Vertex ๐Ÿ”ž

839 Followers
889 Following
2.5K Posts

V.23 | it/its | demi | machine | no minors! ๐Ÿ”ž

British-Australian ๐Ÿ‡ฌ๐Ÿ‡ง๐Ÿ‡ฆ๐Ÿ‡บ living in London!
Systems Engineer, worldbuilder & writer

all NSFW posts will have a content warning

Pronounsit/its
GenderMachine
Matrix@vertex:glassway.net
why do we say eleven, twelve, thirteen, fourteen, etc instead of tenty-one, tenty-two, tenty-three, tenty-four :3
why do vendors get my money instantly but it always takes 14 business days or whatever for them to process refunds. shouldnโ€™t we be able to do better than this in 2026??
how many of these ingots do you know :P
a rock is the most secure object in the universe. you cannot hack it, it has zero points of failure, truly perfect supply chain security, the firmware is always up to date, it is beyond IP69 rated and fully hermetically sealed, and fully TEMPEST, SDIP-27, NIAP, and Common Criteria EAL7+ compliant, it tolerates all forms of electromagnetic interference including EMPs, and itโ€™s fully radiation hardened
NASA's Artemis II Crew Launches To The Moon (Official Broadcast)

YouTube
select your mood
eventually denuvo will probably require secure boot, tpm attestation, and VT-D to runโ€ฆ how long before we canโ€™t even attach debuggers to games anymore

Ok, I've done some research and I *think* I understand why

1. When the drive is locked the controller refuses to read or write to the locked regions, so it prevents attempts at forensic recovery of the LUKS ciphertext or the LUKS headers
2. It allows you to do a hardware crypto erase without the PSID
3. FIPS compliance or something, I guess?

1 is *incredibly* paranoid and 2 is pretty much moot since LUKS erases its own headers anyway when doing a wipe, but I guess it might technically be more effective to do a lower level erase of the controller's keys as well. But yeah, mostly inconsequential

just found out cryptsetup has a mode to use both LUKS and OPAL at the same time. the release notes say:

โ€œTCG interface (SEDs - self-encrypting drives). Using hardware disk encryption is controversial as you must trust proprietary hardware. On the other side, using both software and hardware encryption layers increases the security margin by adding an additional layer of protection.โ€

โ€ฆwhich makes sense, but if you donโ€™t trust OPAL anyway, why have it as a point of failure? Itโ€™s true that it doesnโ€™t cost anything to turn it on because OPAL drives already encrypt everything transparently but it seems rather redundant if you already inherently trust LUKS. maybe someone else can weigh in here?

your vertex unit may be refueled with any of the following isotopes: cobalt-60. caesium-137. iodine-131. plutonium-239. lead-209.

*other isotopes may work, but it might bite you if it dislikes them