Ok, thinking about secure hibernation again. We can't rely on LUKS because we can't trust the initramfs, and someone could simply drop a LUKS swap partition on top of the existing one and resume from that. So we need this to be kernel mediated (ChromeOS doesn't have this restriction so has an easier job)

0

If you have a fediverse account, you can quote this note from your own instance. Search https://nondeterministic.computer/users/mjg59/statuses/115491928573781876 on your instance and quote it. (Note that quoting is not supported in Mastodon.)