@nixCraft@mastodon.social avatar nixCraft , (edited ) to random

Poll: Is your laptop's (or desktop's) hard disk fully (FDE) encrypted?

grahamperrin ,
@grahamperrin@bsd.cafe avatar

@nixCraft nearly all suitably encrypted. No FDE.

OpenZFS encryption for:

  • the sensitive part of a mobile hard disk drive

  • three low-spec USB memory sticks that add around 145 GiB persistent removable L2ARC to a circa 2014 HP ZBook with 32 G memory and a ~1 TB internal HDD.

GELI for 16 G swap.

GELI for 915 G /

tmpfs for /tmp/

<https://github.com/openzfs/zfs/issues/10256>

「… blocks in the L2ARC have the exact same on-disk representation as they do in the main pool. …」

geli(8) <https://man.freebsd.org/cgi/man.cgi?query=geli&sektion=8&manpath=freebsd-release> – automatically configured when FreeBSD was installed.

tmpfs(4) <https://man.freebsd.org/cgi/man.cgi?query=tmpfs&sektion=4&manpath=freebsd-current> (FreeBSD 15.0-CURRENT)