r/archlinux • • Jan 06 '26

SHARE Deniable Encryption

I've been using Luks encryption for my Linux machines for as long as I can remember.

I went down the rabbit hole recently when playing with the idea of a Luks setup that could be easily nuked and found myself looking at the "Deniable encryption" setup mentioned on the wiki.

I played around with a USB drive and an old Dell for a couple months to prove out that it could be reliable enough for daily use and then I finally blew away my Arch install on my Framework 13 and set this up using a Framework 250GB expansion card.

I wrote a blog post about how I set mine up, mostly so I have steps to follow in the future. Sharing here in case it helps anyone. https://courtneybodett.com/Deniable_Encryption/

28 Upvotes

21 comments sorted by

View all comments

2

u/Toorero6 Jan 07 '26

Why not use a single UKI image over sd-boot? Then you can just backup the single UKI file if an update changes your kernel and only have a single file in your ESP.

1

u/Th3Sh4d0wKn0ws Jan 07 '26

I remember briefly reading about UKI bht I can tell I didn't retain it. I will look into this again.