If I die first... Widow Notebook

I use QubesOS, Veracrypt, LUKS, Protonmail, Yubikey, Keypass and many such things. In case I die first, my wife would have a hard time to access all this.

Now my idea is to keep a second Thinkpad ready, without internet connection, with a LUKS encrypted disk, with a Linux OS, and all the files unencrypted. On there would be a Guide how to open my GrapheneOS phone, how to access my email, etc.

Does this sound like a good idea?

The Linux Distro would have to be secure, easy to use, and without unneccessary things. Which one would you recommend?

I think that’s exactly one of the use cases Ente locker was built for, so you could give it a try.

Thank you. I’d like to keep it offline. A small notebook in our vault at the local bank was the idea.

TailsOS with persistent storage on a thumbdrive?

No privacy needed, as it’s offline. Ease of use ans security is more important. Switch on, enter a password.

So basically TailsOS, then? → Plug in to any pc/laptop, switch on, enter password

My wife has no notebook. She uses an iPad. So where does she plug in the tails usb-drive? She cannot plug it in my notebook because the BIOS is password protected and boots only the internal drive with QubesOS.

I’ve already bought a small notebook that does not use too much space in the vault.

Now I’m looking for a secure OS with no unneccessary software on it and a simple GUI.

With “secure” I mean noone can access the files without the password for fde (luks). I hope Luks is secure…

I’m not an infosec expert, but it sounds to me like your concern is really just FDE. You don’t need a “secure” operating system if your Thinkpad is physically air-gapped/offline. As for “easy to use”, you and your partner will just have to look around the distro market and actively test which is more intuitive and easy for you guys. Try taking this quiz to see which one to start off with. As for “unnecessary things” (or bloat?), I’d just say to uninstall whatever you want. It’s a non-issue.