April 13, 2022, 12:20 a.m. | /u/Necessary-Helpful

Privacy & Freedom in the Information Age www.reddit.com

I'm looking to use FDE on my Fedora system drive, most likely with btrfs but otherwise ext4.

Which of these schemes would be most secure?:

1. separate unencrypted /boot on USB thumb drive and fully encrypted NVME OS drive. yubi-key as 2nd factor to decrypt drive. luks headers backed up on other drives.
2. fully encrypted NVME OS drive, including /boot. luks headers backed up on other drives. apparently can't use yubi-key for 2nd factor to decrypt drive if /boot …

cons disk encryption encryption full disk encryption privacy

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Dir-Information Security - Cyber Analytics

@ Marriott International | Bethesda, MD, United States

Security Engineer - Security Operations

@ TravelPerk | Barcelona, Barcelona, Spain

Information Security Mgmt- Risk Assessor

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SAP CO Consultant

@ Atos | Istanbul, TR