Re: Follow-up: MFS Meeting. (at PLANT NOMA) Tue, 17 July. "CryptoPractical"

Michael Dorrington <[email protected]> Fri, 27 Jul 2018 08:47:44 +0100
Newsgroups gmane.politics.software.free-software.manchester,gmane.org.fsf.uk
Message-ID <[email protected]>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============5645881219985993687==
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8
Content-Type: multipart/mixed; boundary="UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T";
 protected-headers="v1"
From: Michael Dorrington <[email protected]>
To: Manchester Free Software <[email protected]>
Cc: Free Software and the United Kingdom <fsfe-uk-mXXj517/[email protected]>,
 "Open Rights Group (ORG) Manchester"
 <org-manchester-ZwoEplunGu0Bf2Lc/[email protected]>
Message-ID: <9e9c419a-0859-689e-6e6b-3ee43b6815b6-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org>
Subject: Re: Follow-up: MFS Meeting. (at PLANT NOMA) Tue, 17 July.
 "CryptoPractical"
References: <d729cc72-b08e-8983-1122-7169fc711e63-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org>
 <7b015aeb-b112-9517-5355-f4e56854c01b-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org>
In-Reply-To: <7b015aeb-b112-9517-5355-f4e56854c01b-IGUgQLVVQiRCV4ILt04nZQ@public.gmane.org>

--UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T
Content-Type: text/plain; charset=utf-8
Content-Language: en-GB
Content-Transfer-Encoding: quoted-printable

On 21/07/18 18:19, Michael Dorrington wrote:
> On 12/07/18 08:46, Michael Dorrington wrote:
>=20
>> * Event: Manchester Free Software's July Meeting
>>
>> * Talk: CryptoPractical
>> * Speaker: Michael Dorrington
>=20
> Exercises (and feel free to ask for help on the MFS mailinglist):
>=20
> 1. Set up an encrypted USB stick using LUKS.
>=20
> Some things to keep in mind:
>=20
> a) Triple check you are messing with the right block ("disk") device.
> Commands like `lsblk` and `lsblk --scsi` help here.
>=20
> b) Fill the disk/block device with random data first, something like:
>=20
> dd bs=3D1M if=3D/dev/urandom of=3D/dev/sdKNOWWHATYOUAREDOING

The Debian Reference manual has details how to do this in "Chapter 9.
System tips" under "9.8.1. Removable disk encryption with
dm-crypt/LUKS".  In this they use `badblocks` with random test pattern
instead of the above `dd` with urandom.  The badblocks command has the
advantage that it checks that the data written to the disk is the same
as that read back, particularly worth doing with USB sticks.  However,
I'm not sure the randomness is sufficiently random.  Advanced question,
how random is the "random" test pattern in badblocks, particularly
compared to urandom?

They also use the new cryptsetup syntax of "open --type luks" rather
than "luksOpen".

See:

https://www.debian.org/doc/manuals/debian-reference/ch09.en.html#_removab=
le_disk_encryption_with_dm_crypt_luks

The Debian Reference manual is worth checking out.  It has been packaged
too, see: https://packages.debian.org/debian-reference-en

M.

--=20
FSF member #9429
http://www.fsf.org/register_form?referrer=3D9429
http://www.fsf.org/about
"The Free Software Foundation (FSF) is a nonprofit with a worldwide
mission to promote computer user freedom and to defend the rights of all
free software users."


--UweLakvJwHkZQPp0vg9tDDc0Cmpz7ad6T--

--7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQJWBAEBCABAFiEEymnV/lrtCqpNhpze13JsPqr44+8FAltazi4iHG1pY2hhZWwu
ZG9ycmluZ3RvbkBtZW1iZXIuZnNmLm9yZwAKCRDXcmw+qvjj7zpRD/9pnEHO4uck
hY1MmvcfXyEaEby6TwKZMaIznt5CCIgxDEJbLuwg1L9BqtEGhWoBxP6Lmo+yxy0u
SYyESrsWpviOqtkGCfU70rzgvopQNiJSdWsIaHLWE4vW5P46c1e3K6XeUJpQf5xi
hPKPXuSKfJkL8dMOcq5mfZA0MYpX6BKvOSMbdlW67IPI5Q/2jBlrCdko67seZdVs
3HTdi8DU6EPvT3fCINDvJbtJs9zP5Lqi8kIuixcKrZ+o6P848opotC68k9fITQEM
EQhwBAI3ODjSb5urrinsNqvx2YeuvsaS7ffqKvRjpid+Smn7E48zIxlzPCZKfEuT
GFmOhvFe2CRWkjzI/EeYh2dfvddiouMeaN0sCXO0e94MeI6NKJAsNIMr699QbLhs
gYT0BhWF3R9INbMoZaXrF0GRkmt76D7tgeb3bf+FLFveG2/KVbrqzWrZ3Py5N6BP
eXWk346G9Kek6cdarWPLKUrLX7kSb8dUiK/wsfDEGDCAw9N2vUPt+v5sFHTEMMdY
s4TjHKzZjqUbQ2LUnf/7i5e/Au1PYACFTfv/7phlZTbl3Y+DdAfuJgHW+uhtzBvf
+6j9iaitWF5i+fPqioWAwZ1529Z3BuY1PED2T7R7JfglKDT6heflI9TxkYgfBpID
vvfz7Opvg3sGQw0haiak6dw2vZwEqPBGvw==
=iVBR
-----END PGP SIGNATURE-----

--7VlR1IuPWqk4mBthdV31ZhqdITAVgBMV8--


--===============5645881219985993687==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Fsuk-manchester mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/fsuk-manchester

--===============5645881219985993687==--