alex_giusi_tiri has joined #nixos-aarch64
alunduil has quit [Ping timeout: 268 seconds]
alunduil has joined #nixos-aarch64
alunduil has quit [Max SendQ exceeded]
alunduil has joined #nixos-aarch64
alunduil has quit [Max SendQ exceeded]
alunduil has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Client Quit]
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
st4ll1 has joined #nixos-aarch64
alex_giusi_tiri has left #nixos-aarch64 [#nixos-aarch64]
zupo has joined #nixos-aarch64
zupo has quit [Ping timeout: 264 seconds]
duncan^ has quit [Ping timeout: 252 seconds]
duncan^ has joined #nixos-aarch64
orivej has joined #nixos-aarch64
pxc has quit [Ping timeout: 240 seconds]
<
mthst>
is it possible to have full disk encryption on an RPi 3?
<
sphalerite>
mthst: depends on how full "full" is :)
<
sphalerite>
mthst: you can have a LUKSed root filesystem like on most devices, but I think /boot needs to be unencrypted
<
sphalerite>
that would be enough for your data not to be accessible if someone steals the pi or the SD card though.
<
mthst>
that would be good enough for me
<
sphalerite>
I don't know how to actually do this without an installer system booted though
<
mthst>
i don't understand
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej_ has joined #nixos-aarch64
orivej has quit [Ping timeout: 268 seconds]
orivej_ has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
<
clever>
mthst: such changes have to be done when the OS isnt booted, and you then run nixos-install
<
clever>
youll probably want a 2nd SD card in a usb reader, and install to that, then swap and boot
<
mthst>
clever: oh, got it.
<
mthst>
but according to wikipedia the RPi 3 can boot from usb
<
duncan^>
it needs something on sd card though I think?
<
duncan^>
to read the boot blob for the video or something is what I recall
zupo has joined #nixos-aarch64
<
sphalerite>
because the raspi has a really weird architecture where the GPU brings up the CPU rather than the other way round
<
sphalerite>
clever knows these things
<
mthst>
oh, yes i've read this somewhere
<
mthst>
you can boot to usb without an sd card
<
mthst>
but you have to "set the usb boot bit in one-time programmable memory"
<
mthst>
how do you do it on NixOS?
<
clever>
same as every other distro
<
clever>
set a field in config.txt and reboot
<
mthst>
who reads the config.txt?
<
clever>
the gpu firmware, as it boots
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
<
mthst>
i can't change it back if i set the bit, right? are there any drawbacks?
<
clever>
i think it also enables netboot
zupo has joined #nixos-aarch64
<
clever>
if an attacker is on your ethernet he could boot his own thing on the pi, if the sd and usb is missing
<
mthst>
can nixos-install to an iso?
<
mthst>
and then i can dd it back to the sd
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
zupo has joined #nixos-aarch64
Thra11 has joined #nixos-aarch64
zupo_ has joined #nixos-aarch64
zupo has quit [Ping timeout: 264 seconds]
zupo_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
Thra11 has quit [Ping timeout: 250 seconds]
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Remote host closed the connection]
orivej has joined #nixos-aarch64
zupo has joined #nixos-aarch64
pxc has joined #nixos-aarch64
pxc has quit [Ping timeout: 250 seconds]
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
pxc has joined #nixos-aarch64
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
zupo has joined #nixos-aarch64
pxc has quit [Ping timeout: 250 seconds]
pxc has joined #nixos-aarch64
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]