The State of Authenticated Boot and Disk Encryption on Generic Linux
0pointer.net
0pointer.net
Instead of leveraging the same system-wide disk encryption on the `/home` directory and instead, use a separate encryption volume for each user under its home directory?
This way, the choice is left to the user who can choose their own algorithm (as well as its own authenticator method) for an encryption of its own home directory; it still reap the benefit of not doing a double-encrypting;
Also in the case of hijacked key scenario, an integrity failure of a boot would not even attempt to compromise or access the user data (at '/home' data resting state).