| ▲ | drdexebtjl 9 hours ago | |
You can store the key in the TPM. If someone steals the NAS, they can only decrypt it if they continue running the exact same software, which you harden (e.g. disable password login from the TTY). Or you can SSH in and type the key once per reboot. | ||