Comment on Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
talkingpumpkin@lemmy.world 2 days ago
Does this have anything to do with self hosting?
Comment on Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
talkingpumpkin@lemmy.world 2 days ago
Does this have anything to do with self hosting?
modem_down@thebrainbin.org 2 days ago
Yes. Here are 3 common self-hosting scenarios:
For all three, FDE is a sensible precaution to protect the data in case the server is physically stolen.
Linux is probably the most common OS kernel for self-hosting. On that kernel, [LUKS (Linux Unified Key Setup)](Linux Unified Key Setup) is probably the most sensible FDE system to use. It's mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.
Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted. Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.
However, there is more than one way to do that. Hence the question in my OP.
talkingpumpkin@lemmy.world 1 day ago
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
There’s a project that allows unlocking LUKS with a decryption key retrieved from another machine in your network. I don’t recall the name but someone hopefully will.
The idea is that put the key on, say, a raspberry pi zero w that you hide somewhere in your house so that if someone steals your server they don’t have the key.
percent@infosec.pub 17 hours ago
My servers require manual unlock via SSH at boot. It has been great for years.
JustEnoughDucks@slrpnk.net 1 day ago
Some people are fine with down time/inconvenience in exchange for security.
I have my boot drive on a secured USB and LUKS keyfile with the rest of the partitions on an encrypted SSD and data on encrypted HDDs.
In a smash and grab (or fascist government gestapo smash and grab), the server is pretty impossible to steal information from (inject illegal content to in order to fabricate evidence) without the USB and they can’t simply inject boot malware either. A network device is almost always findable either by cables or WiFi broadcast analyzing.
modem_down@thebrainbin.org 1 day ago
That depends. If you only plan to boot it when you're physically present, then it's fine.
esc@piefed.social@piefed.social 1 day ago
tang
modem_down@thebrainbin.org 1 day ago
Thanks. TIL about Clevis/Tang.
superglue@lemmy.dbzer0.com 1 day ago
I haven’t actually tried it yet, but on that note, if you have an OpenWRT router you can configure dropbear to unlock it.