Thanks lembas, that's a great option.
Thanks jxself, now I know how to do it, and why I should (or not).
The way I roughly consider my threat model is this: even if there's no threat involved, if it's easy/takes little time to setup, it's better to have it than not.

This could be a good option for computers that don't support libreboot and can't have an encrypted /boot (since proprietary BIOSes typically do not have support for reading an encrypted /boot it needs to be left unencrypted.) Looking at this (https://wiki.archlinux.org/index.php/GRUB#Boot_partition) and this (http://www.pavelkogan.com/2014/05/23/luks-full-disk-encryption/), it seems I don't need to be on Libreboot in order to have a functioning encrypted /boot anymore. Grub offers this exception now.

Even if I'm not on Libreboot on this machine, I still can boot manually. But I can't figure out how to save my manual input. Yet.




Reply via email to