public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Alan Cox <alan@lxorguk.ukuu.org.uk>
To: jonathan@jonmasters.org
Cc: Robert White <rwhite@casabyte.com>,
	Andrea Arcangeli <andrea@novell.com>,
	Nigel Cunningham <ncunningham@linuxmail.org>,
	Chris Wright <chrisw@osdl.org>, Jeff Garzik <jgarzik@pobox.com>,
	Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
	Andrew Morton <akpm@osdl.org>
Subject: Re: mlock(1)
Date: Wed, 29 Sep 2004 02:23:28 +0100	[thread overview]
Message-ID: <1096421006.14637.4.camel@localhost.localdomain> (raw)
In-Reply-To: <35fb2e59040928181676b15c1b@mail.gmail.com>

On Mer, 2004-09-29 at 02:16, Jon Masters wrote:
> I don't see in your argument how this is meant to be cryptographically
> secure. Nor do I see from any of the original mail an idea which does
> anything more than offer a fake promise of security to those who are
> willing to assume only dumb criminals steal their laptop. This is
> worse than no security at all and renders the idea of encrypting swap
> completely useless.

Most criminals are dumb. That means a boot screen that says 
"Property of Dave Miller, if found please leave anywhere in Tahoe"
"Password:"

and a boot/bios password will defeat them and may get the laptop dumped
back where it can be recovered.

Thus don't rule out the value of the deterrent It isnt appropriate if
you leave national secrets on the train like all our finest government
employees keep doing obviously.

> 1). I open the laptop up (I'm allowed to do that if I've already nicked it :P).
> 2). I take a copy of the BIOS.
> 3). I replace the BIOS with a hardware configuration (however done -
> perhaps hot swapping chips, perhaps some simple logic device helps me)
> in which the original BIOS is available once booting begins.
> 4). That part of the security model was just destroyed.

This threat level is why secure systems people use smartcards for the
encryption keys and related processing. Just don't leave the smartcard
on the train!


  reply	other threads:[~2004-09-29  2:26 UTC|newest]

Thread overview: 71+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-09-24 19:57 mlock(1) Jeff Garzik
2004-09-24 20:15 ` mlock(1) Neil Horman
2004-09-24 20:21   ` mlock(1) Neil Horman
2004-09-24 20:31   ` mlock(1) Lee Revell
2004-09-24 20:33     ` mlock(1) Jeff Garzik
2004-09-24 20:39       ` mlock(1) Lee Revell
2004-09-24 20:22 ` mlock(1) Chris Wright
2004-09-24 20:41   ` mlock(1) Chris Friesen
2004-09-24 20:46     ` mlock(1) Chris Wright
2004-09-24 20:54       ` mlock(1) Chris Friesen
2004-09-24 20:59         ` mlock(1) Chris Wright
2004-09-24 22:48     ` mlock(1) Ryan Cumming
2004-09-24 21:07   ` mlock(1) Alan Cox
2004-09-24 22:19     ` mlock(1) Chris Wright
2004-09-24 22:30       ` mlock(1) Jeff Garzik
2004-09-24 23:08         ` mlock(1) Chris Wright
2004-09-24 22:59     ` mlock(1) Andrea Arcangeli
2004-09-24 23:46       ` mlock(1) Nigel Cunningham
2004-09-25  1:07         ` mlock(1) Andrea Arcangeli
2004-09-25  1:21           ` mlock(1) David Lang
2004-09-25  1:30             ` mlock(1) Andrea Arcangeli
2004-09-25  1:46               ` mlock(1) Valdis.Kletnieks
2004-09-25  2:15                 ` mlock(1) Andrea Arcangeli
2004-09-25  2:46                   ` mlock(1) Valdis.Kletnieks
2004-09-25  2:58                     ` mlock(1) Andrea Arcangeli
2004-09-25  3:29                       ` mlock(1) Valdis.Kletnieks
2004-09-25  4:07                         ` mlock(1) Andrea Arcangeli
2004-09-25  4:52                           ` mlock(1) Valdis.Kletnieks
2004-09-25 17:15                         ` mlock(1) Andy Lutomirski
2004-09-25  2:33                 ` mlock(1) Bernd Eckenfels
2004-09-25  1:27           ` mlock(1) Andrea Arcangeli
2004-09-28 22:03             ` mlock(1) Robert White
2004-09-28 22:15               ` mlock(1) Andrea Arcangeli
2004-09-28 23:26                 ` mlock(1) Robert White
2004-09-29  1:16                   ` mlock(1) Jon Masters
2004-09-29  1:23                     ` Alan Cox [this message]
2004-09-29  3:46                     ` mlock(1) Robert White
2004-09-29 12:34                       ` mlock(1) Jon Masters
2004-09-29 15:57                       ` mlock(1) Lee Revell
2004-09-29 22:56                         ` mlock(1) Paul Jackson
2004-09-25 12:21           ` mlock(1) Nigel Cunningham
2004-09-25 14:53             ` mlock(1) Andrea Arcangeli
2004-09-28  8:48               ` mlock(1) Pavel Machek
2004-09-30 17:42                 ` mlock(1) Andrea Arcangeli
2004-09-30 18:54                   ` mlock(1) Pavel Machek
2004-09-30 19:17                     ` mlock(1) Andrea Arcangeli
2004-09-30 19:52                       ` mlock(1) Pavel Machek
2004-10-04 12:21                   ` mlock(1) Jack Lloyd
2004-09-24 23:59       ` mlock(1) Bernd Eckenfels
2004-09-25  0:25         ` mlock(1) Nigel Cunningham
2004-09-25  1:18           ` mlock(1) Andrea Arcangeli
2004-09-27  6:16             ` mlock(1) Stefan Seyfried
2004-09-27 10:32               ` mlock(1) Nigel Cunningham
2004-09-27 14:29                 ` mlock(1) Andrea Arcangeli
2004-09-27 20:32                   ` mlock(1) Wolfgang Walter
2004-09-27 14:16               ` mlock(1) Andrea Arcangeli
2004-09-27 13:31                 ` mlock(1) Alan Cox
2004-09-29  1:48                   ` mlock(1) Andrea Arcangeli
2004-09-27 14:34                 ` mlock(1) Stefan Seyfried
2004-09-27 15:07                   ` mlock(1) Andrea Arcangeli
2004-09-27 15:25                     ` mlock(1) Stefan Seyfried
2004-09-27 15:38                       ` mlock(1) Andrea Arcangeli
2004-09-30 13:04                     ` mlock(1) Pavel Machek
2004-09-27 22:22                 ` mlock(1) Nigel Cunningham
2004-09-27 22:43                   ` mlock(1) Andrea Arcangeli
2004-09-28 22:03                     ` mlock(1) Nigel Cunningham
2004-09-24 20:24 ` mlock(1) Chris Friesen
2004-09-24 21:17 ` mlock(1) Andrew Morton
2004-09-25  0:26   ` mlock(1) Chris Wright
2004-09-25  1:28     ` mlock(1) Andrew Morton
2004-09-25  1:33       ` mlock(1) Chris Wright

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1096421006.14637.4.camel@localhost.localdomain \
    --to=alan@lxorguk.ukuu.org.uk \
    --cc=akpm@osdl.org \
    --cc=andrea@novell.com \
    --cc=chrisw@osdl.org \
    --cc=jgarzik@pobox.com \
    --cc=jonathan@jonmasters.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ncunningham@linuxmail.org \
    --cc=rwhite@casabyte.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox