The packets are encrypted. LE can get your VPN encryption keys from the VPS.
Hence, they can decrypt the captured encrypted traffic. Definitely smarts to encrypt the drives separately, and disabling pw login.
It all depends on who you've pissed off. If you've got a nation-state power like the CIA after you, there's basically nothing you can do to protect yourself, short of going fully off-grid.
(post is archived)