anyway, new old laptop is here, time to install linux onto it

does anyone have any suggestions for another distro i should try, or should i just continue using void?

(nix and guix are banned on my machines, with strong prejudice)

apparently the most difficult part is telling ubuntu to *not* autosuspend the machine to do the measurement. which has to be done with 3 separate config options in the settings

tbh, wish i could do a proper self-enrolled encrypted-drive-plus-secure-boot thing, but then id have to deal with UEFI, the TPM, making sure everything properly reenrolls again whenever a grub/kernel update happens, and more bullshit. plus the UEFI is probably vulnerable anyway

feels like just putting the luks header on a separate drive i carry with me at all times is a better idea

hm actually, this laptop has a smartcard reader

.... can i use that to encrypt/decrypt the luks header?

apparently you can use FIDO2 for this, but that needs systemd

.... is there an edition of void linux out there with systemd, then?

Sign in to participate in the conversation
Pixietown

Small server part of the pixie.town infrastructure. Registration is closed.