Gentoo Archives: gentoo-hardened

From: "W. Michael Petullo" <mike@××××.org>
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Re: Hardened Laptops / Talk is cheap
Date: Wed, 27 Aug 2003 14:01:42
Message-Id: 20030828001434.GA11140@flyn.org
In Reply to: Re: [gentoo-hardened] Re: Hardened Laptops / Talk is cheap by Nigel Stepp
1 > > IIRC, we've always been leaning towards a method that would have the
2 > > passphrase on a USB device that would obviously need to be present to
3 > > unencrypt the filesystems on the laptop. I think that it's also important to
4 > > have the good old enter-your-passphrase-at-boot decryption of one's
5 > > filesystems as an option.
6 >
7 > I agree, although I ended up doing that just because I was afraid of
8 > losing my usb drive, or it somehow becoming currupted. If it can't find
9 > the usb drive, then I have it give me a shell so I can set things up
10 > manually.
11 >
12 > For me, the ability to get at my data, given at least the
13 > presense of both the laptop and myself, was paramount.
14
15 I like the idea of a random key on a USB stick (or other physical token).
16 As a backup I think the key's hex digits written down and stored in a
17 secure location might be good (or a memorized passphrase, but I've never
18 been fond of memorized passphrases). Then on boot one could enter some
19 type of emergency manual key entry mode if necessary.
20
21 Also, my (util-linux 2.12 / Linux 2.6) cryptoswap and cryptotmp scripts
22 are now available at http://www.flyn.org/projects/cryptoswap/index.html.
23 As with my initrd, I'm just starting to get this all working so it may
24 or may not work for you. The scripts are Debian-centric at this point
25 (*gasp*, not gentoo!). The initrd stuff I sent to this list earlier is
26 not yet included.
27
28 Do we need someone to start tracking all of this stuff?
29
30 --
31 Mike
32
33 :wq
34
35 --
36 gentoo-hardened@g.o mailing list

Replies

Subject Author
[gentoo-hardened] ProPolice and building mit-krb5 Laurence Jupp <laurence@×××××.org>