From: Matthias Schniedermeyer <ms@citd.de>
To: TimC <tconnors@astro.swin.edu.au>
Cc: Bodo Eggert <7eggert@gmx.de>,
Lennart Sorensen <lsorense@csclub.uwaterloo.ca>,
Tuomo Valkonen <tuomov@iki.fi>,
linux-kernel@vger.kernel.org
Subject: Re: The ext3 way of journalling
Date: Sat, 12 Jan 2008 11:08:35 +0100 [thread overview]
Message-ID: <20080112100835.GA14605@citd.de> (raw)
In-Reply-To: <slrn-0.9.7.4-27208-4606-200801121808-tc@hexane.ssi.swin.edu.au>
On 12.01.2008 18:10, TimC wrote:
> Bodo Eggert <7eggert@gmx.de> said on Sat, 12 Jan 2008 02:41:17 +0100 (CET):
> > On Fri, 11 Jan 2008, Lennart Sorensen wrote:
> > > On Fri, Jan 11, 2008 at 05:22:45PM +0100, Bodo Eggert wrote:
> >
> > > > What can happen if someone does tune2fs -Lroot /dev/usbstick
> > > > and puts that stick into this system?
> > >
> > > Don't know. I use UUIDs rather than LABELs. Having duplicated labels
> > > just means being careless. Having duplicate UUIDs should require being
> > > malicous.
> >
> > That's exactly what you have to assume for your users. Otherwise, you could
> > remove any security feature from the system.
>
> If they've got physical access to your machine, you've already lost.
As a last resort there is always the option to encrypt everything.
Of course you loose the LABEL & UUID support with that.
But i circumvented that by a custom udev script and marking the MBR in
the documented 4 bytes for an ID that is used by said script to create
an appropriate symlink.
Together with a matching autofs-conf i can still automatically mount all
my >50 encrypted HDDs i have stacked on my shelf. :-)
Bis denn
--
Real Programmers consider "what you see is what you get" to be just as
bad a concept in Text Editors as it is in women. No, the Real Programmer
wants a "you asked for it, you got it" text editor -- complicated,
cryptic, powerful, unforgiving, dangerous.
next prev parent reply other threads:[~2008-01-12 10:08 UTC|newest]
Thread overview: 83+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <9JpbI-5yi-9@gated-at.bofh.it>
[not found] ` <9JpEP-6df-25@gated-at.bofh.it>
[not found] ` <9JpYc-6Eb-13@gated-at.bofh.it>
[not found] ` <9Jqhr-7l9-13@gated-at.bofh.it>
[not found] ` <9JqKt-7Z5-9@gated-at.bofh.it>
2008-01-08 22:24 ` The ext3 way of journalling Bodo Eggert
[not found] ` <9Jqri-7ym-17@gated-at.bofh.it>
[not found] ` <9JqUn-8bF-15@gated-at.bofh.it>
[not found] ` <9JvKj-85h-41@gated-at.bofh.it>
2008-01-11 16:22 ` Bodo Eggert
2008-01-11 18:39 ` Lennart Sorensen
2008-01-12 1:41 ` Bodo Eggert
2008-01-12 7:10 ` TimC
2008-01-12 10:08 ` Matthias Schniedermeyer [this message]
2008-01-08 16:07 Tuomo Valkonen
2008-01-08 16:35 ` Jan Engelhardt
2008-01-08 16:52 ` Tuomo Valkonen
2008-01-08 17:18 ` Jan Engelhardt
2008-01-08 17:48 ` Tuomo Valkonen
2008-01-08 18:20 ` Jan Engelhardt
2008-01-08 18:32 ` Diego Calleja
2008-01-08 18:42 ` Tuomo Valkonen
2008-01-08 16:39 ` John Stoffel
2008-01-08 16:59 ` Tuomo Valkonen
2008-01-08 21:49 ` John Stoffel
2008-01-09 13:39 ` Mathieu SEGAUD
2008-01-09 14:16 ` Tuomo Valkonen
2008-01-10 13:16 ` Theodore Tso
2008-01-10 13:41 ` Tuomo Valkonen
2008-01-12 15:06 ` Theodore Tso
2008-01-12 19:24 ` Andrey Vul
2008-01-13 22:13 ` Tuomo Valkonen
2008-01-13 22:23 ` Tuomo Valkonen
2008-01-13 23:11 ` Theodore Tso
2008-01-14 7:15 ` Tuomo Valkonen
2008-01-14 9:42 ` Bernd Petrovitsch
2008-01-14 9:48 ` Tuomo Valkonen
2008-01-14 9:57 ` Bernd Petrovitsch
2008-01-14 10:44 ` Christer Weinigel
2008-01-14 11:11 ` Tuomo Valkonen
2008-01-14 11:18 ` Bernd Petrovitsch
2008-01-14 11:27 ` Tuomo Valkonen
2008-01-14 10:06 ` Krzysztof Halasa
2008-01-14 11:03 ` Tuomo Valkonen
2008-01-14 12:46 ` Krzysztof Halasa
2008-01-14 16:18 ` Lennart Sorensen
2008-01-14 23:13 ` Alejandro Riveira Fernández
2008-01-15 16:31 ` Lennart Sorensen
2008-01-15 1:09 ` Krzysztof Halasa
2008-01-15 16:32 ` Lennart Sorensen
2008-01-14 16:10 ` me
2008-01-14 16:17 ` Tuomo Valkonen
2008-01-14 22:39 ` John Hubbard
2008-01-14 0:36 ` Bernd Eckenfels
2008-01-08 16:48 ` Andre Noll
2008-01-08 17:52 ` Tuomo Valkonen
2008-01-08 18:07 ` Masoud Sharbiani "مسعود شربیانی"
2008-01-08 18:16 ` Tuomo Valkonen
2008-01-08 18:22 ` Alan Cox
2008-01-08 18:11 ` Jan Engelhardt
2008-01-08 18:20 ` Tuomo Valkonen
2008-01-08 18:29 ` Andre Noll
2008-01-08 18:40 ` Tuomo Valkonen
2008-01-08 18:47 ` Alan Cox
2008-01-08 23:06 ` Matthias Schniedermeyer
2008-01-09 7:56 ` Tuomo Valkonen
2008-01-09 10:21 ` Matthias Schniedermeyer
2008-01-09 10:28 ` Matthias Schniedermeyer
2008-01-09 12:30 ` Theodore Tso
2008-01-10 11:30 ` Helge Hafting
2008-01-10 14:02 ` Lennart Sorensen
2008-01-10 14:41 ` Matthias Schniedermeyer
2008-01-09 2:05 ` Bernd Petrovitsch
2008-01-08 16:53 ` Andi Kleen
2008-01-08 17:01 ` Tuomo Valkonen
2008-01-08 18:15 ` Theodore Tso
2008-01-08 20:51 ` Andi Kleen
2008-01-08 21:03 ` Ondrej Zary
2008-01-08 21:57 ` Theodore Tso
2008-01-09 3:21 ` Kyle Moffett
2008-01-09 7:55 ` Valdis.Kletnieks
2008-01-09 12:49 ` Theodore Tso
2008-01-09 8:00 ` BuraphaLinux Server
2008-01-09 8:21 ` Valdis.Kletnieks
2008-01-09 9:54 ` Martin Schwidefsky
2008-01-09 12:25 ` Theodore Tso
2008-01-09 12:44 ` Michal Schmidt
2008-01-09 13:53 ` Martin Schwidefsky
2008-01-09 19:47 ` Martin Schwidefsky
2008-01-08 21:32 ` Pavel Machek
2008-02-08 4:16 ` Rogelio Serrano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20080112100835.GA14605@citd.de \
--to=ms@citd.de \
--cc=7eggert@gmx.de \
--cc=linux-kernel@vger.kernel.org \
--cc=lsorense@csclub.uwaterloo.ca \
--cc=tconnors@astro.swin.edu.au \
--cc=tuomov@iki.fi \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.