Full disk encryption (including /boot) Luks2+argon2id

No custom packages needed …

That is because it is not for the faint of heart - beware of the :dragon: …

I have created a proof-of-concept - it is a manual process - but it is doable - you cannot use any kind of dual-boot - of course you can skip the use of Secure Boot - but I’d recommend creating your own signed loader and apply the key to the firmware - after you have verified it works - lock the firmware with a supervisor password.

1 Like