NixOS: Installation Guide with RAID 1, encryption, and TPM Unlock (part 6 - Mitigating the volume swap attack)
The NixOS disk is encrypted, but a careful LUKS volume swap attack can still be used to obtain the encryption master key.
There is still a loophole where one could obtain the LUKS volume encryption key using another operating system. Let’s fix that.
The NixOS disk is encrypted, but a careful LUKS volume swap attack can still be used to obtain the encryption master key.
At last, we are going to automatically decrypt the NixOS disk using the TPM!
In the fourth post of our series, we are going to configure Secure Boot to ensure that only trusted operating systems can be executed.
I’m continuing my journey of setting up a NixOS machine with secure and redundant storage. In this post, we’re going to perform the actual OS …
In this post I keep on building a NixOS setup with secure storage, now going deeper into Disko, LUKS, and btrfs.
It is time to migrate from Ubuntu to NixOS!
In April 2009, 16 years ago, I received the Microsoft MVP award for the first time, and I renewed it every year. Until today.
The data center initiative proposed by the federal government has many problems. Let’s dive deep into them and explore alternatives.
In the last few days, I updated this site to Bootstrap 5. I took the opportunity to make several improvements and I want to share how that process …
I abandoned my favorite publishing platform and embraced the Hugo static site generator. In this post, I tell you why.