All of lore.kernel.org
 help / color / mirror / Atom feed
From: Bill Davidsen <davidsen@tmr.com>
To: Valdis.Kletnieks@vt.edu
Cc: Paulo Marques <pmarques@grupopie.com>,
	"Nico Augustijn." <kernel@janestarz.com>,
	hvr@gnu.org, clemens@endorphin.org, linux-kernel@vger.kernel.org
Subject: Re: Cryptoloop patch for builtin default passphrase
Date: Tue, 26 Oct 2004 17:15:44 -0400	[thread overview]
Message-ID: <417EBE80.3030505@tmr.com> (raw)
In-Reply-To: <200410251905.i9PJ5Rrj013717@turing-police.cc.vt.edu>

Valdis.Kletnieks@vt.edu wrote:
> On Mon, 25 Oct 2004 19:23:35 BST, Paulo Marques said:
> 
> 
>>(why would you need confidential information to boot in the first place?)
> 
> 
> The problem is not that the info in the NVRAM is "confidential",
> but that most of it is "configuration".
> 
> Really sucks if you recable your SCSI controllers, the default boot disk
> changes from controller 4, device 5, to controller 2, device 3 - and you
> have to go and re-cable the OLD way, find the rescue CD, and fix /etc/fstab
> so that you can boot in the same config that you installed the software?
> 
> Either that, or forever lose the use of "default boot device", and
> have to specify it on every single boot if you want the software to work.
> That *really* sucks if it's a rack-mount in a colo, you need to get physical
> access to reboot....
> 
> 
>>No it is not. You would just type in again *if* the contents of nvram 
>>got lost which shouldn't happen in the first place (or at least happen 
>>rarely).
> 
> 
> So you change IRQ9 from level to edge trigger, or change "default boot order"
> from "floppy, cd, hard drive" to "floppy, cd, hard drive, network", and
> suddenly your software evaporates?
> 
> That certainly violates the Principle of Least Surprise, and why I asked
> if it was an intended effect.

It depends on the intent of the encryption. If the purpose is the 
protect the data, then this is acceptable. In some cases it is more 
important to protect the data than to preserve them.

More to the point, I thought there was a small section of nvram reserved 
to local system use, which the BIOS should not change. The appropriate 
manual is 100 miles away, I have no time to google. Beside which someone 
will pop up with the answer before I could look ;-)

-- 
    -bill davidsen (davidsen@tmr.com)
"The secret to procrastination is to put things off until the
  last possible moment - but no longer"  -me

  parent reply	other threads:[~2004-10-26 21:14 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-10-25 11:54 Cryptoloop patch for builtin default passphrase Nico Augustijn.
2004-10-25 17:19 ` Valdis.Kletnieks
2004-10-25 17:33   ` Paulo Marques
2004-10-25 17:54     ` Valdis.Kletnieks
2004-10-25 18:23       ` Paulo Marques
2004-10-25 19:05         ` Valdis.Kletnieks
2004-10-26 11:17           ` Paulo Marques
2004-10-26 21:15           ` Bill Davidsen [this message]
2004-10-25 18:57   ` Nico Augustijn
2004-10-25 19:13     ` Valdis.Kletnieks
2004-10-26  6:17 ` Jan Engelhardt
  -- strict thread matches above, loose matches on Subject: below --
2004-10-27 13:27 Nico Augustijn
2004-10-27 20:01 ` Bill Davidsen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=417EBE80.3030505@tmr.com \
    --to=davidsen@tmr.com \
    --cc=Valdis.Kletnieks@vt.edu \
    --cc=clemens@endorphin.org \
    --cc=hvr@gnu.org \
    --cc=kernel@janestarz.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pmarques@grupopie.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.