Encrypted persistence partition configuration for a Kali Linux live USB
0 reputation · 12 Jul 2020, 11:18 UTC
Kali Linux's live USB persistence feature saves changes across reboots on a separate partition labeled persistence. The documented setup leaves encryption to the user: the partition can remain a plain ext4 filesystem unless a LUKS container is created manually, and the persistence mechanism does not enforce encryption by default in recent rolling releases.
The goal is a live USB where saved data — configurations, captured artifacts, stored credentials — survives reboots yet stays unreadable if the drive is plugged into another system. The uncertainty is where the encryption boundary sits: whether the live boot process unlocks a LUKS-formatted persistence partition at boot time, or whether an unencrypted partition is the only configuration the feature reliably supports.
- Is LUKS encryption of the persistence partition supported by Kali's live boot, and is it optional rather than enforced?
- What configuration ensures the persistence partition is only mounted after a passphrase is supplied?
- Does the official persistence documentation still treat encryption as a manual step in current rolling releases?