This document is intended to help others achieve a fully encrypted platform, with lowered attack surface for at-rest data. The following text is designed and tailored for the Framework laptop, but should be applicable to most platforms. We will not be covering nested decryption nor the security implications of using TRIM/Discard
, there are numerous documents that cover this thuroughly.
You should be comfortable with filesystem and storage management.
- General understanding of the Linux commandline interface.
- General understanding of LUKS and LVM partitioning.