  1. Good advice, just one minor suggestion – when scrubbing a new disk, rather than writing to a file on the file system just write random data to the raw disk device e.g.
    dd if=/dev/urandom of=/dev/sda
    (replace /dev/sda with the disk device)
    then run cryptsetup to set up encryption, then format the plaintext device in /dev/mapper with your chosen filesystem

    Obviously you can’t do this to a disk that is in use unless you back up to another disk first and restore afterwards.

