DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "michaelof@rocketmail.com" <michaelof@rocketmail.com>
To: dm-crypt@saout.de
Subject: [dm-crypt] General question: Encrypytion on virtual servers (VPS/Vserver)
Date: Tue, 21 Feb 2017 14:42:51 +0100	[thread overview]
Message-ID: <517282b9-becc-aa96-602a-9b6f603d01f1@rocketmail.com> (raw)


Dear list members,


as a newbie I've read the detailed FAQ at https://gitlab.com/cryptsetup/cryptsetup/wikis/FrequentlyAskedQuestions and
was deeply impressed by the carefulness of the author aubout the highly political various perilous aspects of
encryption. Great job, thank you !!!

My intention for a usage of LUKS / cryptsetup are less political, but privacy. To get control back for my private data,
I'm running a Vserver with a complete mail server setup (postfix, dovecot, ...) plus owncloud and a couple of other free
software.

My questions here are of a more general nature, hopefully not be seen as off-topic by the valued list members:

As my Vserver is hardened against potential outside attacks as much as I've been able to, it's currently completely
unprotected against "internal" attacks.  Means that anyone from the hosting company e.g. could clone this Vserver or
copy the unecnrypted virtual disks, even without my knowledge, and access all data on it.

Of course I trust this hosting company, otherwise I wouldn't have chosen them. But I would like to "solve" this generic
issue, if possible, independent of a specific company.

In the German IT journal "c't" I've found an interesting article about encrypting a home server against data theft, if
the home server get's physically stolen. Could easily be done by encrypting the whole disk(s), sure. But imho a very
nice idea of this article was a LXC container based setup. A non-excrypted base setup with more or less only sshd, and
an encrypted container for anything else. Nice idea, because this setup is able to "survive" a reboot after power-loss,
sending an email to the server-owner, notifying him to ssh-login and restart the inner container = entering the
deencryption password(s).

Having read this article, I've started to think about if this scenario wouldn't also be perfectly suitable for my
Vserver requirements.

But when asking the author of this article about some small questions left, he stated his personal opinion that any
encryption on an externally hosted vserver/VPS would be a waste of time. Because the to be entered at boot time
deencryption passwords would be stored in memory of the virtual machine (all is KVM based at this company), they could
easily be read from memory, in case of a "real" attack.

Coming to the point: As this sounds reasonable, is there any chance to circumvent this issue?


Thank you,
Michael

             reply	other threads:[~2017-02-21 13:42 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-02-21 13:42 michaelof [this message]
2017-02-21 13:58 ` [dm-crypt] General question: Encrypytion on virtual servers (VPS/Vserver) Daniel P. Berrange
2017-02-21 16:21   ` Arno Wagner
2017-02-21 16:33     ` Daniel P. Berrange
2017-02-21 18:14       ` Arno Wagner
2017-02-21 13:59 ` Arno Wagner
2017-02-21 14:13 ` Michael Kjörling

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=517282b9-becc-aa96-602a-9b6f603d01f1@rocketmail.com \
    --to=michaelof@rocketmail.com \
    --cc=dm-crypt@saout.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox