From mandos at recompile.se Sun Nov 6 03:41:45 2011 From: mandos at recompile.se (Mandos Maintainers) Date: Sun, 06 Nov 2011 03:41:45 +0100 Subject: FreedomBox with encrypted filesystem Message-ID: <87sjm2otue.fsf@tower.recompile.se> We watched the video of your talk at Elevate 2011, which was very interesting. In it, you said "[...], if we do encrypt the filesystem, then the thing cannot be rebooted remotely, which is a downside." We would like to point out that we have written, starting in 2007, a program called "Mandos", which fixes this problem. The program is made specifically for Debian and is in the official Debian distribution. In short, it uses the local network to get the disk password, over an encrypted channel. (Conceptually, this transforms the password from something you *know* into something you *have*.) Depending on your setup, you can have most of the convenience of unencrypted disks with most of the security of encrypted disks; for details, see the manual: http://www.recompile.se/mandos/man/intro.8mandos The Mandos website: http://www.recompile.se/mandos /Teddy Hogeborn & Bj?rn P?hlsson -- The Mandos Project http://www.recompile.se/mandos -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 221 bytes Desc: not available URL: From vasile at freedomboxfoundation.org Mon Nov 7 03:44:40 2011 From: vasile at freedomboxfoundation.org (James Vasile) Date: Sun, 06 Nov 2011 21:44:40 -0500 Subject: FreedomBox with encrypted filesystem In-Reply-To: <87sjm2otue.fsf@tower.recompile.se> References: <87sjm2otue.fsf@tower.recompile.se> Message-ID: <87ehxkwt0n.fsf@wyzanski.jamesvasile.com> Excellent! Thanks much for the tip. One reason I give talks like that is so people tell me I'm wrong in just this way! I'll pass this on to your dev folks. Best, James