Email or username:

Password:

Forgot your password?
Alexandra Moved :antiverified:

Hello,

Like a good girl i do daily backup automatically (in a different drive), i also do a manual weekly backup on a SSD nvme m.2 Sandisk 1To.

Every disk where i save are encrypted with luks2.

There is the problem i do search cheap online backup services (must have support for Webauth (or u2f).

I also search a secure audited usb key with encryption (with keypad) (to store my SSD encryption key securely).

Thanks for any help.

#hardware #linux #encryption #security #opensource #backup

8 comments
Alexandra Moved :antiverified:

@edgren Thanks i will check on that (the online is for the "offsite") the usb key i ask is because i do host myself my password manager (vaultwarden) so i do need a secure way to store my encryption key (of my backup) and my id to access this offsite backup in case of total loss (all hardware).

Airikr :endeavourOS:

@somegirlprivacy Ok. Yeah, Duplicity[1] will encrypt all your data before sending it to Backblaze so your data will be stored secured πŸ™‚

[1]: duplicity.gitlab.io/

Joshua Lee :kde: :emacs:

@somegirlprivacy borgbase is the most reasonable service I found. It does require you use borgbackup which uses ssh for verification and backup.

𝓑𝓾𝓭𝓸𝓡𝓯 πŸ‡ΊπŸ‡¦ :unverified:

@somegirlprivacy
All USB keys I saw audited were easily broken.
I would use an enrcypted container on a normal key with truecrypt/veracrypt.
That can be read with linux/windows/android.

Alexandra Moved :antiverified:

@rudolf i mean it's more to have the feature of (10 pin fail = autoremove key) to protect the key from bruteforcing, like that i can use a luks2 (with a more easy password) on it.

𝓑𝓾𝓭𝓸𝓡𝓯 πŸ‡ΊπŸ‡¦ :unverified:

@somegirlprivacy
The ones I read about were broken by simple reverse engineering, not by brute force. A volume encrypted by Truecrypt/Veracrypt is much safer and can be read by almost any device.

Alexandra Moved :antiverified:

@rudolf i don't care about vera crypt, i will use luks who also have flawless security, the hardware security is AGAIN, to have the bruteforce protection out of the box, because only Governement have the power to do search to bypass them

Go Up