logoalt Hacker News

codedokodetoday at 4:15 PM2 repliesview on HN

I am too lazy for that, and I hate that after boot you need to launch everything again.


Replies

IngoBlechschmidtoday at 4:28 PM

Suspend to (encrypted) swap might be a good middle ground between you and grandparent. Suspend to memory will (at best) protect your LUKS volume key, but other sensitive data remains.

A couple of years ago, three security researchers from the TU Munich implemented a prototype for also encrypting (most) parts of the memory just before suspend, to address this limitation; but as far as I know, it was not upstreamed or developed further: https://www.sec.in.tum.de/i20/publications/fridgelock-preven...

1718627440today at 4:21 PM

You can usually change that in the settings of the Desktop environment.

show 1 reply