U
U
user0name02018-09-11 16:20:20
linux
user0name0, 2018-09-11 16:20:20

Encryption without data loss on Linux?

What are the options for encrypting the entire disk or at least the / home partition without losing data?
If only /home is encrypted, what data can be retrieved if there is physical access?

Answer the question

In order to leave comments, you need to log in

4 answer(s)
X
Xadok, 2018-09-27
@user0name0

It doesn't make sense to encrypt only /home. Encrypt /var and swap at the same time. The most convenient option to use is to encrypt the entire drive with LUKS. Only the efi section remains, tk. Previously, it was impossible to boot from the encrypted partition, now cryptoboot has appeared, but has not yet deployed it. Install lvm on a fully encrypted drive. We get +1 abstraction level from lvm. It is also natural to lose speed due to this and due to encryption. This difference is not very noticeable on ssd, but a different result is possible on HDD. The above process is well described https://wiki.archlinux.org/index.php/Dm-crypt/Encr... here, there is also an overview of the main ways to encrypt a whole drive besides truecrypt/veracrypt.

S
Stanislav Bodrov, 2018-09-11
@jenki

As mentioned above - GnuPG. It may not go by default in some distributions (minimal option), it is installed with one command, it does not take up much space. Extremely convenient and functional program. Supports symmetric and asymmetric (even on elliptic curves) encryption, signature, compression.

If only /home is encrypted, what data can be retrieved if there is physical access?
In the case of a symmetric key of 256 bits or an asymmetric key on elliptic curves of 512 bits, nothing but a headache for an outsider.

N
NSA-bot, 2018-09-14
@NSA-bot

So Linux Mint has full-disk encryption out of the box. When installing the system, check the box and indicate which partitions and everything is encrypted (if I'm not mistaken with LUKS). You can encrypt the hamster separately, and it will work transparently for you. And if you mount such a partition under a different user or to another computer, then nothing is visible there. Well, that is, it is clear that there is encrypted and that's it.

O
O. J, 2018-09-11
@OrlovEvgeny

GnuPG (from GPG) - already pre-installed on most distributions. Mainly used for asymmetric encryption.
all encrypted data without the private part of the key is just garbage.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question