I've heard in the past that it is possible to have a setup using luks where the header would reside on a removable media along with the boot partition and the hard drive would make use of full disk encryption with not even the luks header residing in it..thus giving the option of plausible deniability.
How can I get a setup like that, to be more specific..how do I move luksHeader onto a removable media and patch grub in a way so that they work as expected.
Thanks

