DEV Community

Cover image for How to setup Full Disk Encryption on a secondary HDD in Linux

How to setup Full Disk Encryption on a secondary HDD in Linux

Víctor Adrián on January 25, 2018

Let’s say that you get a brand new 2TB/4TB/8TB/XXTB HDD, and you want to use it as a safe backup device. That means you want to encrypt everything ...
Collapse
 
dsanchezseco profile image
dsanchezseco

For security it's better to write the disk with /dev/urandom as with zeroing it can be recoverable, at least HDDs in which the bit retains partially the orientation.

Collapse
 
lobo_tuerto profile image
Víctor Adrián

You are right, but I wanted to provide a compromise between security and time spent formatting the drive.

You can use /dev/urandom but need to be prepared to spent ~3 days waiting for the drive to be filled with random bits.

Collapse
 
dsanchezseco profile image
dsanchezseco

That's true, but its always worthy leaving a brick when resigning hahahahaha

Collapse
 
iridakos profile image
Lazarus Lazaridis

Very useful, thanks!

Collapse
 
jochemstoel profile image
Jochem Stoel

A little off topic, I know but how did you set a fb:image meta for your post?

Collapse
 
lobo_tuerto profile image
Víctor Adrián

Er... I don't know? I just uploaded it and then set it as cover_image in the front matter list for this article.

Does that answer your question?

Collapse
 
jochemstoel profile image
Jochem Stoel

It actually does, thank you. I was unaware of this variable.

Thread Thread
 
lobo_tuerto profile image
Víctor Adrián

No problem, glad to be of help! :)

Collapse
 
cannuhlar profile image
Can Nuhlar

Any tips on choosing a secure passphrase?

Collapse
 
lobo_tuerto profile image
Víctor Adrián

Yes, of course, there is a XKCD for that!

xkcd.com/936/

Basically, don't trouble yourself with something hard to remember like this:

tH15-iz_my_pa55phras0rz

You should pick something easy to remember with multiple words like:

hey, you won't be able to guess this one even if you try, don't you agree?

... or something like that. :)