On Wed, Jan 18, 2017 at 03:38:57 -0800, Chris Marusich wrote: > As a bonus, I realized that one could use this feature to encrypt swap, > also. You can encrypt your swap area by using a swap file in the root > file system. Specifically, if you do something like this...
Using an ephemeral key for swap (that is: a temporary key that is randomly generated and never stored) is preferred: when you unmount it, the data won't be recoverable. Mounting a normal swapfile, on the other hand, writes swapped memory to disk, which opens a host of potential security and forensic issues. Of course, so does traditional swap. :) I'm not familiar enough with Guix (yet!) to know how to set it up, but I also haven't done any research. Arch has a good summary: https://wiki.archlinux.org/index.php/Dm-crypt/Swap_encryption -- Mike Gerwitz Free Software Hacker+Activist | GNU Maintainer & Volunteer GPG: D6E9 B930 028A 6C38 F43B 2388 FEF6 3574 5E6F 6D05 Old: 2217 5B02 E626 BC98 D7C0 C2E5 F22B B815 8EE3 0EAB https://mikegerwitz.com
signature.asc
Description: PGP signature