Re: Follow-up: MFS Meeting. (at PLANT NOMA) Tue, 17 July. "CryptoPractical"
Michael Dorrington <[email protected]> Fri, 27 Jul 2018 08:47:44 +0100
| Newsgroups | gmane.politics.software.free-software.manchester,gmane.org.fsf.uk |
|---|---|
| Message-ID | <[email protected]> |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============5645881219985993687== Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8" This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8 Content-Type: multipart/mixed; boundary="UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T"; protected-headers="v1" From: Michael Dorrington <[email protected]> To: Manchester Free Software <[email protected]> Cc: Free Software and the United Kingdom <fsfe-uk-mXXj517/[email protected]>, "Open Rights Group (ORG) Manchester" <org-manchester-ZwoEplunGu0Bf2Lc/[email protected]> Message-ID: <9e9c419a-0859-689e-6e6b-3ee43b6815b6-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org> Subject: Re: Follow-up: MFS Meeting. (at PLANT NOMA) Tue, 17 July. "CryptoPractical" References: <d729cc72-b08e-8983-1122-7169fc711e63-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org> <7b015aeb-b112-9517-5355-f4e56854c01b-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org> In-Reply-To: <7b015aeb-b112-9517-5355-f4e56854c01b-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org> --UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T Content-Type: text/plain; charset=utf-8 Content-Language: en-GB Content-Transfer-Encoding: quoted-printable On 21/07/18 18:19, Michael Dorrington wrote: > On 12/07/18 08:46, Michael Dorrington wrote: >=20 >> * Event: Manchester Free Software's July Meeting >> >> * Talk: CryptoPractical >> * Speaker: Michael Dorrington >=20 > Exercises (and feel free to ask for help on the MFS mailinglist): >=20 > 1. Set up an encrypted USB stick using LUKS. >=20 > Some things to keep in mind: >=20 > a) Triple check you are messing with the right block ("disk") device. > Commands like `lsblk` and `lsblk --scsi` help here. >=20 > b) Fill the disk/block device with random data first, something like: >=20 > dd bs=3D1M if=3D/dev/urandom of=3D/dev/sdKNOWWHATYOUAREDOING The Debian Reference manual has details how to do this in "Chapter 9. System tips" under "9.8.1. Removable disk encryption with dm-crypt/LUKS". In this they use `badblocks` with random test pattern instead of the above `dd` with urandom. The badblocks command has the advantage that it checks that the data written to the disk is the same as that read back, particularly worth doing with USB sticks. However, I'm not sure the randomness is sufficiently random. Advanced question, how random is the "random" test pattern in badblocks, particularly compared to urandom? They also use the new cryptsetup syntax of "open --type luks" rather than "luksOpen". See: https://www.debian.org/doc/manuals/debian-reference/ch09.en.html#_removab= le_disk_encryption_with_dm_crypt_luks The Debian Reference manual is worth checking out. It has been packaged too, see: https://packages.debian.org/debian-reference-en M. --=20 FSF member #9429 http://www.fsf.org/register_form?referrer=3D9429 http://www.fsf.org/about "The Free Software Foundation (FSF) is a nonprofit with a worldwide mission to promote computer user freedom and to defend the rights of all free software users." --UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T-- --7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8 Content-Type: application/pgp-signature; name="signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="signature.asc" -----BEGIN PGP SIGNATURE----- iQJWBAEBCABAFiEEymnV/lrtCqpNhpze13JsPqr44+8FAltazi4iHG1pY2hhZWwu ZG9ycmluZ3RvbkBtZW1iZXIuZnNmLm9yZwAKCRDXcmw+qvjj7zpRD/9pnEHO4uck hY1MmvcfXyEaEby6TwKZMaIznt5CCIgxDEJbLuwg1L9BqtEGhWoBxP6Lmo+yxy0u SYyESrsWpviOqtkGCfU70rzgvopQNiJSdWsIaHLWE4vW5P46c1e3K6XeUJpQf5xi hPKPXuSKfJkL8dMOcq5mfZA0MYpX6BKvOSMbdlW67IPI5Q/2jBlrCdko67seZdVs 3HTdi8DU6EPvT3fCINDvJbtJs9zP5Lqi8kIuixcKrZ+o6P848opotC68k9fITQEM EQhwBAI3ODjSb5urrinsNqvx2YeuvsaS7ffqKvRjpid+Smn7E48zIxlzPCZKfEuT GFmOhvFe2CRWkjzI/EeYh2dfvddiouMeaN0sCXO0e94MeI6NKJAsNIMr699QbLhs gYT0BhWF3R9INbMoZaXrF0GRkmt76D7tgeb3bf+FLFveG2/KVbrqzWrZ3Py5N6BP eXWk346G9Kek6cdarWPLKUrLX7kSb8dUiK/wsfDEGDCAw9N2vUPt+v5sFHTEMMdY s4TjHKzZjqUbQ2LUnf/7i5e/Au1PYACFTfv/7phlZTbl3Y+DdAfuJgHW+uhtzBvf +6j9iaitWF5i+fPqioWAwZ1529Z3BuY1PED2T7R7JfglKDT6heflI9TxkYgfBpID vvfz7Opvg3sGQw0haiak6dw2vZwEqPBGvw== =iVBR -----END PGP SIGNATURE----- --7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8-- --===============5645881219985993687== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Fsuk-manchester mailing list [email protected] https://lists.nongnu.org/mailman/listinfo/fsuk-manchester --===============5645881219985993687==--