All of lore.kernel.org
 help / color / mirror / Atom feed
* [dm-crypt] SSD disks and cryptsetup-reencrypt
@ 2013-06-12 14:44 octane indice
  2013-06-12 22:30 ` Arno Wagner
  0 siblings, 1 reply; 4+ messages in thread
From: octane indice @ 2013-06-12 14:44 UTC (permalink / raw)
  To: dm-crypt


Hello

I read the FAQ, the point 5.19, especially:
(...)
However, for LUKS, the worst case is that key-slots and LUKS header may end up in these 
internal pools. This means that password management functionality is compromised (the old 
passwords may still be around, potentially for a very long time) and that fast erase by 
overwriting the header and key-slot area is insecure. 
(...)

Now, we have a cryptsetup-reencrypt tool that could change the master-key.
So, we could use it after changing a password for a slot.

But, dm-crypt use 512bytes for block operations, so the problem remains the same?
An attacker with the knowledge of the master-key could read old sectors un-erased and 
decipher data?

Thanks 

Envoyé avec Inmano, ma messagerie renversante et gratuite : http://www.inmano.com

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2013-06-13  5:51 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-06-12 14:44 [dm-crypt] SSD disks and cryptsetup-reencrypt octane indice
2013-06-12 22:30 ` Arno Wagner
2013-06-12 23:43   ` Matthias Schniedermeyer
2013-06-13  5:51     ` Yves-Alexis Perez

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.