From: dhvvcb@lavabit.com
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] Boot from fully encrypted disk which looks like unused
Date: Tue, 24 May 2011 10:33:11 +0600 [thread overview]
Message-ID: <1306211591.2079.92.camel@localhost> (raw)
In-Reply-To: <4DDA083D.801@redhat.com>
On Mon, 23/05/2011 at 09:09 +0200, Milan Broz wrote:
> One simple change will be support for detached LUKS header in some
> next version of cryptsetup.
> So you can have header on separate (USB or so) device or in file.
> The unlocked drive then does not contain any visible metadata then.
Reasonable intention.
Arno Wagner
You consider only two extreme situations. First, you may easily refuse
to give the key. Second, government is hunting for you and keen to find
out your secrets. You will not believe, but there are many other
situations. Opponents may not be so intelligent and they do not know
that random-looking parts of a disk can contain information. If they
suspect presence of encryption, the extent how much they will try to
affect you depends on their confidence, and presence of a cryptographic
header would apparently be bad. And so on. I don't claim that deniable
encryption guarantee personal security. However there is a lot of
situations when visible cryptographic header is definitely undesirable.
I think it is obvious and I wouldn't like to argue about that. At last,
there is no legal ground to demand the key if there is no indication of
encryption. Citizens must not explain anything. Otherwise, it is
lawlessness. They should get used to random bits.
All I am interested in this topic is how to modify initramfs so that
kernel would understand option root=/dev/mapper/hhd2 or something like
that. In brief, task is following. Bootloader (grub), kernel (vmlinuz)
and vfs (initramfs) are placed on a usb flash drive. Encrypted root file
system is placed on hdd drive (with no cryptographic header). Kernel
should be able to decrypt root file system. Any hints are welcome.
next prev parent reply other threads:[~2011-05-24 4:25 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-05-22 15:53 [dm-crypt] Boot from fully encrypted disk which looks like unused dhvvcb
2011-05-23 0:13 ` Arno Wagner
2011-05-23 3:35 ` dhvvcb
2011-05-23 7:09 ` Milan Broz
2011-05-23 17:20 ` PsiStormYamato
2011-05-24 4:33 ` dhvvcb [this message]
2011-05-23 7:45 ` Arno Wagner
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1306211591.2079.92.camel@localhost \
--to=dhvvcb@lavabit.com \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox