I use QubesOS, Veracrypt, LUKS, Protonmail, Yubikey, Keypass and many such things. In case I die first, my wife would have a hard time to access all this.
Now my idea is to keep a second Thinkpad ready, without internet connection, with a LUKS encrypted disk, with a Linux OS, and all the files unencrypted. On there would be a Guide how to open my GrapheneOS phone, how to access my email, etc.
Does this sound like a good idea?
The Linux Distro would have to be secure, easy to use, and without unneccessary things. Which one would you recommend?
My wife has no notebook. She uses an iPad. So where does she plug in the tails usb-drive? She cannot plug it in my notebook because the BIOS is password protected and boots only the internal drive with QubesOS.
I’ve already bought a small notebook that does not use too much space in the vault.
Now I’m looking for a secure OS with no unneccessary software on it and a simple GUI.
With “secure” I mean noone can access the files without the password for fde (luks). I hope Luks is secure…
I’m not an infosec expert, but it sounds to me like your concern is really just FDE. You don’t need a “secure” operating system if your Thinkpad is physically air-gapped/offline. As for “easy to use”, you and your partner will just have to look around the distro market and actively test which is more intuitive and easy for you guys. Try taking this quiz to see which one to start off with. As for “unnecessary things” (or bloat?), I’d just say to uninstall whatever you want. It’s a non-issue.