11-05-2019, 08:56 PM
You answered what I was asking for but not what I meant
I was interested in the advantage of luks / over luks /home. I think that boils down to:
Swap can be trivially encrypted with luks as well. /tmp can be made a memory filesystem - that's not the default in our Debian, though. It's really not great exposing /var/log and /etc.
I was interested in the advantage of luks / over luks /home. I think that boils down to:
Quote:While you can keep all private data in your homedir, it's easy to leak outside that - /var/log, swap, /etc, /tmp, etc.
Swap can be trivially encrypted with luks as well. /tmp can be made a memory filesystem - that's not the default in our Debian, though. It's really not great exposing /var/log and /etc.