Replies (13)

timeseed.io another option for encrypting/decrypting messages and files without a third party in play. Might add Veracrypt works great on Linux too.
If Windows backdoors BitLocker, you can have no confidence of any encryption, open source or closed, unlocked with Windows as a host. Veracrypt encryption won't save you if private keys need to be loaded on a compromised Windows kernel. LUKS or Veracrypt on an open source Linux or BSD distro is the only way.
Correct. LUKS makes everything depend on the strength of the encryption password, as a good hardware wallet should do, and does not depend on untrusted hardware (TPM or Secure Element). That said, LUKS can be configured with TPM, but I strongly advise against it for this reason. "Kerckhoffs' cryptography principle (also called Kerckhoffs' desideratum, assumption, axiom, doctrine, or law) was stated by Dutch cryptographer Auguste Kerckhoffs in the 19th century. The principle states that a cryptosystem must be secure even if everything about the system, except the key, is public knowledge. This concept is widely adopted by cryptographers, in contrast to security through obscurity, which is not."
โ†‘