Interesting post about the strange state of data authentication and encryption in Linux distros... encrypting the OS and user data with the same secret doesn't make sense in a multiuser setting. Also asking for credentials from an initrd whose authenticity is not validated is problematic.

