Bookmeat

joined 1 year ago
[–] [email protected] 0 points 1 week ago

They all decay to fascism, if you haven't noticed.

[–] [email protected] 5 points 3 weeks ago

Nice. Fuck Russia.

[–] [email protected] 63 points 1 month ago (4 children)

The problem with repairing the earth's climate isn't that we don't know what to do. It's that humans refuse to organize themselves in a way that achieves that goal. AI won't fix that.

[–] [email protected] 44 points 1 month ago

"But the breakthrough will come just as soon as the chips no one can make are delivered."

Probably.

[–] [email protected] 6 points 1 month ago

People will misuse this for personal gain at the expense of others and the planet. Consequences will be dramatic.

[–] [email protected] 28 points 2 months ago

Give me a free car and I'll test it out with this "service". I'm not buying a car that advertises to me.

[–] [email protected] 10 points 2 months ago (1 children)

Poachers. Poachers are next.

[–] [email protected] -4 points 3 months ago (2 children)

Back of a cell phone won't work because people put those into bulky cases.

[–] [email protected] 1 points 3 months ago

Right. I forgot that browsers have the roots built in. Thanks!

[–] [email protected] 1 points 3 months ago (3 children)

Do they though? If you're going to forge one cert why not forge the whole chain?

[–] [email protected] 2 points 3 months ago (5 children)

Aren't they a MITM here? Can't they easily forge certs for the domain name of their fake resolvers since they intercept and resolve your DNS requests?

16
submitted 9 months ago* (last edited 9 months ago) by [email protected] to c/[email protected]
 

I currently have a storage server with the following config.

Multiple raid6 volumes (mdadm) -> aggregated into a lvm volume group -> lvm volumes -> encrypted with luks1 -> (no partitioning) xfs file systems mounted and used by the os

I have the following criteria: I want to keep software raid (mdadm) with multiple raid sets, xfs, and lvm. I don't mind using 2fa, but I don't want to just store my secret keys on a dongle attached to my PC because that seems to defeat the point of encryption at rest.

My questions:

  1. Is there a better way to encrypt my data at rest?

  2. Is there a better layer at which to apply the encryption?

I'm mostly unhappy with luks1 over a whole lvm volume and looking for alternatives.

--

Thank you everyone for these great responses! I'll be looking into these ideas :)

view more: next ›