New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cryptsetup Nuke Keys Patch #921

Open
marmarek opened this Issue Mar 8, 2015 · 4 comments

Comments

Projects
None yet
2 participants
@marmarek
Member

marmarek commented Mar 8, 2015

Reported by anonymous on 9 Nov 2014 21:03 UTC
Feature Request: Cryptsetup Nuke Keys Patch

Upstream Provider: Kali Linux

Kali Linux webpage: kali.org

Nuke Keys Git Repo: https://github.com/offensive-security/cryptsetup-nuke-keys

Arch Linux AUR package: https://aur.archlinux.org/packages/cryptsetup-nuke-keys/

Where: dom0

Purpose: Allows user to erase keyslots using an alternate "nuke" password.
Easier than other erasure methods.
Does not require input of decryption password.
Resistant to user error via overwriting non-keyslot data using alternate erasure methods.

How: User chooses a 'nuke' passphrase.
Upon using nuke passphrase, all keyslots are wiped, rendering drive unusable.
Keyslots can be restored later using keyslot backups.

Note: May require modification from original files to work.

Migrated-From: https://wiki.qubes-os.org/ticket/921

@marmarek

This comment has been minimized.

Show comment
Hide comment
@marmarek

marmarek Mar 8, 2015

Member

Modified by marmarek on 11 Nov 2014 02:44 UTC

Member

marmarek commented Mar 8, 2015

Modified by marmarek on 11 Nov 2014 02:44 UTC

@marmarek marmarek added this to the Release 3 milestone Mar 8, 2015

@marmarek

This comment has been minimized.

Show comment
Hide comment
@marmarek

marmarek Mar 8, 2015

Member

Comment by John on 2 Dec 2014 05:53 UTC
The pros and cons are described in section 5.21 of the official FAQ of the cryptsetup project:

https://github.com/mbroz/cryptsetup/blob/master/FAQ

In short: it fails to increase security to any significant degree.

Member

marmarek commented Mar 8, 2015

Comment by John on 2 Dec 2014 05:53 UTC
The pros and cons are described in section 5.21 of the official FAQ of the cryptsetup project:

https://github.com/mbroz/cryptsetup/blob/master/FAQ

In short: it fails to increase security to any significant degree.

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Jun 30, 2016

Member

Recent discussion about the usefulness of this feature:
https://groups.google.com/d/topic/qubes-users/1Qu0v2b7-bg/discussion

Member

andrewdavidwong commented Jun 30, 2016

Recent discussion about the usefulness of this feature:
https://groups.google.com/d/topic/qubes-users/1Qu0v2b7-bg/discussion

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment