Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: Encrypting Ubuntu - Protecting Assets

  1. #11
    Join Date
    Sep 2007
    Beans
    59

    Re: Encrypting Ubuntu - Protecting Assets

    I appreciate everyones time, input and ideas on solutions.

    I should probably clarify; this PC is litterally just in a shed / workshop of mine, its not a high value system but rather a Intel NUC which is a few years old (but much loved as it has served me well).

    I understand that a lot of different encryption mechanisms can only be relied upon for their full protection when at rest / off, but in this scenario I am anticipating physical theft by a unsophisticated thief and assume it will be off when stolen. Considering the workshop is alarmed I'm not anticipating a burglar to be tampering, rebooting or working with the system whilst online, it's going to be a snatch and grab afair if anything happens.

    It wont be storing any critical or highly sensitive information which may be attrative to sophistcated attackers, but rather I just wanted to limit damage from logged in browser sessions, keys or other credentials from being stolen if it were physically stolen from me.

    I hadn't thought about running the system within a VM on it, which is crazy really considering as part of my work we run hundreds of servers many of which utilise different forms of virtualisation + and at home for personal use I use VirtualBox.

    Whilst I do love virtual machines I have found the visual / graphical capabilities a little limiting at times and buggy, for a power use that uses a wide variety of applications. This system in the workshop will be using CNC/Laser software and working with graphics a lot. Still I could give virtualisation a go, it may be a good combo in this scenario.

    I also love Raspberry Pi's so I thought the idea of using one of those as a out of band input device was cool. I also have access to a few Yubikeys and other 2FA possibilities so I really do appreciate all the ideas.

    I'll have to see if my NUC has any inbuilt Intel out of band capabilities as well.

  2. #12
    Join Date
    Mar 2010
    Location
    Squidbilly-Land
    Beans
    Hidden!
    Distro
    Ubuntu

    Re: Encrypting Ubuntu - Protecting Assets

    Thanks for posting the location. That information would have been very useful a few days ago. Seems the real issue is just having to walk 200 ft on a cold night. If that is true, I'd just use normal LUKs whole-drive encryption with a challenge/response yukikey to access it and a 50+ random character passphrase as a backup. I don't have the details handy, but this:
    https://www.howtoforge.com/ubuntu-tw...tion-with-luks seems reasonable for a how-to.
    There are 8 slots for authentication in LUKS. Pick which ever slots you like, just be certain they are different.

    Current KVM+libvirt+spice protocols are amazing.

    Ran into a guy who used AutoCAD inside a Windows VM over Spice. My recent testing of SPICE connections, local and remote, show it to be freakin' amazing compared to what we had 2+ yrs ago. I think the KVM + Spice improvements were all backported to 16.04.

Page 2 of 2 FirstFirst 12

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •