• fmo@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    11 months ago

    I only encrypt the data using LUKS and I have a password stored in Google Secrets Manager. I have a script that runs as a systemd service, goes fetch the password and unlocks the volume. If the drive is somehow stolen, I just revoke the key and the data is unreadable.