Encrypting my hard drive requires a password at boot, which meant physically plugging in a keyboard until I could figure out how to decrypt using a USB drive instead. For a device that can easily be forgotten in public and one whose back can be easily taken off, I’m willing to deal with this slight inconvenience for encryption, but it’s one Android doesn’t require.
This is an issue I run into running a headless Linux computer as well. On macOS I’m never running headless, so never ran into this issue. But needing to enter a password before the OS boots is a decision that makes Linux kind of awkward to use disk encryption with.
And I’m almost certainly doing it wrong, so would appreciate being nudged in the right direction.
I’ve seen a post about storing the encryption keys in TPM, but others say then you can lose your keys if the mobo dies. I’ve heard you can use ssh keys, but I’m not sure how — and here that would require a second device to unlock your tablet.
macOS uses a read only OS partition to boot and then encrypts your user data partition, can I do that with Linux?