Post B7ljbvFPcsErgZ333Y by paul@notnull.space
 (DIR) More posts by paul@notnull.space
 (DIR) Post #B7ljbuSqXROHFwKGMC by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @adamsdesk @orbitalmartianNo LUKS?
       
 (DIR) Post #B7ljbufblzbBtWISFU by adamsdesk@polymaths.social
       0 likes, 0 repeats
       
       @rl_dane @orbitalmartian No
       
 (DIR) Post #B7ljbut4xuNGZIbDFI by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @adamsdesk @orbitalmartianThere's your (lack of) problem! 🤣In my experience, Arch (and derivatives) + grub + LUKS = spock_horta_PAINNNN.mp4
       
 (DIR) Post #B7ljbvFPcsErgZ333Y by paul@notnull.space
       0 likes, 0 repeats
       
       @rl_dane @adamsdesk @orbitalmartian still very strongly on the side of you don't need encryption on root. Have the stuff that matters on an encrypted mounted volume and prevent boot worries 🙂
       
 (DIR) Post #B7ljbvTEnTIWNRW5bc by kabel42@polymaths.social
       0 likes, 0 repeats
       
       @paul @rl_dane @adamsdesk @orbitalmartian encrypted root still gives you a bit of protection, e.g. it's harder to manipulate stuff but for most people that's very deep in the diminishing returns :)On my stationary PC i have a small encrypted file mounted as loopback device. The chance of an attacker getting at the data while the PC is off is pretty small.
       
 (DIR) Post #B7ljbvea7IN6wcp9Hs by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @kabel42 @paul @adamsdesk @orbitalmartianThe "Bad Maid Problem" is still an issue with encrypted /home or whatnot, but it's a personal choice how paranoid you wanna be. ;)
       
 (DIR) Post #B7ljbvtTDwHVgnn2Ui by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @paul @rl_dane @adamsdesk @orbitalmartian @kabel42 ah I’d rather have the assurance that /var/tmp and /var/log are also encrypted, as the latter can also collect PII by accident, so FDE except /boot is a bit easier on the mind(I am also putting dm-integrity below it these days, so…)(I will have to find replacements for that in NetBSD, amn’t I?)
       
 (DIR) Post #B7lkZ0NYBwEsgY1lnE by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @paul @adamsdesk @orbitalmartian @kabel42Yeah, AFAIK, you have to boot into a minimal unencrypted / and have it chroot from there, or something.https://www.dwarmstrong.org/netbsd-encrypt-install/OHAI, he's on fedi! @dwarmstrong thanks for the HOWTO. Looking forward to trying it out sometime soonish. ;)
       
 (DIR) Post #B7lkZ0hkyoOzhDTuHw by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @paul @kabel42 @rl_dane @adamsdesk @orbitalmartian yeah risky, but I meant dm-integrity
       
 (DIR) Post #B7lqkVAYeYiv5fod7I by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @paul @kabel42 @adamsdesk @orbitalmartianOh, ok. Not familiar with it.
       
 (DIR) Post #B7lqkVU3U4Js48wCVU by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @orbitalmartian @kabel42 @adamsdesk @rl_dane @paul it stores checksums, so a RAID 1 can detect silent corruption and become self-healing
       
 (DIR) Post #B7lylQCxNroLcst4iW by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @orbitalmartian @kabel42 @adamsdesk @paulAh, neat. Is there something like that in BSD? Wouldn't ZFS handle that?
       
 (DIR) Post #B7lylQRUVpRALxggN6 by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @adamsdesk @kabel42 @paul @rl_dane @orbitalmartian no idea, I don’t think NetBSD has ZFS
       
 (DIR) Post #B7lypeh9SndjiP1t9k by kabel42@polymaths.social
       0 likes, 0 repeats
       
       @rl_dane @mirabilos @orbitalmartian @adamsdesk @paul zfs should handle that for data corruption on disk, but i've been told it's super vulnerable to bitflips in its giant cache and "you need  real ECC RAM"
       
 (DIR) Post #B7lypeyWQDXCaH9lEO by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @kabel42 @adamsdesk @paul @orbitalmartian @rl_dane and insane amounts of it, yes
       
 (DIR) Post #B7lzZ7MNjb1heJzbeq by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @adamsdesk @kabel42 @paul @orbitalmartianSeems to?https://wiki.netbsd.org/zfs/P.S., if you drop a question with the NetBSD hashtag, someone helpful usually pops up. ;)
       
 (DIR) Post #B7lzZ7e6fhCkXIHlHk by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @adamsdesk @kabel42 @paul @orbitalmartian @rl_daneconsuming excessive amounts of memory on systems with less than about 8 GB, and systems of 4 GB and lower have been observed to lock upyeah, no.hashtagI’m not at a stage where I even could do anything useful with the information yet. I barely get dayjob stuff done atm, let alone anything else.Had to water the vegetable pots and beds last night, did it at heat minimum (just before sunup), still got a pulse of up to 168 in the 45-60 minutes it tool me…I’ll keep the bullseye systems for a while, and evaluate NetBSD for where I run Linux atm… sometime. Unless they also integrate slop. Then, it won’t matter and all will be lost.Shocking how the downfall of FOSS came so quickly and unexpectedly.
       
 (DIR) Post #B7m3DOtmFGWfUSVrvM by kabel42@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @adamsdesk @paul @orbitalmartian @rl_daneinsane amountswell, for a notebook half as old as I am, insane.for a NAS ca. 2019, way more reasonable :)
       
 (DIR) Post #B7m3DPQOI0c77blul6 by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @kabel42 @adamsdesk @paul @orbitalmartian @rl_dane nope.Small VMs is a use case. These often have barely 1 GiB RAM.
       
 (DIR) Post #B7m3sswXReyKXpaOJM by kabel42@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos I was thinking one of those small 4 bay NAS with that one atom that supports ECC for some reason. Those can usually be upgraded to 6-8 GiB of RAM@adamsdesk @paul @orbitalmartian @rl_dane
       
 (DIR) Post #B7m3stAiawJZFoDiPg by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @kabel42 @adamsdesk @paul @orbitalmartian @rl_dane I said above “everything I currently use Linux for”, which does include several small to very small VMs.
       
 (DIR) Post #B7o6Wtfik9Poc2qWqe by rl_dane@polymaths.social
       0 likes, 0 repeats
       
       @mirabilos @kabel42 @adamsdesk @paul @orbitalmartianI'm… not seeing the runaway RAM usage with zfs?$ ps wwaux |sort -nsk6 |cut -c 31-38,67-    RSS COMMAND     16 [busdma]     16 [rand_harvestq]     16 [g_eli[0] ada0p4]     16 [g_eli[1] ada0p4]     16 [audit]     16 [sequencer 00]     16 [acpi_thermal]     16 [g_eli[2] ada0p4]     16 [g_eli[3] ada0p4]     16 [vmdaemon]     16 [vnlru]     16 [syncer]     16 [g_eli[0] ada0p3]     16 [g_eli[1] ada0p3]     16 [g_eli[2] ada0p3]     16 [g_eli[3] ada0p3]     48 [cam]     48 [geom]     48 [pagedaemon]     64 [idle]     64 [clock]     64 [ng_queue]     80 [crypto]     80 [usb]     80 [bufdaemon]    208 [intr]    408 /sbin/init    896 [zfskern]   1760 adjkerntz -i   1824 /usr/sbin/powerd -a hiadaptive -b minimum -m 100 -N   1824 sleep 60   1840 /usr/local/bin/seatd -g video   1848 footclient -L   1856 footclient -L   1860 /usr/libexec/getty Pc ttyv2   1860 /usr/libexec/getty Pc ttyv3   1860 /usr/libexec/getty Pc ttyv5   1860 /usr/libexec/getty Pc ttyv6   1864 /usr/libexec/getty Pc ttyv4   1868 /usr/libexec/getty Pc ttyv1   1872 /usr/libexec/getty Pc ttyv7   1932 daemon: /usr/local/bin/seatd[7076] (daemon)   2068 /usr/sbin/cron -s   2092 /usr/sbin/moused -p /dev/psm0 -t auto   2128 ksh /home/rld/bin/fbsdstatus   2140 ksh /home/rld/bin/fbsdstatus   2188 sort -nsk6   2256 dhclient: system.syslog (dhclient)   2320 login [pam] (login)   2328 dhclient: wlan0 [priv] (dhclient)   2340 swayidle -w timeout 300 swaylock -Ffei ~/Pictures/backgrounds/earth.jpg --indicator-radius 75 timeout 310 swaymsg "output * dpms off" resume swaymsg "output * dpms on" timeout 360 ~/bin/suspend --battery-only   2344 /usr/sbin/syslogd -ss   2400 dhclient: wlan0 (dhclient)   2516 wlsunset -l 33 -L -97   2872 i3status -c /home/rld/.config/i3status/config   2896 ps wwaux   2924 dbus-launch --autolaunch 1623344c27d411b2a85cdc1c23bd6c8e --binary-syntax --close-stderr   2932 /usr/local/bin/dbus-daemon --config-file=/usr/local/share/defaults/at-spi2/accessibility.conf --nofork --print-address 14 --address=unix:path=/var/run/xdg/rld/at-spi/bus_0   3220 /usr/local/bin/dbus-daemon --syslog-only --fork --print-pid 5 --print-address 7 --session   3308 /sbin/devd   3608 bash /home/rld/bin/powertrack   6036 /usr/local/libexec/xdg-permission-store (xdg-permission-stor)   6464 sshd: /usr/sbin/sshd [listener] 0 of 10-100 startups (sshd)   6764 /usr/local/libexec/at-spi-bus-launcher   6900 /usr/local/libexec/at-spi2-registryd --use-gnome-session   7264 /usr/sbin/ntpd -p /var/db/ntp/ntpd.pid -c /etc/ntp.conf -f /var/db/ntp/ntpd.drift -g   7660 -/usr/local/bin/bash   7676 -/usr/local/bin/bash   7676 -/usr/local/bin/bash   7684 -/usr/local/bin/bash   8060 /usr/sbin/wpa_supplicant -s -B -i wlan0 -c /etc/wpa_supplicant.conf -D bsd -P /var/run/wpa_supplicant/wlan0.pid   9824 [kernel]  12652 /usr/local/libexec/xdg-desktop-portal  16868 syncthing --no-browser  23504 swaybar -b bar-0  31140 tut  40100 swaybg -o * -i /home/rld/Pictures/backgrounds/earth.jpg -m fill  64028 foot --server -c /home/rld/.config/foot/foot.ini  71892 swaync -c /dev/null  78804 Xwayland :0 -rootless -core -terminate 10 -listenfd 35 -listenfd 36 -displayfd 70 -wm 67  94912 sway -d 381076 /usr/local/bin/syncthing --no-browser
       
 (DIR) Post #B7o6Wu0zT4Qfg0nW08 by mirabilos@toot.mirbsd.org
       0 likes, 0 repeats
       
       @rl_dane @kabel42 @adamsdesk @paul @orbitalmartian ps shows userland processes, duh.Anyway, as I said, not going to invest time or mental capacity into that. It’s licenced weirdly anyway.