Re: encrypted filesystems



On Aug 17, 2:16 pm, Måns Rullgård <m...@xxxxxxxxx> wrote:

This is precisely what encryption is supposed to prevent -- getting
back data that is different from what you gave it.

Encryption is for keeping data secret.

Right, and in this example, the encryption failed to keep the data
secret by failing to protect the integrity of an access control
mechanism.

 Checksums are for verifying
data integrity.  They can each be used alone or combined, and cases
can be imagined where any of the four possible combinations is
preferred.

Right, but there is a huge risk when you don't combine them. Failure
to ensure the integrity of access control information can result in
failure to keep other information secret. An encryption solution that
doesn't protect the integrity of data may wind up not keeping its
contents secret either.

Certainly it's a fair question whether or not the encryption is to
blame or not. I would argue that if it doesn't at least mention this
possible system vulnerability, then the encryption is at least
partially to blame.

DS
.



Relevant Pages

  • Re: Securing data to a process principal
    ... Yes, you can protect against ... The RM analyst also uses an app that has an embedded obfuscated key (I'll ... where the secret is stored in the registry. ... encryption would be done with a key that was associated with the app ID. ...
    (microsoft.public.platformsdk.security)
  • Re: Securing data to a process principal
    ... reasonable controls that protect against "casual" abuse. ... hooks into your encryption function) and you cannot prevent an admin using ... The RM analyst also uses an app that has an embedded obfuscated key (I'll ... where the secret is stored in the registry. ...
    (microsoft.public.platformsdk.security)
  • Re: Securing data to a process principal
    ... reasonable controls that protect against "casual" abuse. ... hooks into your encryption function) and you cannot prevent an admin using ... The RM analyst also uses an app that has an embedded obfuscated key (I'll ... where the secret is stored in the registry. ...
    (microsoft.public.platformsdk.security)
  • Re: encrypted filesystems
    ... |> Encryption is for keeping data secret. ... The original descryption was a network security configuration being tampered ... layer or the block device layer to ensure data integrity, ...
    (comp.os.linux.development.system)
  • Re: What alternatives there are for encrypting your entire HDD?
    ... If you want to keep the temporary files, logs, etc., secret, then ask ... encryption doesn't necessarily help with ... might or might not help with integrity. ...
    (sci.crypt)