All of lore.kernel.org
 help / color / mirror / Atom feed
From: Yaron Sheffer <yaronf@gmx.com>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] Blog post on FDE and integrity protection
Date: Thu, 01 Sep 2011 13:51:38 +0300	[thread overview]
Message-ID: <4E5F63BA.2070701@gmx.com> (raw)
In-Reply-To: <mailman.1.1314871201.12413.dm-crypt@saout.de>

Hi Arno,

Thank you for reviewing my post. Please see my comments below.

Thanks,
     Yaron

> Message: 3
> Date: Wed, 31 Aug 2011 23:29:40 +0200
> From: Arno Wagner<arno@wagner.name>
> To: dm-crypt@saout.de
> Subject: Re: [dm-crypt] Blog post on FDE and integrity protection
> Message-ID:<20110831212940.GB25013@tansi.org>
> Content-Type: text/plain; charset=us-ascii
>
>
> Commercial, for sure. It combines fragments from well-known
> facts and marketing speech. And it has not understood the
> problem, advertizing for SAN/cloud services, where storage is
> not block-based but file-based.
The most commonly used public cloud is Amazon WS. This cloud offers two 
storage possibilities, S3 which is object ("file") storage, and EBS 
which is block storage, and is exposed to the application as a disk 
volume. The post is about EBS, sorry if that wasn't clear.
> I should also note to anyone contemplating "solution" 3
> that RAID1 does not read both devices on read access,
> and inconsistencies will only show up if you or your
> distro does RAID consistency checks.
This is correct, thanks.
> And of course the whole article does not apply to the
> SAN/cloud setting in the first place, as the attack
> scenario is for an unmapped encrypted filesystem and
> an attacker getting write access to that, i.e. the
> encrypted raw (block) view needs to be exported to
> the attacker. I do not see how that would be done in the
> SAN/Cloud setting. These do their own filesystem
> and block encryption must be done below the FS layer,
> there is no way around that.
The attack scenario is for someone who has access (possibly limited 
access) to your cloud account to detach your EBS volume from its current 
virtual server, attach it to a different server, and then modify the 
(encrypted) storage. This is all completely doable and actually standard 
procedure on AWS.
>
> Arno
>
>
>
> On Wed, Aug 31, 2011 at 04:25:51PM +0200, Heinz Diehl wrote:
>> On 31.08.2011, Yaron Sheffer wrote:
>>
>> [....]
>>
>> In what way is this related to LUKS / dmcrypt?
>> It's plain advertising, isn't it? Gaah!
>>
>>
>>
>>
>> _______________________________________________
>> dm-crypt mailing list
>> dm-crypt@saout.de
>> http://www.saout.de/mailman/listinfo/dm-crypt
>>

       reply	other threads:[~2011-09-01 10:51 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <mailman.1.1314871201.12413.dm-crypt@saout.de>
2011-09-01 10:51 ` Yaron Sheffer [this message]
2011-09-01 11:27   ` [dm-crypt] Blog post on FDE and integrity protection Arno Wagner
2011-09-01 12:34     ` Robert.Heinzmann
2011-09-01 16:45       ` Arno Wagner
2011-09-01 17:37         ` Robert.Heinzmann
2011-08-31 13:02 Yaron Sheffer
2011-08-31 14:25 ` Heinz Diehl
2011-08-31 21:29   ` Arno Wagner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4E5F63BA.2070701@gmx.com \
    --to=yaronf@gmx.com \
    --cc=dm-crypt@saout.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.