Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #241189 > unrolled thread

Re: Re: LUKS encryption help

Started bydetrito@tuta.io
First post2021-10-11 15:10 +0200
Last post2021-10-12 18:20 +0200
Articles 7 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  Re: Re: LUKS encryption help detrito@tuta.io - 2021-10-11 15:10 +0200
    Re: LUKS encryption help David Christensen <dpchrist@holgerdanske.com> - 2021-10-11 21:50 +0200
      Re: LUKS encryption help David Wright <deblis@lionunicorn.co.uk> - 2021-10-11 23:30 +0200
      Re: LUKS encryption help deloptes <emanoil.kotsev@deloptes.org> - 2021-10-11 23:30 +0200
        Re: LUKS encryption help David Wright <deblis@lionunicorn.co.uk> - 2021-10-12 00:00 +0200
    Re: Re: LUKS encryption help Cindy Sue Causey <butterflybytes@gmail.com> - 2021-10-12 07:20 +0200
      Re: LUKS encryption help David Wright <deblis@lionunicorn.co.uk> - 2021-10-12 18:20 +0200

#241189 — Re: Re: LUKS encryption help

Fromdetrito@tuta.io
Date2021-10-11 15:10 +0200
SubjectRe: Re: LUKS encryption help
Message-ID<D73e1-2Gx-3@gated-at.bofh.it>
Hello friends, I'm sending this last email to inform you that I have given up on trying to recover the contents of my external hard drive and that I formatted it.
Thank you to every single one of you who spared their time to try and help me.
On one last note, I should I drag attention to what seemed to be a bug on the boot screen that asked for my LUKS password: It considered backspaces as a normal character. I type my password and it shows an asterisk on the screen for every character I type - instead of deleting the asterisk, the backspace key created one more asterisk each time I pressed it.

[toc] | [next] | [standalone]


#241206

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2021-10-11 21:50 +0200
Message-ID<D79t8-6ko-7@gated-at.bofh.it>
In reply to#241189
On 10/11/21 05:50, detrito@tuta.io wrote:
> Hello friends, I'm sending this last email to inform you that I have given up on trying to recover the contents of my external hard drive and that I formatted it.


I hope you have implemented backups procedures, to prevent losing data 
in the future.


> Thank you to every single one of you who spared their time to try and help me.


You are welcome.  :-)


> On one last note, I should I drag attention to what seemed to be a bug on the boot screen that asked for my LUKS password: It considered backspaces as a normal character. I type my password and it shows an asterisk on the screen for every character I type - instead of deleting the asterisk, the backspace key created one more asterisk each time I pressed it.


When I boot my Debian machines with LUKS encrypted root filesystems, I 
see a bunch of time-stamped bootloader messages followed by the prompt:

     Please unlock disk sda3_crypt:


When I type on the keyboard, nothing is echoed to the screen.


David

[toc] | [prev] | [next] | [standalone]


#241211

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2021-10-11 23:30 +0200
Message-ID<D7b1T-7kS-9@gated-at.bofh.it>
In reply to#241206
On Mon 11 Oct 2021 at 12:43:21 (-0700), David Christensen wrote:
> On 10/11/21 05:50, detrito@tuta.io wrote:
> > Hello friends, I'm sending this last email to inform you that I have given up on trying to recover the contents of my external hard drive and that I formatted it.
> 
> I hope you have implemented backups procedures, to prevent losing data
> in the future.
> 
> > Thank you to every single one of you who spared their time to try and help me.

A pity that it's reformatted; I would have liked to know more about
the circumstances of the unlocking attempts.

> > On one last note, I should I drag attention to what seemed to be a bug on the boot screen that asked for my LUKS password: It considered backspaces as a normal character.

What do you mean by a "normal character"? AFAIK you can't put
backspaces into a passphrase, and it would be ill-advised to type
any backspaces when /setting/ a new passphrase: better to Ctrl-C
out of setting it, or type some garbage to make it so that the
verification deliberately fails and you can start over.

When you're typing the /old/ passphrase, then backspace should erase
the previous character as usual, and an excessive number of them
should be ignored.

> > I type my password and it shows an asterisk on the screen for every character I type - instead of deleting the asterisk, the backspace key created one more asterisk each time I pressed it.

There are arguments both ways: reflecting an asterisk indicates that
the key was successfully depressed, whereas erasing an asterisk
allows you to count how far through the passphrase you have typed.

Because of a previous problem¹ I had with stretch on a Lenovo laptop,
I haven't configured my encrypted devices to unlock in the manner
where asterisks are printed. So I can't tell whether it's possible,
as you get asterisks printed, whether there's a possibility that the
backspace key is not doing something unexpected under the exact
circumstances. (I'm recalling the ambiguity of the Backspace and
Delete keys, and whether they emitted ^H, ^?, or escape sequences.)

> When I boot my Debian machines with LUKS encrypted root filesystems, I
> see a bunch of time-stamped bootloader messages followed by the
> prompt:
> 
>     Please unlock disk sda3_crypt:
> 
> When I type on the keyboard, nothing is echoed to the screen.

IIRC that's the prompt I saw when I recently tried out a
root-encrypted installation in order to see how Grub boots it.
And I don't recall asterisks. However, it's not clear to me
what the OP means by "boot screen". If you specify partitions
to be unlocked by passphrase in /etc/crypttab, then part-way
through booting, you get a more fullsome prompt:
Please enter passphrase for disk PARTLABEL (LABEL) on MOUNTPOINT
with relevant substitutions. This dialogue uses asterisks.
If it hadn't, I could have suffered similar consequences to the
OP, as the asterisks were the only reason I knew that there was
a "ghost in the machine".

Nowadays, I only use /etc/crypttab to configure my randomly
encrypted swap partition, so no prompt at all. I explicitly
unlock /home later, mainly because I can then wake machines
up and unlock them remotely. As in your case, udisksctl is
asterisk-less during typing, and it's also terse enough for
me to prefix my own prompt about what exactly I am unlocking.

¹
https://lists.debian.org/debian-user/2018/03/msg01030.html

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#241212

Fromdeloptes <emanoil.kotsev@deloptes.org>
Date2021-10-11 23:30 +0200
Message-ID<D7b1T-7kS-11@gated-at.bofh.it>
In reply to#241206
David Christensen wrote:

> When I boot my Debian machines with LUKS encrypted root filesystems, I
> see a bunch of time-stamped bootloader messages followed by the prompt:
> 
> Please unlock disk sda3_crypt:
> 
> 
> When I type on the keyboard, nothing is echoed to the screen.

I use plymouth or alike and there I see the asterisk displayed, but with
backspace I can delete an asterisk and it does not produce another one.
It seems there was something wrong with the terminal there.

-- 
FCD6 3719 0FFB F1BF 38EA 4727 5348 5F1F DCFE BCB0

[toc] | [prev] | [next] | [standalone]


#241213

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2021-10-12 00:00 +0200
Message-ID<D7buX-7vC-5@gated-at.bofh.it>
In reply to#241212
On Mon 11 Oct 2021 at 23:25:07 (+0200), deloptes wrote:
> David Christensen wrote:
> 
> > When I boot my Debian machines with LUKS encrypted root filesystems, I
> > see a bunch of time-stamped bootloader messages followed by the prompt:
> > 
> > Please unlock disk sda3_crypt:
> > 
> > 
> > When I type on the keyboard, nothing is echoed to the screen.
> 
> I use plymouth or alike and there I see the asterisk displayed, but with
> backspace I can delete an asterisk and it does not produce another one.
> It seems there was something wrong with the terminal there.

Ouch. That's suggests that my first suggestion (keyboard layout)
was close to the mark, though I never thought of suggesting the
behaviour of Backspace, and the OP didn't bring it up. However,
it's odd that none of the other routes into unlocking produced
any results either.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#241231

FromCindy Sue Causey <butterflybytes@gmail.com>
Date2021-10-12 07:20 +0200
Message-ID<D7imK-3VZ-15@gated-at.bofh.it>
In reply to#241189
On 10/11/21, detrito@tuta.io <detrito@tuta.io> wrote:
> Hello friends, I'm sending this last email to inform you that I have given
> up on trying to recover the contents of my external hard drive and that I
> formatted it.
> Thank you to every single one of you who spared their time to try and help
> me.
> On one last note, I should I drag attention to what seemed to be a bug on
> the boot screen that asked for my LUKS password: It considered backspaces as
> a normal character. I type my password and it shows an asterisk on the
> screen for every character I type - instead of deleting the asterisk, the
> backspace key created one more asterisk each time I pressed it.


DISCLAIMER: Mine doesn't display the asterisks, but maybe this is
still somehow what's occurring that causes that asterisks to appear
where they aren't expected.

This sounds like a twist on something that's aggravating for me on the
"console" reached via e.g. "CTRL+F3". It happens with my user name
when I'm typing too fast ahead of the speed of my brain.

Mine occurs with a fairly basic debootstrapped XFCE4's "console". I'll
type in my username then hit TAB the way I normally do via the initial
GUI login screen. For those console logon instances, I should be
hitting ENTER immediately after the username. If I backspace to
eliminate the TAB's blank space addition to my username instead of
attempting CTRL+C to start over, the logon attempt fails.

All I can figure is that it's treating both the TAB and backspace
keyboard actions as necessary keystroke parts of the logon name. Since
they're not, that's apparently why it fails. If that is by intentional
design, repeated personal experience has been that... it works!

Something similar also occurs for the password. I can backspace all I
want in a GUI xfce4-terminal window, and it works fine after the
proper password is eventually entered (e.g. for gaining root
privileges). On that CTRL+F3 console, it appears to treat each
corrective backspace action as a deliberate, additional keystroke part
of the password instead of as a user correcting a typing error.

It occurred to me to try the same thing to run "apt-get update" while
over there in the CTRL+F3 console. The password works fine no matter
how many TAB and backspace entries a user makes after one successfully
logs in to get to that point of access.

Oh, goodness, I hope that came out at least halfway understandable, grin.

Cindy :)
-- 
Cindy-Sue Causey
Talking Rock, Pickens County, Georgia, USA
* runs with birdseed *

[toc] | [prev] | [next] | [standalone]


#241248

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2021-10-12 18:20 +0200
Message-ID<D7sFr-1Z5-5@gated-at.bofh.it>
In reply to#241231
On Tue 12 Oct 2021 at 01:12:21 (-0400), Cindy Sue Causey wrote:
> On 10/11/21, detrito@tuta.io <detrito@tuta.io> wrote:
> > Hello friends, I'm sending this last email to inform you that I have given
> > up on trying to recover the contents of my external hard drive and that I
> > formatted it.
> > Thank you to every single one of you who spared their time to try and help
> > me.
> > On one last note, I should I drag attention to what seemed to be a bug on
> > the boot screen that asked for my LUKS password: It considered backspaces as
> > a normal character. I type my password and it shows an asterisk on the
> > screen for every character I type - instead of deleting the asterisk, the
> > backspace key created one more asterisk each time I pressed it.
> 
> DISCLAIMER: Mine doesn't display the asterisks, but maybe this is
> still somehow what's occurring that causes that asterisks to appear
> where they aren't expected.
> 
> This sounds like a twist on something that's aggravating for me on the
> "console" reached via e.g. "CTRL+F3". It happens with my user name
> when I'm typing too fast ahead of the speed of my brain.
> 
> Mine occurs with a fairly basic debootstrapped XFCE4's "console". I'll
> type in my username then hit TAB the way I normally do via the initial
> GUI login screen. For those console logon instances, I should be
> hitting ENTER immediately after the username. If I backspace to
> eliminate the TAB's blank space addition to my username instead of
> attempting CTRL+C to start over, the logon attempt fails.
> 
> All I can figure is that it's treating both the TAB and backspace
> keyboard actions as necessary keystroke parts of the logon name. Since
> they're not, that's apparently why it fails. If that is by intentional
> design, repeated personal experience has been that... it works!

I don't know what a CTRL+F3 console is, and googling this only hints
that it might be   /xfwm4/custom/<Control>F3 workspace_3_key   and
/xfwm4/default/<Control>F3 workspace_3_key, whatever that is.

So my first step would be to find out what process it is that you're
typing into when all this occurs.

> Something similar also occurs for the password. I can backspace all I
> want in a GUI xfce4-terminal window, and it works fine after the
> proper password is eventually entered (e.g. for gaining root
> privileges). On that CTRL+F3 console, it appears to treat each
> corrective backspace action as a deliberate, additional keystroke part
> of the password instead of as a user correcting a typing error.

Ditto.

> It occurred to me to try the same thing to run "apt-get update" while
> over there in the CTRL+F3 console. The password works fine no matter
> how many TAB and backspace entries a user makes after one successfully
> logs in to get to that point of access.

Ditto, and what's asking for a password with apt-get?

Pinning down the exact process might not be straightforward or
particularly productive. My own attempt (an asterisk occurrence) was
fairly fruitless as the answer appeared to be udisksctl, which under
other circumstances emits no asterisks.

https://lists.debian.org/debian-user/2019/06/msg00585.html

Cheers,
David.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web