Re: NFS4 authentification / fsuid

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Kyle Moffett
Date: Thursday, September 6, 2007 - 10:47 pm

On Sep 07, 2007, at 01:14:09, Trond Myklebust wrote:

A fully self-certifying system that can prevent any attack is  
impossible to achieve.  If I have the device and can devote as many  
hours as I want to breaking into it, there is exactly ZERO way to  
prevent that, aside from encrypting things and not giving out the key  
(which sorta makes it useless but is precisely the point of real  
crypto).

There is a HUGE difference between "I don't want the end-user to hack  
into this" and "The end-user wants a certain degree of assurance that  
his data can't be compromised.  In the former case (IE: DRM) you are  
NOT using cryptography because you are giving the user: (A) the data,  
(B) the algorithm, and (C) the key, which means they can decrypt it  
ANY TIME THEY WANT.  In the latter case the attacker DOES NOT have  
the key and virtually all of the attacks forms of "How do I get the  
key?".  The end-user is REQUIRED to provide an appropriate level of  
physical security based on the nature of the data;  If I'm that  
worried about somebody substituting my /boot CD, then I'm going to  
make DAMN sure that I keep it on my person at all times.

So you can't draw any relationships between "Protect the end-user"  
with "Protect the device FROM the end-user", the former can be done  
very reliably to whatever level of risk-reduction you need and the  
latter can't practically be done at all.

Cheers,
Kyle Moffett
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:12 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:29 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:32 am)
Re: NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:42 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 8:04 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 8:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 2:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:14 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:29 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:06 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:11 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:21 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 4:30 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:32 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:35 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 5:56 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 10:14 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 10:47 pm)
Re: NFS4 authentification / fsuid, Bernd Eckenfels, (Thu Sep 6, 11:37 pm)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Fri Sep 7, 8:34 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:12 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:27 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:48 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Tue Sep 18, 10:16 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 5:16 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Wed Sep 19, 6:49 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 7:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Wed Sep 19, 8:01 am)
Re: NFS4 authentification / fsuid, Valdis.Kletnieks, (Wed Sep 19, 9:38 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:03 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:15 am)