Avoid using weak encryption.
Goodbye keyboards and monitors!
So easy!
We encrypt a user home directory with eCryptfs. The consequence is that the contents of this directory are only accessible if at least one of the following is true:
Put that second drive to use!
To make it even harder for predatory institutions to find your keys.
Use autossh and a systemd service…
So easy!
LUKS partitions cannot be recovered once the header is lost.
No need to enable full login shell if the only intended usage is proxying.