Hi,

On 04/13/2011 04:22 PM, Philip Hands wrote:
On Wed, 13 Apr 2011 15:16:39 +0200, [email protected] wrote:
Hi,

Maybe one way to start working on the freedombox with this plug you
received might be to install debian on it, with encrypted rootfs, and then
install a bunch of the software/services listed on the wiki, with minimal
configuration and try to benchmark it to see how it behaves.

Just out of curiosity, why encrypt the rootfs?

Well, if *someone* snatches the device out of my place, I definitely
don't want them being able to read the data on the device. And no,
it does not matter a whee bit, what the reason was to take it away,
nor who exactly did it, nor whether they had the right to do so.
That means IMHO: no keys are on the device. If it dies and comes back,
it needs some interaction. That would be the price for the above.

It's bad enough that /boot is needed in clear, and on the long run
I would like to see separate boot media, which can be removed after
the boot. And yes, this is not exactly zero-admin ... but I'm
wandering off into technical details, sorry.


> <snip>

Cheers,
Erich

_______________________________________________
Freedombox-discuss mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/freedombox-discuss

Reply via email to