this post was submitted on 16 Jan 2025
173 points (98.9% liked)

Linux

49140 readers
1174 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS
 

I was recently intrigued to learn that only half of the respondents to a survey said that they used disk encryption. Android, iOS, macOS, and Windows have been increasingly using encryption by default. On the other hand, while most Linux installers I've encountered include the option to encrypt, it is not selected by default.

Whether it's a test bench, beater laptop, NAS, or daily driver, I encrypt for peace of mind. Whatever I end up doing on my machines, I can be pretty confident my data won't end up in the wrong hands if the drive is stolen or lost and can be erased by simply overwriting the LUKS header. Recovering from an unbootable state or copying files out from an encrypted boot drive only takes a couple more commands compared to an unencrypted setup.

But that's just me and I'm curious to hear what other reasons to encrypt or not to encrypt are out there.

you are viewing a single comment's thread
view the rest of the comments
[–] mholiv@lemmy.world 4 points 5 days ago* (last edited 5 days ago) (5 children)

I would strongly encourage people to encrypt their on site data storage drives even if they never leave the house and theft isn’t a realistic thing that can happen.

The issue is hard drive malfunction. If a drive has sensitive data on it and malfunctions. It becomes very hard to destroy that data.

If that malfunctioning hard drive was encrypted you can simply toss it into an e-waste bin worry free. If that malfunctioning drive was not encrypted you need to break out some heavy tools tool ensure that data is destroyed.

[–] scholar@lemmy.world 10 points 5 days ago (2 children)

1 torx screwdriver 1 hammer

not the hardest thing to scratch up the platters and then fold them into abstract art

[–] IsoKiero@sopuli.xyz 3 points 5 days ago

I don't bother to take out the screws. I just drill handful of holes trough the whole thing. Or if you're really paranoid a MAP torch is enough to melt the whole thing (don't breath the smoke).

[–] mholiv@lemmy.world 2 points 5 days ago

True. This does work. But it is less secure and much harder than just tossing an encrypted HDD into an e-waste bin. It probably is more fun though. 🤔

[–] InFerNo@lemmy.ml 2 points 4 days ago (1 children)

If your drive starts malfunctioning, then without encryption you might be able to read some sectors and recover a few things. With encryption you are SOL.

[–] mholiv@lemmy.world 1 points 4 days ago* (last edited 4 days ago)

This is why backups are important. But even if the drive is encrypted recovering data is exactly as easy as recovery from a non encrypted drive.

  1. Do a ddrescue of the drive.
  2. Re apply the luks header.
  3. decrypt all non corrupt sectors
  4. Use appropriate tools to recover files.

Like you lose the same sectors if those sectors are encrypted or not.

[–] netvor@lemmy.world 2 points 4 days ago (1 children)

Great point.

I provided reasons why I encrypted my drives but this one is even better.

(Another one could be if you need to get your computer to a repair shop, and for some reason you can't just remove the drive.)

[–] mholiv@lemmy.world 1 points 3 days ago

Another one is that if you delete a file on an encrypted drive it can’t be undeleted later on. Lots of benefits.

[–] bjwest@lemmy.ml 1 points 4 days ago (1 children)

If that malfunctioning drive was not encrypted you need to break out some heavy tools tool ensure that data is destroyed.

If by heavy tools, you mean a screwdriver and an angle grinder, then yeah, but it's not that hard in reality.

[–] mholiv@lemmy.world 1 points 4 days ago

I mean if you have an angle grinder and a space to safely use it sure. But it’s still harder than just dropping the HDD off at an e-waste bin.

[–] Limeade3425@lemmy.one 1 points 4 days ago (1 children)

I just encrypt devices that leave the house. I do have access to a hard drive crusher if I lose a drive (recently crushed a tablet that wouldn't power on)

[–] mholiv@lemmy.world 1 points 4 days ago

Fair. If you have access to a crusher then maybe I can see not encrypting. But even then with non encrypted drives files can be recovered even after deleting etc.