* [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs
@ 2014-01-22 15:47 Daniel P. Berrange
2014-01-22 15:56 ` Eric Blake
2014-01-27 15:12 ` Stefan Hajnoczi
0 siblings, 2 replies; 3+ messages in thread
From: Daniel P. Berrange @ 2014-01-22 15:47 UTC (permalink / raw)
To: qemu-devel
Cc: Kevin Wolf, Peter Maydell, Markus Armbruster, Stefan Hajnoczi,
Paolo Bonzini
The qemu-img.texi / qemu-doc.texi files currently describe the
qcow2/qcow2 encryption thus
"Encryption uses the AES format which is very secure (128 bit
keys). Use a long password (16 characters) to get maximum
protection."
While AES is indeed a strong encryption system, the way that
QCow/QCow2 use it results in a poor/weak encryption system.
Due to the use of predictable IVs, based on the sector number
extended to 128 bits, it is vulnerable to chosen plaintext
attacks which can reveal the existence of encrypted data.
The direct use of the user passphrase as the encryption key
also leads to an inability to change the passphrase of an
image. If passphrase is ever compromised the image data will
all be vulnerable, since it cannot be re-encrypted. The admin
has to clone the image files with a new passphrase and then
use a program like shred to secure erase all the old files.
Recommend against any use of QCow/QCow2 encryption, directing
users to dm-crypt / LUKS which can meet modern cryptography
best practices.
Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
Reviewed-by: Markus Armbruster <armbru@redhat.com>
---
qemu-doc.texi | 23 ++++++++++++++++++++---
qemu-img.texi | 23 ++++++++++++++++++++---
2 files changed, 40 insertions(+), 6 deletions(-)
Changed in v3:
- Addressed feedback/typos from Eric & Markus
In v2:
- Addressed typos reported by Peter
Still welcome info about any other flaws qcow2 has in this
area that should be documented.
diff --git a/qemu-doc.texi b/qemu-doc.texi
index 4e9c6e9..6f0b80b 100644
--- a/qemu-doc.texi
+++ b/qemu-doc.texi
@@ -547,10 +547,27 @@ File name of a base image (see @option{create} subcommand)
@item backing_fmt
Image format of the base image
@item encryption
-If this option is set to @code{on}, the image is encrypted.
+If this option is set to @code{on}, the image is encrypted with 128-bit AES-CBC.
+
+The use of encryption in QCow and QCow2 images is considered to be flawed by
+modern cryptography standards, suffering from a number of design problems:
+
+@itemize @minus
+@item The AES-CBC cipher is used with predictable initialization vectors based
+on the sector number. This makes it vulnerable to chosen plaintext attacks
+which can reveal the existence of encrypted data.
+@item The user passphrase is directly used as the encryption key. A poorly
+chosen or short passphrase will compromise the security of the encryption.
+@item In the event of the passphrase being compromised there is no way to
+change the passphrase to protect data in any QCow images. The files must
+be cloned, using a different encryption passphrase in the new file. The
+original file must then be securely erased using a program like shred,
+though even this is ineffective with many modern storage technologies.
+@end itemize
-Encryption uses the AES format which is very secure (128 bit keys). Use
-a long password (16 characters) to get maximum protection.
+Use of QCow / QCow2 encryption is thus strongly discouraged. Users are
+recommended to use an alternative encryption technology such as the
+Linux dm-crypt / LUKS system.
@item cluster_size
Changes the qcow2 cluster size (must be between 512 and 2M). Smaller cluster
diff --git a/qemu-img.texi b/qemu-img.texi
index 1bba91e..de74fda 100644
--- a/qemu-img.texi
+++ b/qemu-img.texi
@@ -402,10 +402,27 @@ File name of a base image (see @option{create} subcommand)
@item backing_fmt
Image format of the base image
@item encryption
-If this option is set to @code{on}, the image is encrypted.
+If this option is set to @code{on}, the image is encrypted with 128-bit AES-CBC.
-Encryption uses the AES format which is very secure (128 bit keys). Use
-a long password (16 characters) to get maximum protection.
+The use of encryption in QCow and QCow2 images is considered to be flawed by
+modern cryptography standards, suffering from a number of design problems:
+
+@itemize @minus
+@item The AES-CBC cipher is used with predictable initialization vectors based
+on the sector number. This makes it vulnerable to chosen plaintext attacks
+which can reveal the existence of encrypted data.
+@item The user passphrase is directly used as the encryption key. A poorly
+chosen or short passphrase will compromise the security of the encryption.
+@item In the event of the passphrase being compromised there is no way to
+change the passphrase to protect data in any QCow images. The files must
+be cloned, using a different encryption passphrase in the new file. The
+original file must then be securely erased using a program like shred,
+though even this is ineffective with many modern storage technologies.
+@end itemize
+
+Use of QCow / QCow2 encryption is thus strongly discouraged. Users are
+recommended to use an alternative encryption technology such as the
+Linux dm-crypt / LUKS system.
@item cluster_size
Changes the qcow2 cluster size (must be between 512 and 2M). Smaller cluster
--
1.8.4.2
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs
2014-01-22 15:47 [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs Daniel P. Berrange
@ 2014-01-22 15:56 ` Eric Blake
2014-01-27 15:12 ` Stefan Hajnoczi
1 sibling, 0 replies; 3+ messages in thread
From: Eric Blake @ 2014-01-22 15:56 UTC (permalink / raw)
To: Daniel P. Berrange, qemu-devel
Cc: Kevin Wolf, Paolo Bonzini, Markus Armbruster, Stefan Hajnoczi,
Peter Maydell
[-- Attachment #1: Type: text/plain, Size: 731 bytes --]
On 01/22/2014 08:47 AM, Daniel P. Berrange wrote:
> The qemu-img.texi / qemu-doc.texi files currently describe the
> qcow2/qcow2 encryption thus
>
> Recommend against any use of QCow/QCow2 encryption, directing
> users to dm-crypt / LUKS which can meet modern cryptography
> best practices.
>
> Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
> Reviewed-by: Markus Armbruster <armbru@redhat.com>
> ---
> qemu-doc.texi | 23 ++++++++++++++++++++---
> qemu-img.texi | 23 ++++++++++++++++++++---
> 2 files changed, 40 insertions(+), 6 deletions(-)
Reviewed-by: Eric Blake <eblake@redhat.com>
--
Eric Blake eblake redhat com +1-919-301-3266
Libvirt virtualization library http://libvirt.org
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 604 bytes --]
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs
2014-01-22 15:47 [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs Daniel P. Berrange
2014-01-22 15:56 ` Eric Blake
@ 2014-01-27 15:12 ` Stefan Hajnoczi
1 sibling, 0 replies; 3+ messages in thread
From: Stefan Hajnoczi @ 2014-01-27 15:12 UTC (permalink / raw)
To: Daniel P. Berrange
Cc: Kevin Wolf, Peter Maydell, qemu-devel, Markus Armbruster,
Stefan Hajnoczi, Paolo Bonzini
On Wed, Jan 22, 2014 at 03:47:10PM +0000, Daniel P. Berrange wrote:
> The qemu-img.texi / qemu-doc.texi files currently describe the
> qcow2/qcow2 encryption thus
>
> "Encryption uses the AES format which is very secure (128 bit
> keys). Use a long password (16 characters) to get maximum
> protection."
>
> While AES is indeed a strong encryption system, the way that
> QCow/QCow2 use it results in a poor/weak encryption system.
> Due to the use of predictable IVs, based on the sector number
> extended to 128 bits, it is vulnerable to chosen plaintext
> attacks which can reveal the existence of encrypted data.
>
> The direct use of the user passphrase as the encryption key
> also leads to an inability to change the passphrase of an
> image. If passphrase is ever compromised the image data will
> all be vulnerable, since it cannot be re-encrypted. The admin
> has to clone the image files with a new passphrase and then
> use a program like shred to secure erase all the old files.
>
> Recommend against any use of QCow/QCow2 encryption, directing
> users to dm-crypt / LUKS which can meet modern cryptography
> best practices.
>
> Signed-off-by: Daniel P. Berrange <berrange@redhat.com>
> Reviewed-by: Markus Armbruster <armbru@redhat.com>
> ---
> qemu-doc.texi | 23 ++++++++++++++++++++---
> qemu-img.texi | 23 ++++++++++++++++++++---
> 2 files changed, 40 insertions(+), 6 deletions(-)
>
> Changed in v3:
>
> - Addressed feedback/typos from Eric & Markus
>
> In v2:
>
> - Addressed typos reported by Peter
>
> Still welcome info about any other flaws qcow2 has in this
> area that should be documented.
Changed "Qcow" to "qcow" for consistency.
Thanks, applied to my block tree:
https://github.com/stefanha/qemu/commits/block
Stefan
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2014-01-27 15:13 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-01-22 15:47 [Qemu-devel] [PATCH v3] Describe flaws in qcow/qcow2 encryption in the docs Daniel P. Berrange
2014-01-22 15:56 ` Eric Blake
2014-01-27 15:12 ` Stefan Hajnoczi
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).