Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

Do I need to create FS on BIOS boot partition?


Re: [Trisquel-users] what happened to http://packages.trisquel.info?

2016-10-28 Thread stas . mihaylenko

Try HTTPS instead of HTTP.


Re: [Trisquel-users] what happened to http://packages.trisquel.info?

2016-10-28 Thread greatgnu
It appears that for some reason your Abrowser is set to force https. I have  
httpseverywhere here but browser behaves normally, that is, being that  
http://packages.trisquel.info/ has no https it stays it stays on the page,  
and if I **manually** add the "s" to the http in the url, only then I get  
redirected to  https://devel.trisquel.info/groups/trisquel


cheers


Re: [Trisquel-users] Libreboot Developer Leah Rowe Attack gnu and rms Again

2016-10-28 Thread dguthrie

and... the echo chamber echoes forever


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

And what partition is bootable?


[Trisquel-users] Re : How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread lcerf
There is no filesystem (hence no file) on a BIOS boot partition. That concept  
is unknown to the BIOS. Your BIOS boot partition only has GRUB's stage 1.5  
code, which includes drivers to read all the popular filesystems. In this way  
stage 2 can be in regular files in /boot/grub, kernel images can be loaded by  
their paths, etc.


'grub-install' has not had a --root-directory option since GRUB 1.99. It  
still has a --boot-directory option though. It specifies, well, the boot  
directory, i.e., /boot by default. It is useful when installing from a live  
system (otherwise 'grub-install' will consider the /boot of the live system).


[Trisquel-users] Re : How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread lcerf
If by that you mean "which partition must have the boot flag", the answer is  
none. The BIOS boot partition must have the bios_grub flag though.


[Trisquel-users] Re : How simple/complex is your installation process?

2016-10-28 Thread lcerf

I managed to get the swap encrypted and functional:
$ swapon -s
FilenameTypeSizeUsedPriority
/dev/mapper/cryptswap1  partition   8388604 384 -1
However, I am not quite sure how! Something I did was to *only* have that  
line in /etc/crypttab:

cryptswap1 /dev/sda1 /dev/urandom swap,cipher=aes-cbc-essiv:sha256
/etc/crypttab was containing several lines (probably one per attempt to run  
'sudo ecryptfs-setup-swap'), where the swap partition was specified by  
UUID... with a different UUID on each line. As you can see above, I specified  
the device (/dev/sda1; to change if 'lsblk' indicates another device) rather  
than its UUID. I then rebooted. But I guess there is a way to enable the  
encrypted swap without rebooting.


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

Oh no. I marked LVM as bootable.
Can GRUB_BIOS be in (encrypted) LVM?


Re: [Trisquel-users] How simple/complex is your installation process?

2016-10-28 Thread greatgnu
> However, I am not quite sure how! Something I did was to only have that  
line in /etc/crypttab:

cryptswap1 /dev/sda1 /dev/urandom swap,cipher=aes-cbc-essiv:sha256

Yeah, the line is here too.


Re: [Trisquel-users] Need to Uninstall Trisquel

2016-10-28 Thread silentdreamer
I looked for Xfce in synaptic, what I saw was Xfce 4, and one mention of Xfce  
keyboard. There were many Xfce4's in the list, I have to find which one to  
get. As much as I like Trisquel, I'm still uncertain about keeping it. One  
feature I really like about Trisquel is the screenshot, to me it's a very  
important tool. I noticed Mini doesn't have it, there's a program that can be  
had separately though. I saw a post about that someplace.


Re: [Trisquel-users] Need to Uninstall Trisquel

2016-10-28 Thread silentdreamer
I read some of your prefs, noticed some mention of windows and NT. That says  
to me it's referring to your computer and OS, am I correct?


Oh, and speaking of javascript, you know Diaspora uses it, I'm sure.

Also, about add-ons for Tor- I read it's not recommended to put more than  
what they put in. Some years ago someone said not to use addblock, because it  
reveals info- whatever we use, the sites know we're using it. Would the  
random browser spoofer fool sites into seeing something other than Tor? Would  
that compromise Tor's purpose? Maybe I'll ask this stuff on D, too, and go to  
Tor's IRC channel. I'd have to get my messenger back, when I got scared about  
the DDos, I deleted it.


I haven't added anything new to Tor yet. On IceCat I have HTTPS Everywhere,  
UblockOrigin, Cookie Monster, SpyBlock, Random Browser Spoofer (hope I'm  
remembering the name of that right), NoScript, and I think that's it but  
that's enough. SilverWolf told me too many add-ons could mess things up. He  
helped me get Trisquel.


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

Help me…


[Trisquel-users] Re : How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread lcerf
With GRUB in the MBR, the boot flag is not used. grub_bios is the BIOS boot  
partition:  
https://trisquel.info/forum/how-install-gpt-bios-full-disk-encryption-boot#comment-104804


[Trisquel-users] Re : Need to Uninstall Trisquel

2016-10-28 Thread lcerf
If you want the whole Xfce4 environment, then install "xfce4". It is a  
meta-package that depends on the whole Xfce4 environment. There is a package  
"xfce4-screenshooter" and you may like it. Otherwise, nothing prevents you  
from using "gnome-screenshot" (the name of the command and of the package) on  
Xfce or any other desktop environment.


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

Ok. The last questions:
1. Can bootable BIOS partition be in LVM
2. Can bootable BIOS partition be in encrypted LVM
3. If I will check "Yes" for /home encryption and then create big LVM with  
/boot, /home, / and swap — can I use Hibernate on my laptop after this?


[Trisquel-users] Re : Need to Uninstall Trisquel

2016-10-28 Thread lcerf
Website can detect many things about the Web browser configuration. It can  
indeed know that an ad blocker is used. It can know as well that Tor is used  
(its exit nodes are not secret). The more tweaking, the higher the risk that  
the fingerprint of the browser is (close to) unique and that websites can  
track you. That is why the Tor Browser is configured in a very generic way.  
It even sends wrong information to the websites because that information is  
more common. The developers recommend not to install add-ons or plugins  
because that makes the fingerprint more unique.


All that said, another possibility is to randomize the information, in  
particular the user agent information that gives what browser in what version  
is used. The add-on named "Random Agent Spoofer" does that. But the developer  
of the Tor browser argue that uniformity is safer than randomization:  
https://www.torproject.org/projects/torbrowser/design/#fingerprinting-linkability


[Trisquel-users] Re : How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread lcerf
I have already told you: unless we are talking about hardware-based  
encryption (we are not), the BIOS boot partition cannot be encrypted. And I  
see no reason to manage it with LVM (it is 1 MB large) or to encrypt it (it  
only contains GRUB's stage 1.5).


I have never used LVM but I doubt you can have logical volume inside logical  
volumes. There are ways to encrypt the swap and still be able to hibernate:  
https://help.ubuntu.com/community/EnableHibernateWithEncryptedSwap


Re: [Trisquel-users] Need to Uninstall Trisquel

2016-10-28 Thread silentdreamer
Thank you for the info, I was reading some info at Tor earlier and I'll go to  
the link you gave me.


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread stas . mihaylenko

I following Ubuntu guide: manual disk partitioning & data erase on.


Re: [Trisquel-users] How to do full disk encryption.

2016-10-28 Thread dread71
I don't have a swap partition. Is there anything else I should encrypt? 


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread travis
I'm pretty sure MagicBanana was helping you... by telling you what you want  
is not currently possible. It's obviously not what you want to hear but  
there's nothing we (or you) can do about it, unless you add designing an  
entirely new way for computers to function as we know it to your growing list  
of projects that is.


Re: [Trisquel-users] How to do full disk encryption.

2016-10-28 Thread Alexander Stephen Thomas Ross
hmm...
with full disk encryption there is small partition of around
200MB-hmm300MB(?) of size. which is where the boot loader/kernel is
stored. other wise whats left to load the OS? some software has to be
loaded else how to decrypt and load the system ;)

what can be done is to have the boot partition -as its called- on
another drive, like a usb flash drive. that way only encrypted data is
on the drive in the computer and you can keep the all important
non-encrypted boot partition on a usb drive/sick which you can keep on
your person at all times but for when your using/have the laptop booted.
so its harder for an attacker to physical get hold of it and add a backdoor.

i think this is helpful, when getting though air port "security".

so it depends on your threat level or convenience level


Re: [Trisquel-users] Need to Uninstall Trisquel

2016-10-28 Thread greatgnu

sudo apt-get install xfce4 xfce4-goodies

enjoy :)


Re: [Trisquel-users] Need to Uninstall Trisquel

2016-10-28 Thread greatgnu
>I read some of your prefs, noticed some mention of windows and NT. That says  
to me it's referring to your computer and OS, am I correct?


I assume you are referring to the prefs.js file.
Those are fake values to override the user agent. On panopticlick, with no  
js, I get 6 bits of identifying information, heh ^^


Re: [Trisquel-users] How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread greatgnu

..and the patience award of the year goes to..

https://s-media-cache-ak0.pinimg.com/originals/90/79/02/907902e68927062117ff80840e212c6d.jpg


[Trisquel-users] Re : How to do full disk encryption.

2016-10-28 Thread lcerf
You have encrypted the most sensitive data. However things written in /tmp  
(and maybe in /var) can reveal personal information. If you decide that you  
need fukll-disk encryption, then it is easier to install Trisquel again:  
https://trisquel.info/en/wiki/full-disk-encryption-install


[Trisquel-users] Re : How to install GPT on BIOS & full disk encryption (with boot)?

2016-10-28 Thread pinmaritim

Heres some mushrooms..