just found out cryptsetup has a mode to use both LUKS and OPAL at the same time. the release notes say:
“TCG interface (SEDs - self-encrypting drives). Using hardware disk encryption is controversial as you must trust proprietary hardware. On the other side, using both software and hardware encryption layers increases the security margin by adding an additional layer of protection.”
…which makes sense, but if you don’t trust OPAL anyway, why have it as a point of failure? It’s true that it doesn’t cost anything to turn it on because OPAL drives already encrypt everything transparently but it seems rather redundant if you already inherently trust LUKS. maybe someone else can weigh in here?


