Heck, I'd be OK with it requiring me to enter a passphrase on resume. I'd even be OK with linux having a tunable to hand my root LUKS passphrase to this facility, to keep it easy. Just about everything this runs on should have AES-NI and the on-disk format should be verifyable. This would be a great extension to the service from Intel.
I actually got as far as setting up the partition's GUID before the implications occurred to me. It would be nice, but for now hibernate is my only safe option.
Re: Threat to dm-crypt
I actually got as far as setting up the partition's GUID before the implications occurred to me. It would be nice, but for now hibernate is my only safe option.