I recently switched to Linux (Zorin OS) and I selected “use ZFS and encrypt” during installation. Now before I can log in it asks me “please unlock disk keystore-rpool” and I have to type in the encryption password it before I’m able to get to the login screen.

Is there a way to do this automatically like with Windows or MacOS? Zorin has biometric login which is nice but this defeats the purpose especially because the encryption password is long and tedious to type in.

Also might TPM have anything to do with this?

EDIT: Based on the responses I have to assume some of you guys live in windowless underground bunkers sealed off with concrete because door locks “aren’t secure against battering rams”. Normal people don’t need perfect encryption they just want to add an extra hurdle or two for the crackhead who steals the PC. I assumed Linux had a system similar to what Windows or MacOS has been doing for a decade but I am apparently wrong.

  • Skull giver@popplesburger.hilciferous.nl
    link
    fedilink
    arrow-up
    1
    ·
    4 months ago

    Windows can use biometrics to unlock the TPM and authenticate the user with just one single fingerprint touch. Authentication platforms like Windows Hello use the TPM to authenticate the user, which means the TPM PIN can be used both as a “password” and as the unlock mechanism for Bitlocker disks.

    I’m not aware of any Linux solution that will let you unlock the TPM with biometrics.

    I should also add that last time I read about this system in Windows, someone checked three laptops and found three different ways in which an attacker could trick the biometrics into adding extra fingerprints, including the official Microsoft hardware.

    Good enough for crackheads stealing the laptop and not having them be able to access your dick pics, not good enough for someone actually after your data.