Re: faq8.html#LostPW

Tobias Ulmer <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <[email protected]>
On Sat, Jun 23, 2012 at 11:43:33PM +0200, rustyBSD wrote:
> Hi,
> "If an attacker has physical access to your system, they win, regardless
> of the OS on the computer."
> NO. Some Linux distribs can have a full disk encryption.

It's not possible to boot an operating system from a fully encrypted
disk without dedicated hardware support. They have "almost full disk
encryption", which is susceptible to replacement of the BIOS, boot
loaders, kernel and initrd depending on the configuration.

TPM, UEFI Secure Boot, USB sticks with built-in crypto, smartcards etc.
may help in some regards. But these hardware systems also depend on
physical security. Key loggers are trivial to install. RF shielding is
non-existent in consumer gear. Camera modules are ridiculously small
these days. Dedicated circuitry sniffing the memory bus or injecting
instructions can be made for little money with a FPGA. Focused ion beam
microscopes are available to students at your local university. The list
goes on and on.

> 
> Instead of telling "they win", it should be better to tell something
> like: "OpenBSD doesn't support
> full disk encryption, but you can use vnconfig(8) to crypt a non-root
> partition."
> 

They win.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.