Is Ecryptfs "reasonably" safe for the average user?

Just a thought with eCryptfs - as it's a laptop, it could take a criminal just a few minutes to boot a live session, plant a few files and put it back into the bag ready for the unsuspecting owner. :smiling_imp:

Even though the /home data may be "safe" and scrambled at rest , the remainder of the file system is exposed for tampering with who knows what - a keylogger, a hidden script or software modifications. That's just ready for a compromised system after you've logged in! :unlock: It's very unlikely of course, especially in a restaurant, but there could be someone with shifty eyes leaving USB drives on the ground... :slight_smile: As they say, a chain is only as strong as its weakest link.

So, to directly answer the topic's question - no, use full disk encryption during installation (powered by LUKS) for a secure system. Things only get a little tricky if you want to change the partition layout later, but the same could be said for any encrypted partition (e.g. Bitlocker on Windows)

1 Like