|
|
|
|
|
by KennyBlanken
1690 days ago
|
|
Not ExaMesh, but there are a variety of ways to encrypt the card and remotely unlock it. You can use dropbear to ssh into the Pi and provide the key during boot. You can have the Pi connect to a remote system to retrieve the key. Some methods are obviously not perfect, but it'll definitely make it more complicated than just "copy the card." Remote key retrieval would let you audit when the system was booted and so on. There's a more complex purpose-built open source software package specifically for handling remote disk unlocks but I'm blanking on the name and my google searches aren't turning it up. I vaguely recall it had fairly high levels of paranoia in its design. |
|