this post was submitted on 03 Oct 2026
53 points (100.0% liked)
askchapo
23329 readers
72 users here now
Ask Hexbear is the place to ask and answer ~~thought-provoking~~ questions.
Rules:
-
Posts must ask a question.
-
If the question asked is serious, answer seriously.
-
Questions where you want to learn more about socialism are allowed, but questions in bad faith are not.
-
Try !feedback@hexbear.net if you're having questions about regarding moderation, site policy, the site itself, development, volunteering or the mod team.
founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
If you're using full disk encryption in Linux, your Linux install should be safe from Windows reading it. Assuming there's no evil maid situation.
If you're not using full disk encryption, then Windows could read it.
In both situations it's possible (but unlikely) for Windows to damage the Linux install or the bootloader to prevent it from starting up. Just make sure you've got a good regular backup scheme.
Should I disconnect the Linux drive then? When I installed Linux I had my Windows drive completely taken out, then I moved the Linux drive on top of the boot list in the BIOS. I get a grub bootloader menu when I boot and I just pick which OS I want to boot into. AFAIK Windows has no idea it's even there though one time an update sneakily moved Windows back on top of the list which was easy to reverse.
The fact Windows pissed around with grub means having separate drives would be the safest option.
Windows didn't fuck with grub (as far as I know), the Windows drive just got shuffled to the top of the list in BIOS
Oh. Sorry for the misunderstanding then!
Physical disconnection is guaranteed safe but can be an annoyance to do regularly. Full disk encryption that requires a password on bootup and regular backups of important files should be fine.
True full disk encryption is not possible on the grand majority of computers and even for the few without extreme tinkering and modification. I would even argue calling it FDE is inherently misleading since the boot partition and kernel has to be unencrypted.
This is technically true which is why I mentioned evil maid attacks. But for most people who just want to prevent a normal Windows install from reading data from a normal Linux install, LUKS is good enough.