Re: I got a good security one more ya.



On Fri, Mar 31, 2006 at 12:29:34AM -0600, Gromitigo wrote:
Ok. If I have files saved as a user, and someone takes my hard drive
out, puts it in another machine, mounts it...could they read that file
if they we're root? What about if I write the files as root?

They could read it fine.

Similarly, if you were to tar or zip up a directory containing files
with restricted read permissions (e.g. a backup of your home directory
including gpg or ssh keys), anyone with access to your tar/zip file can
easily read the relevant files.

As was said in another post, if someone swiping your hard drive is a
risk you need to account for, you should look into encrypting your hard
drive. These issues are non-trivial, however; dm-crypt, for example,
has (had?) a timing weakness that allows any user to recover the AES key
in a mere 65 *milliseconds*. [1]

You should also realize that if someone has physical access to your
machine, there are quicker ways to access your data than removing the
hard drive: they could simply boot a Live CD or append init=/bin/sh to
your bootloader's boot string. (These can be locked down if you're that
concerned, however.)

[1] http://www.wisdom.weizmann.ac.il/~tromer/papers/cache.pdf

--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • Re: Disk Druid - Fedora flame #1
    ... What I do as root, ... Root's home directory should contain very little: ... part of a minimal boot environment. ... And the root filesystem should be as small as reasonably possible, ...
    (Fedora)
  • Re: X11Forwarding, ssh -X, and /bin/su
    ... ]>but I'm not really tunneled using ssh then, ... ]connecting to the X server and have the home directory NFS-mounted ... ](unless you leave root unmapped over NFS, ... ]root-readable place and set the environment $XAUTHORITY variable ...
    (comp.security.ssh)
  • Re: Shared User Folders and printer setup
    ... only mapping to the root? ... I have a 2003 standard server setup running as a Terminal Server to allow our other location to access our main SBS 2003 server and run our Mfg/accntg software. ... In order to get this software to work Trans-Micro (the makers of Check Factory) have a detailed procedure that allows multiple Terminal Server users to run the software at the same time. ... Does anyone have any idea why and how can I get it to look at the Home directory path Z: ...
    (microsoft.public.windows.terminal_services)
  • Re: Excellent news.. Malware for OS X!
    ... compromise and that nothing is immune. ... If it isn't already running as root, it will ask for the password ... the majority of Mac users, then malware has an even larger reach. ... Another method of avoiding that is to simply copy everything in /Applications to somewhere in your home directory and changing links appropriately. ...
    (comp.sys.mac.advocacy)
  • Re: move your home directory - second newsgroup post
    ... I'm fairly sure you'll have to enable root access ... user's home directory. ... I've never found ANY action that requires enabling ... Steve W. Jackson ...
    (comp.sys.mac.misc)