• 1 Post
  • 6 Comments
Joined 2 years ago
cake
Cake day: February 24th, 2025

help-circle




  • The thing about automated encrypted drive unlock is that you are missing kernel check pcr (8 or 9 I don’t remember) and without that anyone can boot with compromised kernel and unlock your drive. Which makes encryption kind of pointless. The same pcr, however, means that you have to rebind after every kernel update (which is quite often on many distros). The disadvantage is that with current state of the software handling auto unlock on Linux is kinda flaky and rebinding may involve more than one restart. I eventually realized that it’s less trouble to just skip this altogether and enter the password every time and then set autologin.


  • The permissions have to be justified when uploading to flathub (via PR) and the exceptions are not always accepted. Flatpaks ARE safer than system packages and if you think otherwise I recommend you taking a look who can access all passwords on the keyring and who doesn’t. (Getting such exception on flarhub is very hard). Flatpak 2.0 hopefully gets user approvals for permissions. But still with current flatpak you have the option to reject permission via flatseal.