Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #210592
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Document removal of ecryptfs-utils from Buster |
| Date | 2019-07-02 11:20 +0200 |
| Message-ID | <yfn7c-7bm-9@gated-at.bofh.it> (permalink) |
| References | <yeEMN-5mL-1@gated-at.bofh.it> <yfaCZ-7Sw-9@gated-at.bofh.it> <yfedA-1Fo-1@gated-at.bofh.it> |
| Organization | none,nada,zip |
On Monday 01 July 2019 19:42:08 David Wright wrote: > On Mon 01 Jul 2019 at 15:56:14 (-0400), Gene Heskett wrote: > > On Monday 01 July 2019 09:33:35 David Wright wrote: > > > On Mon 01 Jul 2019 at 06:05:52 (-0400), Gene Heskett wrote: > > > > On Monday 01 July 2019 03:52:55 Jonathan Dowland wrote: > > > > > On Sun, Jun 30, 2019 at 12:45:57PM -0400, Gene Heskett wrote: > > > > > >At this point, I'd call it a buster delaying bug. That last > > > > > > is going to cost too many that can't ignore it and don't > > > > > > have unencrypted backups. Thats going to be a lot of very > > > > > > bad PR. > > > > > > > > > > It's the release teams call, generally speaking, and one of > > > > > the things they might factor in is the size of the user-base > > > > > for the troublesome package. I'm surprised to find that it's > > > > > extremely small according to popcon data: less than 1% of > > > > > reporters: > > > > > https://qa.debian.org/popcon.php?package=ecryptfs-utils > > > > > > > > > > Compare just two alternatives: > > > > > > > > > > encfs: 1.14% https://qa.debian.org/popcon.php?package=encfs > > > > > cryptsetup: 15% > > > > > https://qa.debian.org/popcon.php?package=cryptsetup > > > > > > > > That does put a better light on it. From the comments so far, I > > > > was thinking I'm one of the few not using it. I've depended on > > > > dd-wrt between me and the internet for the last 16 years, and > > > > even before that I was on dialup and the dialup folks didn't > > > > have enough bandwidth to attract the black hats, so I've never > > > > been touched. > > > > > > I was under the impression that these two forms of security, > > > firewalls and encryption, are completely orthogonal. Once you've > > > unlocked, say, an encrypted partition, you're now reliant on the > > > firewall to keep strangers out of your files. OTOH a perfect > > > firewall is of no benefit when your laptop is stolen. > > > > > > > With all the publicity this thread has given the issue, I'll > > > > change my mind (as if it matters to the team :) and say adequate > > > > notice and mitigating paths seems to have been given. Those that > > > > are using it I'd call pretty advanced and are reading this list > > > > just for the notices given so they shouldn't be surprised. So > > > > I'll do an Andy Capp and shuddup. > > > > > > The grey area is for me is the relative benefit of encrypting file > > > by file compared with the whole partition. Assuming that there's > > > just one passphrase involved in each scenario, is more protection > > > given by the former method? After all, once a partition is > > > unlocked, all users on the system are able to read all the files, > > > subject to the normal unix permissions, ACLs, etc. > > > > Whole filesystem encryption would be a total non-starter for me. > > Fair enough. Could you reveal why, or are your reasons cryptic too? No, but if for some reason, say a cerebral accident, I should lose the password, the whole system would be locked away, and that would be unforgivable. And at 84&counting, I've no warranty I'll remember my own name 10 minutes from my hitting send on this message. > > File by > > file with different passwd's according to whats in the file would > > make far more sense to me. Thats my $0.02. > > I can't see how anyone would cope with a scheme like that. How would > you remember all those passwords? By limiting it to probably 2. Normal stuff might just be my user pw, whereas stuff that is truly private might have a 2048 bit hash. > > OTOH I can see that each file must have an individual encryption key, > but the encryption scheme looks after generating those. Otherwise > you would have a large sample of encrypted but known-cleartext files > available for cracking attempts. (Remember that the filenames are not > encrypted, and many files on a system will have entirely predictable > contents, eg much of /usr, your Debian package cache, and so on. Clearly I haven't explored all the ramifications. Its been more of a case of letting my imagination out to play without a chaperone. > Cheers, > David. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis Genes Web page <http://geneslinuxbox.net:6309/gene>
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-06-30 12:00 +0200
Re: Document removal of ecryptfs-utils from Buster Andrea Borgia <andrea@borgia.bo.it> - 2019-06-30 17:40 +0200
Re: Document removal of ecryptfs-utils from Buster Sven Hartge <sven@svenhartge.de> - 2019-06-30 18:20 +0200
Re: Document removal of ecryptfs-utils from Buster Gene Heskett <gheskett@shentel.net> - 2019-06-30 18:50 +0200
Re: Document removal of ecryptfs-utils from Buster Jonathan Dowland <jmtd@debian.org> - 2019-07-01 10:00 +0200
Re: Document removal of ecryptfs-utils from Buster Gene Heskett <gheskett@shentel.net> - 2019-07-01 12:10 +0200
Re: Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-07-01 15:20 +0200
Re: Document removal of ecryptfs-utils from Buster Jonathan Dowland <jmtd@debian.org> - 2019-07-01 15:50 +0200
Re: Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-07-01 16:10 +0200
Re: Document removal of ecryptfs-utils from Buster Gene Heskett <gheskett@shentel.net> - 2019-07-01 22:00 +0200
Re: Document removal of ecryptfs-utils from Buster David Wright <deblis@lionunicorn.co.uk> - 2019-07-01 15:40 +0200
Re: Document removal of ecryptfs-utils from Buster Jonathan Dowland <jmtd@debian.org> - 2019-07-01 15:50 +0200
Re: Document removal of ecryptfs-utils from Buster Gene Heskett <gheskett@shentel.net> - 2019-07-01 22:00 +0200
Re: Document removal of ecryptfs-utils from Buster Jonathan Dowland <jmtd@debian.org> - 2019-07-01 22:20 +0200
Re: Document removal of ecryptfs-utils from Buster David Wright <deblis@lionunicorn.co.uk> - 2019-07-02 01:50 +0200
Re: Document removal of ecryptfs-utils from Buster Gene Heskett <gheskett@shentel.net> - 2019-07-02 11:20 +0200
Re: Document removal of ecryptfs-utils from Buster Richard Hector <richard@walnut.gen.nz> - 2019-07-07 02:10 +0200
Re: Document removal of ecryptfs-utils from Buster Andrea Borgia <andrea@borgia.bo.it> - 2019-06-30 19:00 +0200
Re: Document removal of ecryptfs-utils from Buster Tixy <tixy@yxit.co.uk> - 2019-06-30 19:50 +0200
Re: Document removal of ecryptfs-utils from Buster deloptes <deloptes@gmail.com> - 2019-06-30 21:20 +0200
Re: Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-07-01 09:50 +0200
Re: Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-07-01 16:20 +0200
Re: Document removal of ecryptfs-utils from Buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-07-01 16:50 +0200
Re: Document removal of ecryptfs-utils from Buster Curt <curty@free.fr> - 2019-07-01 17:50 +0200
Re: Document removal of ecryptfs-utils from Buster Greg Wooledge <wooledg@eeg.ccf.org> - 2019-07-01 16:20 +0200
70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) The Wanderer <wanderer@fastmail.fm> - 2019-07-02 14:10 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Curt <curty@free.fr> - 2019-07-02 14:40 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) The Wanderer <wanderer@fastmail.fm> - 2019-07-02 15:00 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) The Wanderer <wanderer@fastmail.fm> - 2019-07-02 15:20 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Greg Wooledge <wooledg@eeg.ccf.org> - 2019-07-02 15:20 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Curt <curty@free.fr> - 2019-07-02 16:20 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) The Wanderer <wanderer@fastmail.fm> - 2019-07-02 16:30 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Brian <ad44@cityscape.co.uk> - 2019-07-02 21:20 +0200
Re: 70-persistent-net-rules no longer supported? Stephan Seitz <stse+debian@fsing.rootsland.net> - 2019-07-03 09:20 +0200
Re: 70-persistent-net-rules no longer supported? Curt <curty@free.fr> - 2019-07-03 10:10 +0200
Re: 70-persistent-net-rules no longer supported? Brian <ad44@cityscape.co.uk> - 2019-07-03 11:30 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Geoff <unit735@bigpond.com> - 2019-07-03 04:30 +0200
Re: 70-persistent-net-rules no longer supported? (Was Re: Document removal of ecryptfs-utils from Buster) Andrei POPESCU <andreimpopescu@gmail.com> - 2019-07-08 11:20 +0200
csiph-web