Re: Announcing crypto suspend

From: Pavel Machek
Date: Mon Mar 20 2006 - 15:32:41 EST


On Po 20-03-06 21:26:23, Rafael J. Wysocki wrote:
> Hi,
>
> On Monday 20 March 2006 20:11, Alon Bar-Lev wrote:
> > Rafael J. Wysocki wrote:
> > > and please read the HOWTO. Unfortunately the RSA-related part hasn't been
> > > documented yet, but it's pretty straightforward.
> >
> > Hello,
> >
> > I don't understand why you are working so hard on this... If
> > you want encryption, you should care about all of your data!
>
> I hope you realize there may be sensitive data in the suspend image
> that are not stored in filesystems (eg. crypto keys, passwords etc.).

If you have your swap partition on encrypted filesystem, that may
actually work okay.

OTOH uswsusp _destroys_ data after resume. Even if you are forced to
reveal your passphrase later, it should not be possible to recover
data from swsusp image.
Pavel
--
Picture of sleeping (Linux) penguin wanted...
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/