Comment on Remote solution to decrypt disk at boot

<- View Parent
Jean_Mich_Much@jlai.lu ⁨11⁩ ⁨months⁩ ago

No problem, I appreciate ;) I hope my answer was not too rude !

At the beginning to try something different, curiosity. I’ve began to write a comparison but in fact I can not doing that because I never used Linux for self hosted services, just for user things like… Checking my mails. I find it easier for that side.

But, for example , after setting my first jails , I’ve read how I could’ve done it on Linux. I’ve found lxc jails and other) hard to learn and configure while chroot was not enough secure to my taste without a little bit tuning. Jail is native, it’s one easy to read and write conf file and four lines in rc.conf to enable it (with its own virtual network interface). With zfs it’s easy to deploy the same base system for all your jails and to maintain it update and it’s fully isolated. Want to enable another service ? Write theservice_load=“YES” in rc.conf. no systemd linking with some file or whatever I know. Same if you want an additional virtual network (+1 more line). Customizing your kernel, build it and installing it is one conf file to edit +4 for short command line (don’t know how to do on Linux)…

Again it’s not a comparison, it’s just why I stay with freebsd, maybe it’s more comfortable to me because I’m not doing real hard security things, I’m not a pro sysadmin , but I found doing and learning those things (customizing kernel, jails and other things) was (really) easy when reading the clear docs. And many security things are native.

Sorry for the long answer ^^

source
Sort:hotnewtop