How to protect an encrypted file system for off-line attack?



Sorry for my ignorance in this respect, I hope you can help me.

I'm actually using encfs to protect my sensitive data, but this is what
is said in the manual:

"""The most intrusive attacks, where an attacker has complete control of
the user’s machine (and can therefor modify EncFS, or FUSE, or the
kernel itself) are not guarded against. Do not assume that encrypted
files will protect your sensitive data if you enter your password into a
compromised computer. How you determine that the computer is safe to
use is beyond the scope of this documentation."""

So my question is: how can I truly protect a filesystem against offline
attacks?

I have thinking of using an SD card for storing the passwords in, and
some kind of script or program to automatically retrive password from
the card when needed. Then, if I retire the card, then my filesystem is
secure.

But I also have more questions... is the AES encoder that encfs uses by
default secure enough? If not, is there another way to use another one,
for example, GnuPG?

Thank you.



--
gpg --keyserver pool.sks-keyservers.net --recv-keys AFC23C68


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



Relevant Pages

  • Re: How to protect an encrypted file system for off-line attack?
    ... root could modify the EncFS program itself to bypass ... attacks, i.e. someone has physical access to your computer without ... automatically input from an SD card or something might actually ... I'm actually using encfs to protect my sensitive data, ...
    (Debian-User)
  • Re: How to protect an encrypted file system for off-line attack?
    ... I'm actually using encfs to protect my sensitive data, ... how can I truly protect a filesystem against offline ...
    (Debian-User)
  • Re: How to protect an encrypted file system for off-line attack?
    ... root could modify the EncFS program itself to bypass ... keylogger" and "how do I catch a user account compromise before the ... attacker can gain root." ... that a friend wants to protect his data ...
    (Debian-User)
  • Re: Password protect access DB?
    ... What is the purpose of your security ... ... protect your data from being manipulated without the interface or prevent ... if it is to protect sensitive data ... ... if it is to prevent third party software from accessing you data ... ...
    (microsoft.public.dotnet.languages.vb)
  • Password protected files
    ... Having a PDA with finger print ID is a pretty secure means to protect ... sensitive data, so on that score I am quite happy but the sensitive date on ... I decided to password protect the files in the ActiveSync folder on the ... I now find that Active Sync does not recognise password protected Word files ...
    (microsoft.public.pocketpc.activesync)