cryptsetup FAQ - clarification of loop device security guarantees
forbytten <[email protected]> Thu, 06 Feb 2025 09:04:02 +0000
| Newsgroups | dev.linux.lists.cryptsetup |
|---|---|
| Message-ID | <ECuOkqnIQPivTNgsB2kV-djutsXXEdcFpuE3OKiwaP2ypwzAyrp9kYt_jGMSYZ6jdEkhmIRvX6sSCLMaITA8IHEpDyA2U9K8HCNdEpCoQ0M=@proton.me> |
Hi, In the cryptsetup FAQ, under "2.6 How do I use LUKS with a loop-device?" it states "This can be very handy for experiments". I am seeking clarification of whether the security "guarantees" of such use would still be suitable for production use. I hypothesize they would be, due to: 1. Arno Wagner, FAQ maintainer, seemed to suggest that "high security" use cases are feasible, albeit that was in 2016: https://lore.kernel.org/dm-crypt/[email protected]/ 2. I would expect the threat model of LUKS2/dm-crypt/aes-xts to include the ability of a threat actor to take a block level image of a physical device and attack it offline, which would be equivalent to having a loop device backing file? 3. I would expect a loop device to behave identically to a block device as far as LUKS2/dm-crypt are concerned. Regards, forbytten Sent with Proton Mail secure email.