Vulnerability with compromised geli credentials?




I'm not really a developer, but was considering if there is a key
vulnerability in geli given that when you change a key there isn't a disk
update.

Consider the scenario where a new file system is created and populated
with some files. At a later time the original key is changed because
someone has gained access to the key and passphrase. A new key is
generated and attached, but none of the files are modified.

Furthermore, let's say the thief has access to the system and is able to
update the disk to use the previous key and then reattach/mount. Is it
then possible for the person that has the stolen credentials to mount the
drive and view the files? The man page does not detail how the metadata is
written.

With that said, if this is possible, what's the best way to update the
system? I suspect that moving the file is not enough, using vi in a script
is not very practical, and using cat may cause problems with some special
characters.


_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Backup solution suggestions [ggated]
    ... from my end to the remote disk.. ... ZFS on top of it. ... Then I went on do do some geli test, geli'ed /dev/ggate0 and newfs'ed, mounted and played around a bit. ... If I can get that to work, then this would be a kickass solution (all encryption stuff works great, I don't have to allocate all space immediatly, I can expand it later without destroying data and starting from scratch etc). ...
    (freebsd-stable)
  • Re: Vulnerability with compromised geli credentials?
    ... PGP disk encryption products: ... If you possess the Master Key that actually used for the encryption, ... The passphrase you're entering to attach geli volume is ... for the reencryption with new master key is the following: ...
    (FreeBSD-Security)
  • Re: GJournal (hopefully) final patches.
    ... It seems like a reasonably modern controller and disk, ... should be capable of issuing a cache flush command. ... So it's UFS over gjournal over bsdlabel over geli over raid3 over ata. ... effective for large files - geli will not encrypt the data twice. ...
    (freebsd-arch)
  • Re: GJournal (hopefully) final patches.
    ... out on a couple machines to see how it goes. ... It seems like a reasonably modern controller and disk, ... So it's UFS over gjournal over bsdlabel over geli over raid3 over ata. ... effective for large files - geli will not encrypt the data twice. ...
    (freebsd-current)
  • Re: GELI - disk encryption for FreeBSD - review request.
    ... > I'm aware of this and I'm going to do what I can to make geli users ... > The situation geli can protect against is when your laptop is stolen, ... Also I think you're not appreciating the value of doing entire disk ... encryption properly. ...
    (sci.crypt)