-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 On 2016-11-09 08:38, [email protected] wrote: > My general thought is, better to be safe than sorry. The exception I could > think of is if I had short-term bkups (I do "long term" bkups on an ext > drive) on this drive they are encrypted but most everything else I figure, > why not encrypt? >
I agree. Modern encryption is very inexpensive (in the sense of being low overhead), especially if your CPU supports AES-NI. > If I wanted something a bit automatic like the > https://www.qubes-os.org/doc/secondary-storage/ option, is there a way the > drive could automatically be mounted/decrypted so that template backups could > be accessed (and updated, wouldn't want out of date templates). I use that method. To have the drive automatically mounted and decrypted on each boot, I added a keyfile in LUKS, then added the drive in /etc/fstab and /etc/crypttab (pointing to the keyfile in dom0). - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -----BEGIN PGP SIGNATURE----- iQIcBAEBCgAGBQJYI8AzAAoJENtN07w5UDAwo/8QAKO8tRY+lrFEn2VQ+l58qBQ7 j1GTgDO2iiSjMZdLeOdoeK3lND1tOU0s9/qG7ARVWjJlyYrcpikLgwryUwgXVhjO jZs7KuxMc2prFGM4WwPXIcWHLfmhSB7iRx867BOoA6+DX/dPRtm8w6UsSF++ABjO AuzRd14uq9IUGlfGeAyCIoHD0IQgY7I2N4HMdes9FYfzJu9asgd8VNjfgxWd+hyn liGnsnucO0FJ2CUrf2qNUeOGWaNGwvwb2yazWAoaOAmQ8lSezb65hNNjDFuxdQFC aZ7hfLduNTfHOH5zJYGDbyypHHeXbZdt3HPt3v/nuSxdZW7cP3PUZMWR8xvNID0W 71yYoIa26Kaj0stLxuf5TIhPukAfp0FUEJzuJOJXPZJlRUvLO37LYa21laSSUbcY o2YFWc7c6mXc2+1/jOFrZfhymmVLfTndgOxVJvx4FRaQ0hulotRfjKgBx95m6aH3 NM1HQzAaDYaZlfTcN5O77QVDtwrwxrA1fqc8kmDCSs7i/seK4xKvawolOu9bpVHl HQhfStbkx4+tOzZ0mqhzRgDNtZ6q82cvLkfEH2QJmADpH0bsezFXlzA4nfervbuV mytRfKfJgQVslVtL67ZIwmHQn8ZTslfOfUo5pNDcUzKK0vIOItmjkJJNI9GJz7Od /PcLWPao6hA7JAGzcat6 =2r29 -----END PGP SIGNATURE----- -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/4f4bb092-9858-41ed-147c-3c877619c1ba%40qubes-os.org. For more options, visit https://groups.google.com/d/optout.
