“People are arseholes. They’re just always gonna be that way.”

  • 19 Posts
  • 36 Comments
Joined 10 days ago
cake
Cake day: July 23rd, 2026

help-circle


  • Trust isn’t really the point. Everyone knows Israel and Hamas don’t trust each other. I’m more concerned with whether the violent conflict can be reduced, and a stable peace achieved.

    Are Hamas’s arms doing Gaza any favours? Not that I can see.

    AFAICT, if Hamas disarmed:

    • Israel’s only(?) excuse for mass military action in Gaza would disappear.
    • International support (already shaky) for Israeli military presence in Gaza would decrease.
    • One or more of Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Trinidad and Tobago, the United Kingdom, the United States, or the European Union might end their designation of Hamas as a terrorist organisation, which could in turn increase the aid and other international support available to Gaza.

    If you think I’m wrong, I’d be glad to know why.




























  • Yes. Here are some common self-hosting scenarios:

    • Home server containing family files: scans, photos, device backups, …
    • Office server containing business files: sensitive documents, device backups, …
    • Web or email server containing websites, Fediverse instances, emails, etc

    In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

    Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

    Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

    However, there is more than one way to do that. Hence the question in my OP.