Good to hear. This will be going on a Debian server too.
I just set up tailscale on the RPi that controls my printer so I’ve got a jump host on the LAN now… Just need to make time to setup dropbear (and keys) on the server.
Just a geek, finding my way in the fediverse.
Good to hear. This will be going on a Debian server too.
I just set up tailscale on the RPi that controls my printer so I’ve got a jump host on the LAN now… Just need to make time to setup dropbear (and keys) on the server.
I’d imagine that if you have physical access and don’t mind plugging in a USB then that’s the easier route.
My personal goal is to be able to unlock it remotely in two main scenarios :
Both of those situations lean towards a remote unlock with no USB. The first one is absolutely doable because I have local access and could plug a device in, it’s just awkward. On the second, physical access is impossible so it must be done remotely.
I mentioned it in another comment but the remote unlock while away from home presents extra challenges for me because I access my server externally via Tailscale. Since Tailscale isn’t available at boot (pre-decrypt), then I’ll have to tailnet+ssh to another machine on the LAN (that doesn’t require a boot password/unlock) and then SSH from that machine to the server to enter the LUKS password to allow boot to continue. Sounds feasible, though perhaps a little clunky. That’s my current plan and hoping to try it out this weekend if time permits.
Great, thanks for checking my understanding of it.
If I’m reading the docs correctly, Clevis can rely on a separate Tang server for retrieving the decryption key, right? So in that scenario I’d need to have another machine for Tang that can also auto-boot without entering a boot/LUKS password. Otherwise, if both machines (server+clevis and Tang server) were in the same room and restarted due to power loss, neither would be able to boot if both were encrypted… or did I misunderstand something important?
And I don’t think I actually want “automatic” unlocking. I just want to be perform the unlock (enter LUKS password) remotely. I realize that comes with manual intervention (entering the password remotely) but I’m okay with that. I should probably have clarified that by “home server” I mean a machine the serves nice to have stuff, nothing mission critical. Plus I’m really the only one who uses it currently so I’ll notice it’s down when something doesn’t work and can then initiate the remote unlock/boot : D
Clevis is interesting but I don’t think it matches my specific situation. Glad I know about it now though, thanks for the info.
This is interesting, another one I hadn’t heard of yet. And, the server is running Debian : )
I enjoy the intro too :
You know how it is. You’ve heard of it happening. The Man comes and takes away your servers, your friends’ servers, the servers of everybody in the same hosting facility. The servers of their neighbors, and their neighbors’ friends. The servers of people who owe them money. And like that, they’re gone. And you doubt you’ll ever see them again. That is why your servers have encrypted root file systems
Exactly this. The chances of my server/drives getting stolen is extremely low but I like to take all the precautions I can even if it’s just an exercise in “I can, so I will”. That and the “peace of mind” you mentioned.
I think this is the first time I’ve heard of dracut. I’ll take a look - thanks for the info.
Sounds like something fun to research either way - thanks
O, I fully intend to. Just wanted to ask for opinions who have done it or have tried other things while I’m sitting here waiting for an appointment.
Plus content… Lemmy… Engagement. If nobody posts then there’s nothing here
Thanks!
I don’t get to game much but have Satisfactory in my library, not Factorio. Every time I go to launch “that factory game” I look under the Fs and am always confused why I can’t find it. 10 min later I’ll realize I was thinking of Satisfactory… :P
I clearly haven’t played long enough because I have no idea what the comments are referring to.
I only ran into hostile alien life while gallivanting around and it was usually pretty easy to zap or run away from.
That, or I’m confusing Factorio with Satisfactory which is extremely common.
Real headline is always in the comments. Thank you for your service 🫡
I’ll never not upvote Veronica Explains. Excellent creator and excellent info on everything I’ve seen.
I learned the other day that a few people (devs) I know and respect have pet names and genders for the LLMs they use and converse with them regularly.
I’m rethinking some of my feelings about those people.
Bonus points for no jailbreak required : D I didn’t even realize there was a jailbreak for it (or what benefits there are to jailbreaking it… I should do some research but I haven’t found anything I couldn’t do with the stock firmware and it sounds like you generally came to the same conclusion).
Mine is using the stock firmware, wifi off unless using Overdrive, but I plug it into my computer to charge and load it with books. It just shows up as a mass storage device like a USB thumb drive and you can copy/paste books onto it (or use Calibre). After disconnecting it will scan for new/changed files and auto-import any recognized formats into the reader application.
Also saying Kobo. I’ve got the Kobo Libra Colour and love it.
It’s the only ereader I’ve ever owned but I used the spouse’s Nook and Kindle a couple of times in the past and the Kobo kills it. Granted, we’re talking about a nearly new release of the Kobo vs a 5+ year old Kindle so it’s not a fair comparison.
Because of eInk and auto-sleep, the battery lasts me well over a month of casual reading (~30min before bed) with the occasional multi hour weekend session. Backlight is present and is totally readable in dark areas at <10% brightness; 100% brightness is like a supernova in your face. While the Libra Colour is not specifically a note-taking tablet like a reMarkable, it does just fine for quick notes/todo lists/etc but I did splurge on the ($60) stylus. There’s a “notes” application that comes pre-installed.
eBook support for writing in margins (or over text), underline/circling, highlighting, etc is really nice but occasionally the highlight is flakey when trying to highlight the end of a paragraph. That seems to have been specific to certain epubs rather than an “always” thing, but it happens in around 20% of epubs I’ve used.
EDIT: Notes and highlights you do in an epub (and presumably other formats) are exportable to your PC via Calibre (“Annotations”). I love this because I like to highlight things I find interesting, particularly good quotes, and this gives me an easy way extract them while retaining a reference to which book it was and where exactly in the book it was. Example attached.
Not that I would know from experience, but I hear there are Calibre plugins that will allow a user to pull the DRM’d book (downloaded via Overdrive) to a computer and remove the DRM.
I’ve read that it’s a polite thing to do because you’re able to return borrowed books much more quickly so other users can check them out.
Look at the elitist over here that knows how to read : P
I never learned and you can’t make me.
Just one… For now :)
It’s a Lenovo Tiny refurb and came with a 1TB NVMe which is plenty for playing around but I’ll have to expand if I move my Jellyfin instance to it.