Skip to content
Go back

Encrypting Linux: from a hack 20+ years ago to firewalls, LUKS and Veracrypt

Edit page

Encrypting Linux: from a hack 20+ years ago to firewalls, LUKS and Veracrypt

Arch Linux. firewalld (nftables) for the network, then LUKS-encrypted root, an unencrypted /boot, and a Veracrypt USB volume.

My experience with Linux dates from over 20 years ago. This is a personal account of how a break-in pushed me from detecting tampering to preventing it — locking the network with a firewall first, then encrypting every disk I own.

Infographic: Encrypting Linux — the hack, detection to prevention, firewall first, LUKS, cryptsetup, overhead, Veracrypt, and rsync backup

1. The hack that started it

2. The shift: from detection to prevention

3. Firewall first: the network before the disk

4. LUKS: encrypting the operating system

5. Veracrypt: encrypted partitions and USB disks

6. What happens if the laptop is stolen

7. Daily backup: rsync from the LUKS disk to the Veracrypt USB

8. Habits

Open questions

Verification commands

lsblk -o NAME,FSTYPE,MOUNTPOINT
findmnt -no FSTYPE /
findmnt -no FSTYPE /boot
command -v cryptsetup veracrypt
# firewall
iptables --version; nft --version
command -v firewall-cmd nft
# requires root; inspect key slots and header info
sudo cryptsetup luksDump <luks-device>

Glossary

Sources

btw, i use arch


Edit page
Share this post on:

Next Post
林徽因