alex_giusi_tiri has joined #nixos-aarch64
alunduil has quit [Ping timeout: 268 seconds]
alunduil has joined #nixos-aarch64
alunduil has quit [Max SendQ exceeded]
alunduil has joined #nixos-aarch64
alunduil has quit [Max SendQ exceeded]
alunduil has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Client Quit]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
st4ll1 has quit [Quit: ZNC 1.7.1 - https://znc.in]
st4ll1 has joined #nixos-aarch64
alex_giusi_tiri has left #nixos-aarch64 [#nixos-aarch64]
zupo has joined #nixos-aarch64
zupo has quit [Ping timeout: 264 seconds]
duncan^ has quit [Ping timeout: 252 seconds]
duncan^ has joined #nixos-aarch64
orivej has joined #nixos-aarch64
pxc has quit [Ping timeout: 240 seconds]
<mthst> is it possible to have full disk encryption on an RPi 3?
<sphalerite> mthst: depends on how full "full" is :)
<sphalerite> mthst: you can have a LUKSed root filesystem like on most devices, but I think /boot needs to be unencrypted
<sphalerite> that would be enough for your data not to be accessible if someone steals the pi or the SD card though.
<mthst> sphalerite: i disabled the use of the /boot partition as described here https://nixos.wiki/wiki/NixOS_on_ARM#Disable_use_of_.2Fboot_partition
<mthst> that would be good enough for me
<sphalerite> I don't know how to actually do this without an installer system booted though
<mthst> i don't understand
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej_ has joined #nixos-aarch64
orivej has quit [Ping timeout: 268 seconds]
orivej_ has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
<clever> mthst: such changes have to be done when the OS isnt booted, and you then run nixos-install
<clever> youll probably want a 2nd SD card in a usb reader, and install to that, then swap and boot
<mthst> clever: oh, got it.
<mthst> but according to wikipedia the RPi 3 can boot from usb
<duncan^> it needs something on sd card though I think?
<duncan^> to read the boot blob for the video or something is what I recall
<mthst> video??
zupo has joined #nixos-aarch64
<sphalerite> because the raspi has a really weird architecture where the GPU brings up the CPU rather than the other way round
<sphalerite> iirc
<sphalerite> clever knows these things
<mthst> oh, yes i've read this somewhere
<mthst> you can boot to usb without an sd card
<mthst> but you have to "set the usb boot bit in one-time programmable memory"
<mthst> first
<clever> yep
<mthst> how do you do it on NixOS?
<clever> same as every other distro
<clever> set a field in config.txt and reboot
<mthst> who reads the config.txt?
<mthst> and when?
<clever> the gpu firmware, as it boots
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
<mthst> i can't change it back if i set the bit, right? are there any drawbacks?
<clever> i think it also enables netboot
zupo has joined #nixos-aarch64
<clever> if an attacker is on your ethernet he could boot his own thing on the pi, if the sd and usb is missing
<mthst> i see
<mthst> can nixos-install to an iso?
<mthst> and then i can dd it back to the sd
<clever> not sure
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
<mthst> what about https://nixos.wiki/wiki/ARM#Build_your_own_image would that work?
zupo has joined #nixos-aarch64
Thra11 has joined #nixos-aarch64
zupo_ has joined #nixos-aarch64
zupo has quit [Ping timeout: 264 seconds]
zupo_ has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
Thra11 has quit [Ping timeout: 250 seconds]
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Remote host closed the connection]
orivej has joined #nixos-aarch64
zupo has joined #nixos-aarch64
pxc has joined #nixos-aarch64
pxc has quit [Ping timeout: 250 seconds]
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
orivej has quit [Quit: No Ping reply in 180 seconds.]
orivej has joined #nixos-aarch64
pxc has joined #nixos-aarch64
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]
zupo has joined #nixos-aarch64
pxc has quit [Ping timeout: 250 seconds]
pxc has joined #nixos-aarch64
zupo has quit [Quit: My MacBook has gone to sleep. ZZZzzz…]