Re: faq8.html#LostPW

Tomas Bodzar <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <CAK3FJdktef=LHBsvm2Jz_b_Yypt9x0JdXUQDM9oZePdrjiHwnQ@mail.gmail.com>
On Sun, Jun 24, 2012 at 9:07 AM, rustyBSD <[email protected]> wrote:
> Le 24/06/2012 07:59, Nick Holland a écrit :
>> On 06/23/12 17:43, rustyBSD wrote:
>>> Hi,
>>> "If an attacker has physical access to your system, they win, regardless
>>> of the OS on the computer."
>>> NO. Some Linux distribs can have a full disk encryption.
>> "NO.  I have a blue car"
>> what you have said is about as relevant.  See, I don't drive the blue
>> car much, so I've mislead you because my daily drivers aren't blue, thus
>> my cars are now 100% safe, right?
>> Oh, doesn't work that way?  Right.  it doesn't.
>>
>> If an attacker has physical access to your system, they win.  If you
>> don't believe me, let me at your computer for a while, preferably while
>> you aren't aware I'm there.   Hint: the bad guys don't attack you in the
>> way you hope, they attack in the way that works.
>>
>> Where I work, someone posted a picture of Darth Vader saying, "I find
>> your lack of encryption disturbing" (Google for it, I thought it was an
>> original, but apparently not).  Some people are very fond of encryption,
>> thinking it equals security.
>> I wish my art skills were a little better, I'd add a picture of a
>> pimple-faced cracker crouched over his keyboard saying, "I find your
>> trust in encryption amusing".
>>
>> Encryption is important, but it is a tiny part of the security puzzle,
>> and usually when it is the first thing people mention, they are missing
>> not only many of the pieces, but also the shape and size of the puzzle
>> (no, that's not a puzzle of daisy, that's a puzzle of a vast landscape,
>> but there is a daisy in it)
>>
>>> Instead of telling "they win", it should be better to tell something
>>> like: "OpenBSD doesn't support
>>> full disk encryption, but you can use vnconfig(8) to crypt a non-root
>>> partition."
>> vnconfig? we got softraid.
>>
>> Nick.
>>
> That reminds me the 'SERIOUS BUSINESS' video.
>
> Look. A guy come and try to access your data. He can't ?
> Mmmhh... That's what you think ! There are a lot of ways
> to get data. For example, he can sell his soul to the devil
> in exchange for your data and power (!) (and money
> and poney), like Faust. Or he can ask Jesus to tell him
> your password ! So, your data aren't secure.
>
> That's what you're telling me.

No, that's not what we are telling ;-) We are telling that it's not
only about encrypting partition like without that you will not have
security (which a lot of other OSs try to pretend). In OpenBSD there's
a lot of other stuff which tries to protect your data/privacy and that
stuff is not in other OSs or is not turned on by default and even
enabling it much more harder than here.

>
> Sure, our data are NEVER totally secure, but they can be
> more secure than in the past. It's as if you were telling me
> that firewall are useless because of the fact that a KGB spy
> could get physical access to your machine.
>
> Cryptography is as important as firewall. In all cases, encrypt
> data is better than don't encrypt data.
>
> This is me, and I could be wrong, maybe physical access is
> a terrible tragedy.

Sure, that's why security is about protecting physical access as well.

>
> Maxime.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.