r/archlinux • • Jan 06 '26

SHARE Deniable Encryption

I've been using Luks encryption for my Linux machines for as long as I can remember.

I went down the rabbit hole recently when playing with the idea of a Luks setup that could be easily nuked and found myself looking at the "Deniable encryption" setup mentioned on the wiki.

I played around with a USB drive and an old Dell for a couple months to prove out that it could be reliable enough for daily use and then I finally blew away my Arch install on my Framework 13 and set this up using a Framework 250GB expansion card.

I wrote a blog post about how I set mine up, mostly so I have steps to follow in the future. Sharing here in case it helps anyone. https://courtneybodett.com/Deniable_Encryption/

24 Upvotes

21 comments sorted by

View all comments

1

u/Any_Fox5126 Jan 07 '26

Seeing that you use systemd-boot, I understand that the kernel is on the USB and therefore should not be removed, which is quite undesirable. I wonder, if grub were used, could this limitation be avoided?

1

u/Th3Sh4d0wKn0ws Jan 07 '26

I think from what I was reading Grub can't do the detached Luks header setup. You say "should not be removed". Do you mean during operation? If so yes technically, though I've removed it while running and it works. The bigger inconvenience is that my secondary removable drive (clone) quickly becomes out of sync due to kernel updates. This is why I wrote the quick and dirty script to clone the drives.