1 |
On May 25, 2017 5:38:35 AM GMT+02:00, Kai Krakow <hurikhan77@×××××.com> wrote: |
2 |
>Am Wed, 24 May 2017 12:30:36 -0700 |
3 |
>schrieb Rich Freeman <rich0@g.o>: |
4 |
> |
5 |
>> On Wed, May 24, 2017 at 11:34 AM, Ian Zimmerman <itz@×××××××.net> |
6 |
>> wrote: |
7 |
>> > On 2017-05-24 08:00, Kai Krakow wrote: |
8 |
>> > |
9 |
>> >> Unix semantics suggest that /tmp is not expected to survive |
10 |
>reboots |
11 |
>> >> anyways (in contrast, /var/tmp is expected to survive reboots), so |
12 |
>> >> tmpfs is a logical consequence to use for /tmp. |
13 |
>> > |
14 |
>> > /tmp is wiped by the bootmisc init job anyway. |
15 |
>> > |
16 |
>> |
17 |
>> In general I haven't found anything that is bothered by /var/tmp |
18 |
>being |
19 |
>> lost on reboot, but obviously that is something you need to be |
20 |
>> prepared for if you put it on tmpfs. |
21 |
>> |
22 |
>> One thing that wasn't mentioned is that having /tmp in tmpfs might |
23 |
>> also have security benefits depending on what is stored there, since |
24 |
>> it won't be written to disk. If you have a filesystem on tmpfs and |
25 |
>> your swap is encrypted (which you should consider setting up since it |
26 |
>> is essentially "free") then /tmp also becomes a useful dumping ground |
27 |
>> for stuff that is decrypted for temporary processing. For example, |
28 |
>if |
29 |
>> you keep your passwords in a gpg-encrypted file you could copy it to |
30 |
>> /tmp, decrypt it there, do what you need to, and then delete it. |
31 |
>That |
32 |
>> wouldn't leave any recoverable traces of the file. |
33 |
> |
34 |
>Interesting point... How much performance impact does encrypted swap |
35 |
>have? I don't mean any benchmark numbers but real life experience from |
36 |
>your perspective when the system experiences memory pressure? |
37 |
|
38 |
I have my laptop encrypted. Has 16GB and occasionally it does use swap. With it all being on SSD. |
39 |
I am not noticing any slowdowns because of it. |
40 |
|
41 |
-- |
42 |
Joost |
43 |
-- |
44 |
Sent from my Android device with K-9 Mail. Please excuse my brevity. |