• 0 Posts
  • 9 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle

  • If you want simple you’ll have to manually decrypt each time it needs doing.

    If you want it to be “automatic” then your best bet is something network based. A “simple” would be to just have a script ssh’s somewhere, pulls the decryption key, and then decrypts the disks. There’s plenty of flaws with this though as while a threat actor couldn’t swipe a single encrypted disk they could just log in as root, get your script, and pull the decryption key themselves.

    The optimal solution would be to also encrypt the root partition but now you need to do network based decryption at boot which adds further complexity. I’ve previously used Clevis and Tang to do this.

    I personally don’tencrypt my server root and only encrypt my data disks. Then ssh in on a reboot or power event and manually decrypt. It is the simplest and most secure option.



  • They do not work well in already humid environments but in a hot and dry climate they do quite well. It absolutely does add to the humidity (obviously) but speaking from experience I’d rather have a evap cooler than not if my AC is out.

    The largest difference in utilizing one over AC is that they rely on airflow so you need to actually ventilate the area you are cooling as compared to AC where you want a sealed space.

    The main driver is power efficiency. Only thing they are doing is running a small water pump and a big fan.