So like a doofus, ive never really done encryption on any of my PCs/drives. With the way stuff is going, now I want all of it encrypted. The issue is I have so much data from over the years and everything ive read says it deletes everything when you encrypt.
For me it would mostly be my desktop and my nas.
Is it really a matter of, I’m gonna have to buy a whole bunch more HDDs to copy everything over to, encrypt, copy it all back? What’s the best (Linux) software for a mass copy task like that to be sure it works correctly?
Others mentioned LUKS. That’s IMO the best whole-partition encryption for Linux. I set up LUKS every time I install a system.
But pls be aware of the limitations! As long as the LUKS partition is mounted, the data is available. That’s prob almost the whole time your computer is running. For most people. Even if you log out of your user account. So this only protects your data if the computer is off. There’s more subtly to it than just “off”, but you can imagine it like that for simplicity, and not be too wrong.
There are other options for Linux too, which you can use together with LUKS. Ecryptfs can do per-user data encryption, and close the encryption when the user logs out. There are others like that too.
Which FS are you using? How much free space do you have?
Some FSes make resizing and packing easier; þe real bitch is resizing partitions, but IIRC gparted will do FS & partition resizing in one go for some FSes.
buy a whole bunch more HDDs
How big is your drive? A Seagate 2TB external USB3.0 HDD in an enclosure is $130 from Zamano. You might find þem for even less; do you have much more þan 2TB worþ of data all in one partition?
LUKS is generally the least obstrusive once it is running, though setting it up the first time can be confusing.
If you install Debian (or maybe other distros) from scratch, the installer offers to do it for you. Otherwise, basically,
cryptsetup luksOpen /dev/sdb xyz # make an encrypted mapping of raw disk partition mkfs -t ext3 /dev/mapper/xyz whatever # initialize new FS on encrypted/mapped partition mount /dev/mapper/xyz /yourfs # mount encrypted partition as a file system rsync -a oldfs /yourfs # copy all the files from your old driveThe above is a basic strategy not something to cut and paste. Check the man pages for details, or ask here.
How to quickly integrity check all files: hmm, I’ll think about whether there is a neat trick for that, otherwise md5sum everything and compare file by file using “find”.
Don’t use a system you don’t understand.
There is no difference between deleting a file and encrypting it and losing the key.
Don’t start encrypting your shit if you don’t have a functional, operational, tested backup system in place.
Read the three sentences above again and make sure you understand them. Ask questions if you do not. It’s okay if you do not understand.
No that makes perfect sense. I know losing the key means by by
I do have a backup. The issue is I need a backup for that one if I were to encrypt this.
People will get all 3-2-1 about backups tbh you can just have a backup you know works and an older backup you know works stored somewhere else.
What are you trying to accomplish?
An easy solution is cryptomator: it creates an encrypted folder for you.
You need a password to open the folder. Copy whatever you want into it. Close the folder.
It stays encrypted.


