao.
You can have FDE binded to the TMP and then inside that encrypted volume an encrypted home.
By doing that you only need to input your login password and get better security than the meme setup and other suggestions.
You would need, iirc (I am typing this from memory):
systemd-cryptenrollI know the steps but for NixOS only lmao.