From a2616e852ba1d861209f66ce4afc8728117a1acd Mon Sep 17 00:00:00 2001 From: Francis Rowe Date: Wed, 20 May 2015 05:25:31 -0400 Subject: docs/gnulinux/encrypted_*.html: Remove notes about --unrestricted These instructions were dangerous. I was provided with them by a user who found them, and I thought that it would be safe to allow access to boot the HDD so long as the OS was encrypted. However, this is not the point. With that option unrestricted, anyone with physical access could replace the HDD with another LUKS-encrypted one with the same set up (just a different system, different key, different passphrase, etc) and now they are able to run their own code on that laptop. This *is* dangerous. There is a lot that an attacker can do to the laptop if they are able to boot an OS on it! Basically, Francis Rowe was being foolish to add these instructions. Now he's wised up a bit. --- (limited to 'docs/gnulinux/grub_cbfs.html') -- cgit v0.9.1