Bookmeat

joined 1 year ago
[–] Bookmeat@lemmy.world 0 points 1 day ago

Install valid certs. Problem solved.

[–] Bookmeat@lemmy.world 11 points 1 day ago (1 children)

It's about control. And monopolies love control (governments, too). If we let them, they'll take it and then we're screwed.

[–] Bookmeat@lemmy.world 6 points 2 days ago (1 children)

Don't even try to find your YouTube music or video play history in a rational way. It's in your profile! W T F .

[–] Bookmeat@lemmy.world -4 points 2 days ago

Russia is the big bad bear. Palestinians are dirt. That's why it's different.

[–] Bookmeat@lemmy.world 54 points 2 days ago* (last edited 2 days ago) (7 children)

It's probably going to move to hardware attestation similar to what Android and iOS are doing. This may or may not be a good thing.

[–] Bookmeat@lemmy.world 24 points 3 days ago

Just write that they lied. They didn't mischaracterise anything.

[–] Bookmeat@lemmy.world 7 points 4 days ago

Taking the fall for Bibi's failings.

[–] Bookmeat@lemmy.world 27 points 4 days ago (5 children)

For realisies this time! >:(

[–] Bookmeat@lemmy.world 4 points 6 days ago

That's why we load them when we use them.

[–] Bookmeat@lemmy.world 3 points 1 week ago (2 children)

Do not store a LOADED gun.

[–] Bookmeat@lemmy.world 28 points 1 week ago

Give me a free car and I'll test it out with this "service". I'm not buying a car that advertises to me.

[–] Bookmeat@lemmy.world 4 points 1 week ago (1 children)

They made metric paper. Time to make metric phones.

16
submitted 7 months ago* (last edited 7 months ago) by Bookmeat@lemmy.world to c/selfhosted@lemmy.world
 

I currently have a storage server with the following config.

Multiple raid6 volumes (mdadm) -> aggregated into a lvm volume group -> lvm volumes -> encrypted with luks1 -> (no partitioning) xfs file systems mounted and used by the os

I have the following criteria: I want to keep software raid (mdadm) with multiple raid sets, xfs, and lvm. I don't mind using 2fa, but I don't want to just store my secret keys on a dongle attached to my PC because that seems to defeat the point of encryption at rest.

My questions:

  1. Is there a better way to encrypt my data at rest?

  2. Is there a better layer at which to apply the encryption?

I'm mostly unhappy with luks1 over a whole lvm volume and looking for alternatives.

--

Thank you everyone for these great responses! I'll be looking into these ideas :)

view more: next ›