Re: faq8.html#LostPW

rustyBSD <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <[email protected]>
Le 24/06/2012 07:59, Nick Holland a écrit :
> On 06/23/12 17:43, rustyBSD wrote:
>> Hi,
>> "If an attacker has physical access to your system, they win, regardless
>> of the OS on the computer."
>> NO. Some Linux distribs can have a full disk encryption.
> "NO.  I have a blue car"
> what you have said is about as relevant.  See, I don't drive the blue
> car much, so I've mislead you because my daily drivers aren't blue, thus
> my cars are now 100% safe, right?
> Oh, doesn't work that way?  Right.  it doesn't.
>
> If an attacker has physical access to your system, they win.  If you
> don't believe me, let me at your computer for a while, preferably while
> you aren't aware I'm there.   Hint: the bad guys don't attack you in the
> way you hope, they attack in the way that works.
>
> Where I work, someone posted a picture of Darth Vader saying, "I find
> your lack of encryption disturbing" (Google for it, I thought it was an
> original, but apparently not).  Some people are very fond of encryption,
> thinking it equals security.
> I wish my art skills were a little better, I'd add a picture of a
> pimple-faced cracker crouched over his keyboard saying, "I find your
> trust in encryption amusing".
>
> Encryption is important, but it is a tiny part of the security puzzle,
> and usually when it is the first thing people mention, they are missing
> not only many of the pieces, but also the shape and size of the puzzle
> (no, that's not a puzzle of daisy, that's a puzzle of a vast landscape,
> but there is a daisy in it)
>
>> Instead of telling "they win", it should be better to tell something
>> like: "OpenBSD doesn't support
>> full disk encryption, but you can use vnconfig(8) to crypt a non-root
>> partition."
> vnconfig? we got softraid.
>
> Nick.
>
That reminds me the 'SERIOUS BUSINESS' video.

Look. A guy come and try to access your data. He can't ?
Mmmhh... That's what you think ! There are a lot of ways
to get data. For example, he can sell his soul to the devil
in exchange for your data and power (!) (and money
and poney), like Faust. Or he can ask Jesus to tell him
your password ! So, your data aren't secure.

That's what you're telling me.

Sure, our data are NEVER totally secure, but they can be
more secure than in the past. It's as if you were telling me
that firewall are useless because of the fact that a KGB spy
could get physical access to your machine.

Cryptography is as important as firewall. In all cases, encrypt
data is better than don't encrypt data.

This is me, and I could be wrong, maybe physical access is
a terrible tragedy.

Maxime.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.