Re: faq8.html#LostPW
Tomas Bodzar <[email protected]>
| Newsgroups | gmane.os.openbsd.www |
|---|---|
| Message-ID | <CAK3FJdktef=LHBsvm2Jz_b_Yypt9x0JdXUQDM9oZePdrjiHwnQ@mail.gmail.com> |
On Sun, Jun 24, 2012 at 9:07 AM, rustyBSD <[email protected]> wrote: > Le 24/06/2012 07:59, Nick Holland a écrit : >> On 06/23/12 17:43, rustyBSD wrote: >>> Hi, >>> "If an attacker has physical access to your system, they win, regardless >>> of the OS on the computer." >>> NO. Some Linux distribs can have a full disk encryption. >> "NO. I have a blue car" >> what you have said is about as relevant. See, I don't drive the blue >> car much, so I've mislead you because my daily drivers aren't blue, thus >> my cars are now 100% safe, right? >> Oh, doesn't work that way? Right. it doesn't. >> >> If an attacker has physical access to your system, they win. If you >> don't believe me, let me at your computer for a while, preferably while >> you aren't aware I'm there. Hint: the bad guys don't attack you in the >> way you hope, they attack in the way that works. >> >> Where I work, someone posted a picture of Darth Vader saying, "I find >> your lack of encryption disturbing" (Google for it, I thought it was an >> original, but apparently not). Some people are very fond of encryption, >> thinking it equals security. >> I wish my art skills were a little better, I'd add a picture of a >> pimple-faced cracker crouched over his keyboard saying, "I find your >> trust in encryption amusing". >> >> Encryption is important, but it is a tiny part of the security puzzle, >> and usually when it is the first thing people mention, they are missing >> not only many of the pieces, but also the shape and size of the puzzle >> (no, that's not a puzzle of daisy, that's a puzzle of a vast landscape, >> but there is a daisy in it) >> >>> Instead of telling "they win", it should be better to tell something >>> like: "OpenBSD doesn't support >>> full disk encryption, but you can use vnconfig(8) to crypt a non-root >>> partition." >> vnconfig? we got softraid. >> >> Nick. >> > That reminds me the 'SERIOUS BUSINESS' video. > > Look. A guy come and try to access your data. He can't ? > Mmmhh... That's what you think ! There are a lot of ways > to get data. For example, he can sell his soul to the devil > in exchange for your data and power (!) (and money > and poney), like Faust. Or he can ask Jesus to tell him > your password ! So, your data aren't secure. > > That's what you're telling me. No, that's not what we are telling ;-) We are telling that it's not only about encrypting partition like without that you will not have security (which a lot of other OSs try to pretend). In OpenBSD there's a lot of other stuff which tries to protect your data/privacy and that stuff is not in other OSs or is not turned on by default and even enabling it much more harder than here. > > Sure, our data are NEVER totally secure, but they can be > more secure than in the past. It's as if you were telling me > that firewall are useless because of the fact that a KGB spy > could get physical access to your machine. > > Cryptography is as important as firewall. In all cases, encrypt > data is better than don't encrypt data. > > This is me, and I could be wrong, maybe physical access is > a terrible tragedy. Sure, that's why security is about protecting physical access as well. > > Maxime.