-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Chris Laprise:
> On 09/26/2017 11:14 AM, Peter Todd wrote:
> > Re: privacy, you can setup swap files to use encrypted storage with *volatile*
> > encryption keys that are generated at boot, and never get written to persistent
> > storage. Dunno if Qubes does this already, but I've set this up myself on
> > Debian boxes before.
That would be
https://github.com/QubesOS/qubes-issues/issues/977 - now
titled "Use random encryption key for swap partition".
> So now I'm looking at my /etc/crypttab wondering if I can change it to use
> /dev/urandom ?
For R3.2 btrfs setups, see
https://gist.github.com/rustybird/917ac2560fe4e9541d1f
but it won't work on LVM, i.e. R4.0... :(
Rusty
-----BEGIN PGP SIGNATURE-----
iQJ8BAEBCgBmBQJZ7K9aXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXQ4NEI1OUJDRkM2MkIxMjlGRTFCMDZEMDQ0
NjlENzhGNDdBQUYyQURGAAoJEEadePR6ryrfhBoP/iC4c8L7X5yOa5G9K32qfT/g
K3JPfFy7GadzZjXH9Qb4AG1ioP+IdwpzGgsJKSRCIO3DMXc63Q1cgftvQInEUaB+
CiLC/FnTaJEXWJUGnwJQmyUbh3185hRgfH9m3gtLkseYVaV5BA1EikNgEP4wmgce
EFhwCKhaKK0p7Be77QBwu64cHz15aLuL+vy0hCyRvnYZGe0Pl6mUj1ycWFym8TaP
B/DqAxVhkuuhhalP572r6tZWOH+hVAWXgXf+ZYYeYY7CTs+Bj46OKhqMe4nH6mnd
oLZ9K7qTt9W4jmBkbeLd7wutrJMYXx/mQ0Rzoqeth+B7HGnLZsAwnhapp3Rrdsal
Pu5QneF844TCZLq384rShvigMoigyMKJoKOCDFRmnhR74RWD7YFIgel7tnQd3AsC
m7yAjpjd9viRDYmzQKBeKDjax51kOBSfJzN8z0zzM81vcyaV0HLJNAcM4rHgzJF9
V2g0agDCQ2Dt/3Nw4Ns8mEH5eUEyiPS2+UywMvLYVWXbSZ2kiq5AO66yGRxsmewx
ciXNsE+Ui4c5j+GtdTHSC58nrIANKC1joCq56COPvf4cChSrc+e8OaG06DecJl9d
d04KimpF3GBNF/UV6rpHO6Go5gDSuWM8CXyZ+Q7pTlZZL3Ek5UZPFTAX+zEcUdLk
cd0OWjVuhxMAkoXEH2Zj
=ur/t
-----END PGP SIGNATURE-----