You do not need the CPU, just its serial number (or the MAC
address of the network card) - and you can easily write that on a piece of
paper and put it in a secure location - or store this information in your office
on an encrypted disk.
hmm, yep this could be a problem, if the CPU got burnt for
example!
On Jan 19, 2008 2:26 PM, John Summerfield <
debian@herakles.homelinux.org
> wrote:
Ahmed Kamal wrote:
> Seems like I could use dm-crypt
to do full disk encryption, with some
> hardware parameter (MAC, CPU
s/n ... ) as the decryption key. That would
> prevent someone from
mounting the disk, or even dd'ing it to a different
> machine. That's
about exactly what I need.
> Not sure if dm-crypt supports getting
decryption keys from hardware params
> though
...
>
Be sure you can read the disk should you need.
You
cannot reply off-list:-)