𝒍𝒆𝒎𝒂𝒏𝒏

Hey! Please contact me at my primary Fedi account: @lemann@lemmy.dbzer0.com

https://lemmy.one/u/lemann@lemmy.dbzer0.com

  • 0 Posts
  • 30 Comments
Joined 1 year ago
cake
Cake day: June 6th, 2023

help-circle
  • Flash drive hidden under the carpet and connected via a USB extension, holding the decryption keys - threat model is a robber making off with the hard drives and gear, where the data just needs to be useless or inaccessible to others.

    There’s a script in the initramfs which looks for the flash drive, and passes the decryption key on it to cryptsetup, which then kicks off the rest of the boot mounting the filesystems underneath the luks

    I could technically remove the flash drive after boot as the system is on a UPS, but I like the ability to reboot remotely without too much hassle.

    What I’d like to do in future would be to implement something more robust with a hardware device requiring 2FA. I’m not familiar with low level hardware security at all though, so the current setup will do fine for the time being!









  • That’s surprising. Dell should have good Linux driver support, seeing as they offer Ubuntu pre-installed in some markets.

    Saying that, we have work issued Dell Precision mobile workstations and there are constantly hardware and driver issues under Windows, where you’d expect things to work just fine…

    • the internal microphone not working (handy for meetings!)
    • the 3.5mm combo jack not working (ah, great, no backup for when the internal microphone stops working)
    • the battery handshake failing, causing the machine to not charge, stay stuck in a low performance mode, and constantly pop up Windows notifications saying the battery is not genuine
    • the presence sensor locking the laptop while you’re literally working it

    Now I use a USB headset, disabled the presence sensor, and reboot the laptop repeatedly until the battery is detected as genuine