Gentoo Archives: gentoo-user

From: "J. Roeleveld" <joost@××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: tmp on tmpfs
Date: Thu, 25 May 2017 16:29:09
Message-Id: F8AED0BF-AA63-4ADB-B36F-AF17481F82F5@antarean.org
In Reply to: Re: [gentoo-user] Re: tmp on tmpfs by Rich Freeman
1 On May 25, 2017 6:06:45 PM GMT+02:00, Rich Freeman <rich0@g.o> wrote:
2 >On Thu, May 25, 2017 at 10:16 AM, J. Roeleveld <joost@××××××××.org>
3 >wrote:
4 >> On May 25, 2017 1:04:07 PM GMT+02:00, Kai Krakow
5 ><hurikhan77@×××××.com> wrote:
6 >>>Am Thu, 25 May 2017 08:34:10 +0200
7 >>>schrieb "J. Roeleveld" <joost@××××××××.org>:
8 >>>
9 >>>> It is possible. I have it set up like that on my laptop.
10 >>>> Apart from a small /boot partition. The whole drive is encrypted.
11 >>>> Decryption keys are stored encrypted in the initramfs, which is
12 >>>> embedded in the kernel.
13 >>>
14 >>>And the kernel is on /boot which is unencrypted, so are your
15 >encryption
16 >>>keys. This is not much better, I guess...
17 >>
18 >> A file full of random characters is encrypted using GPG.
19 >> Unencrypted, this is passed to cryptsetup.
20 >>
21 >> The passphrase to decrypt the key needs to be entered upon boot.
22 >> How can this be improved?
23 >>
24 >
25 >The need to enter a passphrase was the missing bit here. I thought
26 >you were literally just storing the key in the clear.
27 >
28 >As far as I can tell gpg symmetric encryption does salting and
29 >iterations by default, so you're probably fairly secure. I'm not sure
30 >if the defaults were always set up this way - if you set up that file
31 >a long time ago you might just want to check that, unless your
32 >passphrase is really complex.
33
34 Not sure how long ago this was. I'm planning on redoing the whole laptop in the near future anyway.
35
36 If anyone knows of a better way (that works without TPM) I would like to hear about it.
37
38 --
39 Joost
40 --
41 Sent from my Android device with K-9 Mail. Please excuse my brevity.

Replies

Subject Author
Re: [gentoo-user] Re: tmp on tmpfs Rich Freeman <rich0@g.o>