• 0 Posts
  • 4 Comments
Joined 7 months ago
cake
Cake day: September 23rd, 2025

help-circle

  • Yes. Just encrypt /home partition only

    This is dangerous. As some data like cache and logs are stored in the root partition. So some of your data from home partition might trickle up the root partition in that form.

    why encrypt it in the first place?

    My threat model doesn’t include someone gaining direct access to my home desktop. I have Arch Linux with Secure Boot and TPM 2.0 enabled on fully encrypted drive and this chain’s existence makes it easier to know that no one has tampered with my system. On my laptop I am one step further with requirement of BIOS password.