!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

703 Members
Coordination and triage of security issues in nixpkgs216 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
5 Jul 2024
@raitobezarius:matrix.orgraitobezariusoriginal reporter says12:00:27
@raitobezarius:matrix.orgraitobezarius

I have a similar setup with an unencrypted /boot and an encrypted /. When I start the OS it just boots all the way to user login not requiring my decryption password at any time.

12:00:28
@raitobezarius:matrix.orgraitobezariusbut makes no mention of BIOs or UEFI12:00:37
@raitobezarius:matrix.orgraitobezarius * but makes no mention of BIOS or UEFI12:00:41
@septem9er:fairydust.spaceSeptem9er
In reply to @raitobezarius:matrix.org
well /boot is a cryptodisk in that situation so the keys over there are still as protected as before
Yeah. The key is an unencryped boot partition, like it was already said.
12:00:48
@raitobezarius:matrix.orgraitobezarius
In reply to @septem9er:fairydust.space
Yeah. The key is an unencryped boot partition, like it was already said.
yeah but let's distinguish two things
12:01:04
@raitobezarius:matrix.orgraitobezarius(a) the installer creates an unencrypted /boot with an encrypted / by itself12:01:15

Show newer messages


Back to Room ListRoom Version: 6