Re: Wireless Network Key



On Wed, 2008-08-06 at 11:43 -0400, Mark Haney wrote:

Sure those keys are encrypted, and exactly how long do you think it
would take to crack that encrypted file? Not long. The point is, if
the system is compromised with that user account, it being Ubuntu, they
can SUDO into root and get the keys. That's my point. It doesn't
matter in this case. Access to a regular user account in Ubuntu gets
you root access much easier than if it's say Gentoo, or Fedora where
sudo isn't always configured for a particular user.

So, your point about the keys being safer in n-m is just as useless as
mine is from that perspective.

If you use a hard to crack master key phrase, it would be extremely
difficult to get access to the encrypted keys. Root access does not get
you access to the keys in a user's keyring. You need to know the
passphrase. Normally, this looks like it is the user's login password,
but it can be changed, so you are prompted to unlock the keyring when
applications ask for access.
--
Smoot Carl-Mitchell
System/Network Architect
smoot@xxxxxxx
+1 480 922 7313
cell: +1 602 421 9005

--
ubuntu-users mailing list
ubuntu-users@xxxxxxxxxxxxxxxx
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-users



Relevant Pages

  • [Full-disclosure] [USN-612-2] OpenSSH vulnerability
    ... particularly affects the use of encryption keys in OpenSSH. ... Ubuntu) are based on Debian. ... amd64 architecture: ...
    (Full-Disclosure)
  • [USN-612-2] OpenSSH vulnerability
    ... particularly affects the use of encryption keys in OpenSSH. ... Ubuntu) are based on Debian. ... amd64 architecture: ...
    (Bugtraq)
  • [Full-disclosure] [USN-612-3] OpenVPN vulnerability
    ... particularly affects the use of shared encryption keys and SSL/TLS ... certificates in OpenVPN. ... Ubuntu) are based on Debian. ... i386 architecture: ...
    (Full-Disclosure)
  • RE: [USN-612-2] OpenSSH vulnerability
    ... The update for Ubuntu 8.04 was as ... (part of the ssh-server install was a blacklist of keys not to use). ... particularly affects the use of encryption keys in OpenSSH. ... amd64 architecture: ...
    (Ubuntu)
  • Re: Adding all user in a domain to a sharepoint site
    ... keys 'analyze' and 'update', former is used to generate the .xml file ... with all the user account information. ... So at one time you can update all the user account regardless of site ...
    (microsoft.public.sharepoint.portalserver.development)