systemd 247 changes

systemd 247 includes interesting features like creating LUKS encrypted home dirs and an option to ignore the hw RNG input. These are worth looking at for both Whonix and the baremetal equivalent.

1 Like

Interesting. But noting actionable yet.

systemd-homed seems cool.

Reinventing Home Directories - media.ccc.de

But no compelling argument yet. Debian might go for it or it might stay as is.

Whonix current implementation using pam_mkhomedir is very stable.

https://forums.whonix.org/search?q=pam_mkhomedir

LUKS encrypted home dir isn’t crucially important as Full Disk Encryption (FDE) covers that anyhow.

People who just want to outsource their home folder to use it on USB to then use it on different systems, well, I don’t think that’s a realistic use case. In that case, users would be better off installing their whole operating system on USB as per Installation of Whonix on a USB.

  • Setting the SYSTEMD_RDRAND=0 environment variable will now disable RdRand CPU instruction usage even with supported CPUs.

Won’t be needed since we have: