Page 2 of 2 FirstFirst 12
Results 11 to 12 of 12

Thread: home encryption => long passphrase, login => short passphrase

  1. #11

    Re: home encryption => long passphrase, login => short passphrase

    type in console: ecryptfs-unwrap-passphrase

  2. #12
    Join Date
    Apr 2008
    Location
    Far, far away
    Beans
    2,148
    Distro
    Ubuntu 11.04 Natty Narwhal

    Re: home encryption => long passphrase, login => short passphrase

    @jomex,
    You may want to read here ( http://blog.dustinkirkland.com/2009/...tfs-works.html ) to get more familiar with how ecryptfs works. He has other good artcles about it on his blog.

    I don't think it makes much sense to have a shorter password for sudo than login/ecrypt mounting since anyone gaining sudo access will already have full access to your home directory, assuming it was mounted at boot. They could just copy material to non-home areas for later use.

    If you are serious about security I would recommend using your encrypted home with 2-factor authentication. Use a regular password and a usb flash stick as KEY disk. That blog above also has info on how to set that up and it's very easy. Put one of those tiny usb keys on your key ring so only having both password and key will allow access. I do this when traveling.

    Another nice thing about an encrypted home is that it locks when you suspend or the screen saver kicks in so that you can leave your computer and it will secure itself if you forget - probably the biggest class of vulnerabilities is user forgetfulness / errors.

Page 2 of 2 FirstFirst 12

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •