Post #1230567
2026-04-12 07:52 UTC
@happyborg I’m planning a whole post just in the encrypted volume setup since it’s not a very common approach I think. But it does simplify some things compared to FDE which complicates boot of a remote system. This at least enables the system and services that don’t need secrets to start.
I also don’t give the VPS any privileges re: the boxes I control. No SSH keys etc. And PF is on the home side of the tunnel too.
Anytbing else in your threat model?
Replies (1)
-
@happyborg@fosstodon.org 2026-04-12 08:02
@ianthetechie I saw some chap here fighting remote boot due to disk encryption last week, using Proxmox I think. My thought was, I probably don't need that. My HomeLab is for fun = learn then build stuff. Starting with HomeAssistant monitoring humidity sensors as our house has major damp issues. After that, not sure. So my threat model is, try not to be so stupid that stupid can get in, but obviously I'd like better than that with the approaching LLM driven script kiddie security apocalypse.