Archlinux encrypted install - theft proof laptop install

Поділитися
Вставка
  • Опубліковано 5 лис 2024

КОМЕНТАРІ • 97

  • @quiznoid
    @quiznoid 7 років тому +52

    I could just imagine a thief, stealing someone’s laptop, but the laptop has Arch Linux on it.
    So when he turns on the computer, he would be sooo confused haha

    • @andrewnforsyth
      @andrewnforsyth 5 років тому +8

      works good with tech support scammers

  • @whydontyouwork
    @whydontyouwork 7 років тому +32

    Loving the content. I'm a Linux newb. And your videos are confusing and interesting at the same time lol

    • @ryanmcconkey5817
      @ryanmcconkey5817 6 років тому +3

      whydontyouwork welcome to Linux! :D glad to have you aboard . Linux is awesome haha :p I use arch linux :)

    • @srgk26
      @srgk26 5 років тому +1

      Ryan Mcconkey Basically every arch user haha! I use arch btw!

    • @jeffersondavis9397
      @jeffersondavis9397 2 роки тому

      Do you still use Linux?

    • @whydontyouwork
      @whydontyouwork 2 роки тому

      @@jeffersondavis9397 I am a sysadmin at enterprise level now. It’s a windows environment as most companies are. I don’t generally use Linux.

  • @o0Enmity0o
    @o0Enmity0o 6 років тому +4

    Finally, someone who makes my ‘office’ look semi organised. 👌

  • @kasimirdenhertog3516
    @kasimirdenhertog3516 5 років тому +3

    Hi Kai, this video is outdated. I installed Arch before, using this video as a guide. I was now looking it up because I’m doing a fresh install, but I got stuck adding the ‘encrypted’ hook, because mkinitcpio was nowhere to be found... It appears ‘pacstrap /mnt’ is not enough anymore. You have to include ‘linux’ at the end of the command at the least, or better, as per the Arch docs: ‘pacstrap /mnt base linux linux-firmware’. For me, that was still not enough, as I needed DHCP, so I had to pedal back a bit and add ‘dhcpcd’ to the pacstrap command as well.

    • @kaihendry
      @kaihendry  5 років тому +1

      I agree I need to redo this. Struggling to find time.

  • @atomicorang
    @atomicorang 6 років тому +1

    Kai..i always enjoy watching.. You are awesome and make it interesting.

  • @FatboyBass
    @FatboyBass 6 років тому +2

    Thanks for the video. I enjoyed the way you broadcast the terminal. Hopefully you have a tutorial on that. Also good to see another AwesomeWM user in the world. I am hoping this method is as simple with using rEFInd as the bootloader.

    • @kaihendry
      @kaihendry  6 років тому +2

      I use dwm.suckless.org/

    • @FatboyBass
      @FatboyBass 6 років тому +1

      @@kaihendry I3 DWM AwesomeWM. All very close to each other. Tiling Managers for the win

  • @CarlosLopez-oc9nh
    @CarlosLopez-oc9nh 4 роки тому

    Thank you for posting was looking for examples to prepare for LPIC2.

    • @kaihendry
      @kaihendry  4 роки тому

      I have no clue about LPIC2. Do tell me if you pass! Good luck

  • @atomicorang
    @atomicorang 6 років тому +1

    Kai you are brilliant. The X1Carbon is what I would love. You think gen 3 would be sufficient for linuxmint or Arch? Im sporting T430S w/LM 18.3. with the trackpad, camera and microphone disabled.

    • @kaihendry
      @kaihendry  6 років тому +1

      I ran a X1C3 before, no show stoppers come to mind.

  • @voiceoftreason1760
    @voiceoftreason1760 7 років тому +1

    Thanks for making these videos. I am wondering something though: At 2:38 in the video, it shows the arch ISO boot manager for BIOS/CSM booting (it looks different when the arch ISO gets booted in UEFI mode). However, you are installing with a GPT. Does that mean you are installing BIOS/GPT? Does the laptop not have a UEFI enabled firmware? I prefer not to use such a setup as it is incompatible with windows multibooting.

    • @kaihendry
      @kaihendry  7 років тому

      I'm assuming UEFI capable hardware and GPT. It is the most compatible dual boot with Windows approach I know of.

    • @voiceoftreason1760
      @voiceoftreason1760 7 років тому

      the screen at 2:38 makes me think you are booting in csm mode in this video. check it out in a virtual machine, the arch usb boot manager looks different when booted up in UEFI mode.

  • @beat461
    @beat461 5 років тому

    Why did you boot the arch ISO USB with legacy BIOS CSM enabled? When you did `bootctl install` at 9:13 it said "not booted with EFI, skipping EFI variable setup. I'm not sure if at the end of the video you booted the encrypted system with the CSM enabled or disabled. Obviously I want to create a UEFI bootable encrypted install so I'm not even sure if this tutorial is useful for me now.

  • @TheDotBot
    @TheDotBot 7 років тому

    Nice work :) I've found it generally easier using an MBR system, is there any reason GPT is better? The network thing (since you mentioned it) - installing and enabling networkmanager while chrooted in makes most sense to me, I'm going to use it anyway and it beats copying in wpa supplicant commands.

    • @kaihendry
      @kaihendry  7 років тому

      Thank you! I think you need GPT for UEFI / bootctl to work.

    • @TheDotBot
      @TheDotBot 7 років тому

      Ah, fair enough!

    • @beat461
      @beat461 7 років тому

      Dave Blair mbr is deprecated and should not be used anymore unless your system doesnt support booting from a gpt disk.

    • @TheDotBot
      @TheDotBot 7 років тому

      YouwillneverdefeattheriddleoftheBlackRiders
      As far as I know, MBR is not deprecated though it probably will be (same as X). I have used both in the past, but found MBR to be easier to set up and maintain for my purposes. I don't have any benefit from using GPT, so I don't see any point in using it.

    • @beat461
      @beat461 7 років тому

      You generally shouldn't install an MBR and use the CSM or BIOS way of booting if your motherboard has UEFI firmware, because an MBR partitioned disk has several disadvantages over a GPT partitioned disk:
      - gap between MBR and first partition is used to store the rest of the bootloader. There is no convention on where the first partition should start and so your bootloader can be overwritten by a windows update.
      - max 4 primary partitions
      - MBRs can only handle partition information of drives up to 2TB.
      - boot data is only saved on one place on the disk, there is no failsafe mechanism.
      - no cyclic redundancy check recovery in case of a corrupted partition table
      I suspect people who still use an mbr boot to often just be lazy and not wanting to learn about UEFI or even still have an irrational fear of microsoft and secureboot.

  • @smarcomputertech
    @smarcomputertech 7 років тому +1

    After encrypting your drive could you or would you be able to have it so if the password/passphrase was enter incorrectly say 5 times that the hdd was unusable or wiped clean??

    • @cldream
      @cldream 6 років тому +1

      Andrew Armstrong You can make a copy of the encrypt hook and modify it to do the wipe, and build it with your initrd.

  • @viiltelijamurhaaja7225
    @viiltelijamurhaaja7225 2 роки тому

    I like how you start reading how to do this after you turn on camera but cant type yes in capital letters.

  • @t33xbvz83
    @t33xbvz83 6 років тому

    How do you capture the screen of the X1 Carbon 3? At 1:45 you seem to connect something to the X1 Carbon? Maybe it's a HDMI/USB Video Capture Box. If so, which one do you recommend?

    • @kaihendry
      @kaihendry  6 років тому

      I recommend the Magewell natalian.org/2015/03/13/HDMI_in/

    • @t33xbvz83
      @t33xbvz83 6 років тому

      Thank you for your recommendation. You just exceeded 4000 subscribers btw.

  • @BuildFunThings
    @BuildFunThings 7 років тому +2

    Hi Kai, I am wondering; how do you record the screen from the other laptop?

    • @kaihendry
      @kaihendry  7 років тому +4

      With a Magewell XI100DUSB-HDMI & OBS!

  • @levchyk10
    @levchyk10 4 роки тому

    can you make video setting it all up with dracut using key to decrypt luks patition, please? following various tutorials but still can't make it work..

  • @juozasmiskinis3590
    @juozasmiskinis3590 6 років тому +1

    Thanks Kai! Thas was very useful.

    • @kaihendry
      @kaihendry  6 років тому

      You might also enjoy ua-cam.com/play/PLiKgVPlhUNuwCvU4LHf-9EYnvtlLbJe6p.html where I did the same

  • @1Schueni
    @1Schueni 6 років тому +1

    With Grub you could encrypt /boot as well

    • @kaihendry
      @kaihendry  6 років тому +1

      There is no point to encrypting /boot is there? You want complexity not to be in your boot loader. Grub is bloatware.

    • @1Schueni
      @1Schueni 6 років тому +1

      @@kaihendry A hacker could install a keylogger on the unencrypted /boot partition.

    • @kaihendry
      @kaihendry  6 років тому

      I have never thought of this tbh. So thanks for bringing it up. However the counterpoint that comes to mind, is that the hacker could also install a keylogger in Grub, no?

    • @kaihendry
      @kaihendry  6 років тому +1

      Oh look at this! www.phoronix.com/scan.php?page=news_item&px=systemd-cryptsetup-keydev

    • @1Schueni
      @1Schueni 6 років тому

      As far as I understand it, you still need a second device with systemd. With grub not necessarily.

  • @sofadhana1289
    @sofadhana1289 7 років тому

    Interesting - I've always read that you needed keyboard, encrypt, lvm2 BEFORE filesystems in the HOOKS section or you won't be able to type in a password.

  • @DietrichSchmitz
    @DietrichSchmitz 7 років тому +3

    Nice work.

  • @LundMr1
    @LundMr1 7 років тому

    Another great video :) Thanks. Please make a short video about setting up VPN on arch linux

  • @TheRangeControl
    @TheRangeControl 4 роки тому

    Will anyone teach us how to do this stuff on old versions of Macbook pro?

  • @jamiemeadowcroft6744
    @jamiemeadowcroft6744 6 років тому

    can the same principles be applied to other versions of linux like ubuntu? id prefer that to archlinux

  • @EgeKorkan
    @EgeKorkan 6 років тому

    I just want to understand something. In your HOOKS, you put encrypt after filesystems but for me it didnt work like that and after looking at the wiki I put it after and it worked. Do you know how it worked for you?

    • @kaihendry
      @kaihendry  6 років тому

      I ran into an ordering issue in my later videos on other machines. I don't know exactly what went wrong. Wish ordering was not an issue. I use sd-encrypt in my hooks now.

  • @knowledgemania1282
    @knowledgemania1282 3 роки тому

    How to encrypt Boot home partition without format ?

    • @kaihendry
      @kaihendry  3 роки тому

      encrypting the boot partition doesn't make sense to me

    • @knowledgemania1282
      @knowledgemania1282 3 роки тому

      @@kaihendry one more question , if we are encryption new partition then where password or hash save into our system? If we not save any password in system then ?

    • @kaihendry
      @kaihendry  3 роки тому

      @@knowledgemania1282 perhaps you should read how LUKS works

  • @CodeCristo
    @CodeCristo 6 років тому +4

    THE WIKI IS THE BEST MANUAL

  • @andriyrudyk8116
    @andriyrudyk8116 5 років тому +2

    Don't forget to gen fstab and change root password.

  • @MistahBushido
    @MistahBushido 7 років тому

    this video was quite helpful

  • @HarinderSingh-od9db
    @HarinderSingh-od9db 5 років тому

    Please help me I have please unlock disk sda3_crypt

  • @haxhxm841
    @haxhxm841 6 років тому

    finally after couple of hours i got how this works

  • @pieterwillembotha6719
    @pieterwillembotha6719 5 років тому +2

    theft-proof laptop? Not unless someone physically takes it.
    hehe

  • @ajones719
    @ajones719 6 років тому

    Im a noob to linux, but im doing some research for hard drive encryption on several operating systems, is this a good option for linux?

    • @kaihendry
      @kaihendry  6 років тому +1

      Not sure what you're asking. Are you saying whether to trust hardware encryption? I wouldn't.

    • @ajones719
      @ajones719 6 років тому

      i would like to know if its a good alternative to VeraCrypt, also as much as i dont like it, it is becoming a company policy to include full-disk encryption to all machines.

    • @kaihendry
      @kaihendry  6 років тому +1

      I trust Luks a little more than VeraCrypt/Truecrypt. Nonetheless it's decision _you_ need to make.

  • @atomicorang
    @atomicorang 6 років тому

    Kai help me please..all I want to do is install linux in my drive..,not using virtual machine..on T430..i am so illiterate it's not funny

    • @kaihendry
      @kaihendry  6 років тому

      Perhaps become literate first before considering a developer's paradise?

  • @probe2k
    @probe2k 5 років тому +2

    At 3:20, I thought the video paused...

  • @ayan2728
    @ayan2728 3 роки тому

    sorry, i detented my older comment. but maybe cab you mske tike this but wuth swap. because it's very handy to hibernate

    • @kaihendry
      @kaihendry  3 роки тому

      My machine hibernates without a swap partition

  • @unfa00
    @unfa00 4 роки тому

    I would personally appreciate a more to-the-point edit for this video. Watching you look up the web isn't particularly interesting. cut to the chase, please! :)

  • @francissicnarf4707
    @francissicnarf4707 6 років тому

    3:17 LOL who doesn't google to do this?

  • @IhsanAkbarNavzr
    @IhsanAkbarNavzr 7 років тому

    I have one question.... What did u drink?

  • @FrancoisCelliers
    @FrancoisCelliers 5 років тому

    Dude clean your desk

  • @BurhanDanger
    @BurhanDanger 7 років тому

    You're not confident here like your previous arch install video. Everything gave you hard time here. Nevertheless enjoyable.

  • @ifae7dieruazahCi
    @ifae7dieruazahCi 5 років тому

    you fogot genfstab step)

  • @markda12
    @markda12 4 роки тому +1

    So much potential here. Crappy instruction. I’m out.

    • @kaihendry
      @kaihendry  4 роки тому

      Nice Apple avatar. Perhaps you’re better off saving up for Apple?

    • @markda12
      @markda12 4 роки тому

      ​@@kaihendry Don’t take criticism well do you Kai? Poor guy.

  • @azimuth73
    @azimuth73 7 років тому

    ...or you can use the antergos installer ;-)
    (or the newmanjaro architect iso)

    • @kaihendry
      @kaihendry  7 років тому

      Oh, they support encrypted installs? sd-encrypt ?

    • @azimuth73
      @azimuth73 7 років тому

      Kai Hendry yes. I myself installed manjaro openrc with encrypted partitions on nvme ssd drive.
      it is still interesting to know the steps to do that anyway (sometimes the installer fails ;-)

    • @azimuth73
      @azimuth73 7 років тому

      As you might understood I am not a big fan of systemd ;-)

    • @kaihendry
      @kaihendry  7 років тому +1

      +Nadir Boussoukaia I'm cool with healthy resistance, though I've had a good UX