Full Encryption Setup
Posted: 29 May 2015, 05:12
Greetings Earthlings,
I want to encrypt everything on my Debian box, and although there are plenty of howto's on doing this, I haven't seen a single howto that explains why to do any of the steps outlined in the instructions. In short, I have a Debian Wheezy box that has an 80GB drive where I plan to have the OS and swap, and I have a 1TB drive where I plan to store my data. I would like both drives fully encrypted and would like one password for both but would settle for two passwords if need be. However, while setting this up I would like to know the answers to questions like:
It just feels to me like there is a lot of stuff that just "happens magically in the background" rather than being controlled specifically by me. Am I just being paranoid and I should just trust that these questions don't need to be asked? Am I way off base here?
S.
I want to encrypt everything on my Debian box, and although there are plenty of howto's on doing this, I haven't seen a single howto that explains why to do any of the steps outlined in the instructions. In short, I have a Debian Wheezy box that has an 80GB drive where I plan to have the OS and swap, and I have a 1TB drive where I plan to store my data. I would like both drives fully encrypted and would like one password for both but would settle for two passwords if need be. However, while setting this up I would like to know the answers to questions like:
- Is there something better than dmcrypt/LUKS that I should use?
- What cyphers are not available to me and why not?
- What cyphers are available to me, which should I use, and why?
- What hashing systems are not available and why?
- What hashing systems are available, which should I use, and why?
- Should I be concerned about entropy generation and if so then how do I manage it?
It just feels to me like there is a lot of stuff that just "happens magically in the background" rather than being controlled specifically by me. Am I just being paranoid and I should just trust that these questions don't need to be asked? Am I way off base here?
S.

