I suppose boot(8) supporting now crypto volumes would face same attack as truecrypt - Evil Mail[1]
Could be some easy _workaround_ for this? Such as copying boot loader from fixed disks to an usb stick to prevent this kind of physical hardware attack? jirib [1] http://theinvisiblethings.blogspot.cz/2009/10/evil-maid-goes-after-truecrypt.html