Re: Looking for confirmation as I enter the acceptance stage.

Michael Kjörling <[email protected]> Mon, 24 Jul 2023 18:17:28 +0000
Newsgroups dev.linux.lists.cryptsetup
Message-ID <[email protected]>
On 24 Jul 2023 16:03 +0000, from [email protected] (Michael Kjörling):
> I think that there actually just MIGHT be some hope for you. No
> guarantees, but certainly to the point of "don't give up JUST yet".

Well, this is a bit of a bummer.

I did some more testing, and I can't seem to get cryptsetup to accept
the "lukskey" you sent earlier as a key file for an extended version
of the container starting with the header I was able to extract.

This doesn't _have_ to be a showstopper; it's possible that LUKS
simply needs data that's outside of what you've sent, or maybe you've
been using that file differently. (And please think thrice before
sending more; remember, anyone who has a valid key slot passphrase to
a header has access to the plain text data of the container if they
can get their hands on the ciphertext data, and this mailing list _is_
publicly archived. Absolutely do consider that key file compromised,
possibly alongside your other, memorized passphrase for the
container.) But it's somewhat of a downer.

I would still say you have some chance when doing it with more data,
though, so what I suggested previously is absolutely still worth
trying. After all, the extraction I did left only 19823 bytes
including the header signature at the start, which is plenty less than
the canonical size of the full LUKS 1 header.

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”