Language Selection

English French German Italian Portuguese Spanish

LUKS mermaids of remote unlock

Filed under
Security

Recently, I’ve browsed several how-to’s regarding the possibility of unlocking a LUKS root volume remotely using an SSH connection. For reference, the first of its kind is the one for Debian, published at Coulmann.de. Some of these how-to’s were posted to forums and mailing-lists and received many thankful comments from sysadmins wondering how to make their encrypted secure setup also easy to administrate.

The problem with their approach is simple: they asked how to fix their setup, but forgot to ask what they’re trying to protect. Having your root filesystem on an encrypted disk doesn’t protect you from remote exploitation or credential leaks. It just protects you from the risk of someone being able to access your machine locally and steal your data, or just steal the whole machine altogether. Now, if I were an attacker having access to your hardware locally,

I could easily setup a trap for you in less than 5 minutes:




More in Tux Machines

World’s smallest i.MX6 module has onboard WiFi, eMMC

Variscite unveiled a 50 x 20mm “DART-MX6″ module that runs Linux or Android on the Freescale i.MX6, with up to 64GB eMMC flash and -40 to 85°C support. Variscite’s claim that the 50 x 20mm DART-MX6 is the world’s smallest computer-on-module based on Freescale’s i.MX6 system-on-chip appears to be a valid one. It beats the smallest ones we’ve seen to date: TechNexion’s 40 x 36mm PICO-IMX6, and Solid-Run’s 47 x 30mm microSOM i4. It’s also just a hair larger than Variscite’s own 52 x 17mm DART-4460, which is based on a dual-core TI OMAP4460 SoC, and Gumstix’s slightly larger 58 x 17mm Overo modules, which use TI Sitara AM37xx SoCs. Read more

BQ Aquaris E4.5 Ubuntu Edition review

The BQ Aquaris e4.5 Ubuntu Edition is not the debut Canonical must have envisaged for Ubuntu Phone, in the early days of the platform’s development. It’s a perfectly functional smartphone for the most part, and we like the concept of scopes, but the hardware is humdrum, performance is sluggish, and the software running on it is rough and ready, and full of holes. We’ll be tracking the progress of Ubuntu Phone with interest – it surely must get better than this – but this first device is one to write off to experience. Read more