From: Robbie Smith <zoqaeski@gmail.com>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] (More) Questions about LUKS / LVM
Date: Tue, 20 Sep 2011 20:36:58 +1000 [thread overview]
Message-ID: <1316515022.7965.31.camel@zarniwoop> (raw)
Ah, that makes sense. It clicked with me after reading the paper on the
wiki. When you set up the system, it generates a random "master key",
which each key slot encrypts separately. So unlocking any key slot
unlocks the master key, which is then used to decrypt the disk. That's
rather clever actually.
At the moment I'm only planning to encrypt the onboard HDD of the
laptop, mainly to protect it against unauthorised access. It's a
brand-new machine, so I guess there won't be any noticeable latency with
an i3 or i5 processor. I had a few concerns as at the moment I'm using a
5+ year old Pentium "D" (P4 with hyperthreading?) and I get noticeable
latency with some applications; I didn't want to potentially add to
that.
What are some potential worst-case scenarios? i.e. the system had a hard
reset, either because the power got cut or (somehow) an application
brought the system to a complete halt? How would this affect the
encryption, and could it result in total data loss?
The FAQ makes mention that the most frequent cause of data loss is
either losing access to the keys or somehow corrupting the LUKS header.
The former I can understand, and "common" sense would dictate to have a
couple of backup keys in secure locations. I am at a loss though as to
how someone could unintentionally corrupt the header though.
I'm inclined to set up my system with /boot and a LUKS partition, and
then use LVM inside that, so if I decide to rearrange virtual partitions
I won't run the risk of messing up the LUKS header. This also seems like
the simplest setup.
(I keep daily backups of $HOME and of essential system settings, the
rest can be reinstalled if needed, but I'd prefer not to have to spend a
few days recovering everything if I had a hard reset or something like
that.)
Robbie
next reply other threads:[~2011-09-20 10:37 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-09-20 10:36 Robbie Smith [this message]
2011-09-20 10:52 ` [dm-crypt] (More) Questions about LUKS / LVM Quentin Lefebvre
2011-09-20 11:47 ` Arno Wagner
2011-09-20 13:13 ` Milan Broz
2011-09-20 14:14 ` Arno Wagner
2011-09-20 14:52 ` Milan Broz
2011-10-03 6:17 ` Luca Berra
2011-10-03 10:55 ` Arno Wagner
2011-09-20 15:21 ` Alexander Koch
2011-09-20 16:12 ` Milan Broz
2011-09-20 17:41 ` Arno Wagner
2011-09-20 18:06 ` Karl O. Pinc
2011-09-20 18:19 ` Milan Broz
2011-09-21 10:22 ` Arno Wagner
2011-09-21 16:14 ` Dragan Milivojevic
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1316515022.7965.31.camel@zarniwoop \
--to=zoqaeski@gmail.com \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox