Cryptography

Sandy Harris sandyinchina at gmail.com
Sat Oct 24 09:18:10 UTC 2009


On 10/23/09, David Neeley <dbneeley at gmail.com> wrote:

> This morning, I read that a new security enhancement for the Ubuntu
>  family of Linux operating systems has been launched. Using this, users
>  can encrypt their /home directories--the idea being that stolen
>  laptops and such would be very difficult to use to steal confidential
>  files--generally stored either in /home itself or in a subsidiary
>  directory to it. That sounds like an excellent idea to me.

It is, but like many crypto schemes it is easily subverted if someone
can get into the machine and plant a keystroke logger. The "evil
maid" who tampers with the computer in your hotel is one version
of this scenario.

>  I once worked on a startup--which didn't make it, unfortunately. We
>  were attempting to launch a niche product, but one which has a
>  verifiably uncrackable encryption method--the one-time pad.

There's a good FAQ on those:
http://www.ranum.com/security/computer_security/papers/otp-faq/
See also Schneier's comments:
http://www.schneier.com/crypto-gram-0210.html#7

-- 
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
A: Top-posting.
Q: What is the most annoying thing in e-mail?




More information about the ubuntu-users mailing list