0x8F9A2B44C1

Military-grade cryptography, hardware-bound trust anchors, and immutable storage. When you lock Alfred Linux, it stays locked against state-level adversaries.

1E4A 9C8B 44F1 00A1

LUKS2 Full Disk Encryption using AES-XTS with a 512-bit key. Every single sector of your drive is scrambled. Without the master key, the data is mathematically indistinguishable from random noise.

LUKS2 / Argon2id
Volume: /dev/nvme0n1p3 Cipher: aes-xts-plain64 Key Slot 0: Argon2id Iterations: 4,194,304 Memory: 1,048,576 KB Status: [ LOCKED ]

88B1 C99F 0A22 BB14

The decryption keys are sealed inside the Trusted Platform Module (TPM) on your motherboard. The TPM measures the UEFI firmware, bootloader, and kernel. If an attacker modifies a single byte of your boot chain (Evil Maid attack), the TPM refuses to release the keys.

PCR [0, 2, 4, 7, 8, 9]
Measuring Platform Configuration Registers... PCR-00: SHA256: 3a9b4... (Core Root of Trust) PCR-04: SHA256: 8f1c2... (Boot Manager) PCR-07: SHA256: e99a0... (Secure Boot State) PCR State matches baseline. Releasing LUKS2 Volume Key: [ AUTHORIZED ]

ZFS-POOL-CRYPT-001

AlfredOS stores your data on ZFS with native encryption and aggressive snapshotting. If ransomware encrypts your live files, you simply rollback to a read-only snapshot taken 15 minutes prior. The data is immutable.

Copy-On-Write / Snapshots
NAME USED AVAIL REFER MOUNTPOINT zroot/ROOT/default 14.2G 830G 14.2G / zroot/home/gositeme 45.1G 830G 45.1G /home/gositeme Latest Immutable Snapshots: zroot/home@auto-15m-ago READ-ONLY zroot/home@auto-30m-ago READ-ONLY zroot/home@auto-1h-ago READ-ONLY