<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Cumps · Geek.</title><link>/tags/security/</link><description>Recent content in Security on Cumps · Geek.</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright &amp;copy; 2026</copyright><lastBuildDate>Tue, 25 Aug 2026 10:00:00 +0200</lastBuildDate><atom:link href="/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>LUKS on Every Data Volume</title><link>/articles/2026-08-25-luks-everywhere/</link><pubDate>Tue, 25 Aug 2026 10:00:00 +0200</pubDate><guid>/articles/2026-08-25-luks-everywhere/</guid><description>&lt;p&gt;The threat model for a rented server is simple to state: my data sits on disks I will never see, in a data center I will never visit, handled by people I will never meet. Disks get decommissioned, snapshots get copied, hardware gets recycled. I can&amp;rsquo;t control any of that. What I can control is whether the bytes on those disks mean anything without a passphrase. &lt;a href="/articles/2026-08-18-secrets-in-git/"&gt;Last week&lt;/a&gt; covered the secrets that never leave the git repository; this week is about the disks those secrets unlock.&lt;/p&gt;</description></item><item><title>Secrets That Live in Git</title><link>/articles/2026-08-18-secrets-in-git/</link><pubDate>Tue, 18 Aug 2026 10:00:00 +0200</pubDate><guid>/articles/2026-08-18-secrets-in-git/</guid><description>&lt;p&gt;This is the first of the foundation retrospectives I promised in &lt;a href="/articles/2026-08-11-catching-up/"&gt;the catch-up post&lt;/a&gt;. We&amp;rsquo;re going back to December, before a single server existed, when the first real decision of the project wasn&amp;rsquo;t about compute or DNS. It was: where do the secrets live?&lt;/p&gt;</description></item></channel></rss>