Automated encrypted swapfiles
braxs.net
braxs.net
I agree with the sentiment to use swapfiles rather than swap partitions -- the flexibility is appealing (though in practice I rarely need to change the dimensions of mine) and the lack of measurable difference in performance over partitions removes any arguments in favour of dedicated partitions anymore.
But on my secure systems everything other than /boot is encrypted on, so I get encrypted swapfiles just by creating them as /swapfile.x -- I have a saltstack recipe that creates these on new installs automatically now, too, and that doesn't need to be changed for encrypted or non-encrypted root file systems.
The automatic creation of these (and decommissioning them later) based on ephemeral memory usage requirements is an interesting idea, and it's a shame the author hasn't gotten to that point yet. I wonder how useful that'd be in practice, though, especially in an era of 'disk is cheap'.
eswap /dev/mapper/vg0-swap /dev/urandom swap,cipher=aes-cbc-essiv:sha256
[1] http://www.freedesktop.org/software/systemd/man/crypttab.htm...I'm using this currently on my XPS 13 (2015). Works great. However given the architecture of SED and its implementation in this case, it's not as trustworthy as LUKS, for example.
For general laptop security not involving government intervention, I consider it good enough.
It's really just an 'in case of (casual) theft' level of encryption as far as I'm concerned. Good enough on the systems I'm using it on. For everything else, there's LUKS.