Hacker News new | ask | show | jobs
by dbtx 2362 days ago
If your /boot is on a USB drive and you set up with detached header then the disk can already be 100% random data. On the down side, that USB drive is not very deniable and the system can't be set to destroy it since you probably don't keep it connected. Still, you could boot the machine at home, put it to sleep, leave /boot at home, and wake it up whenever you've reattached this kill cord. If you absolutely need to be able to reboot, use kexec (in theory).