login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
openbsd-misc
»
2008
»
October
»
30
Re: new home box for secure data storage
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: Felipe Alfaro Solana
Subject:
Re: new home box for secure data storage
Date: Thursday, October 30, 2008 - 3:53 am
On Wed, Oct 29, 2008 at 9:14 PM, Douglas A. Tutty <dtutty@vianet.ca> wrote:
quoted text
> I'll be setting up a new box for the house and I want to use OpenBSD for > it, both for its security and since it will be an older box it will run > better than with Debian. > > Roles: > > main firewall for dialup internet access. > fetchmail and sendmail to ISP smarthost > other simple stuff (have another box for insecure stuff like watching > videos, surfing the net with javascript and flash). > > > We've moved and now our main security threat is physical security. We > don't want the data on the computer (i.e. in the /home directories) to > be readable if someone steals the box. > > I'm thinking I could go two routes: > > 1. encrypt all of /home with an encrypted virtualfs file. However, > then the data is unencrypted whenever the box is powered on.
Is your data that important? :)
quoted text
> 2. I wonder if there's a way to have per-user home directory > encryption so that the user's directory is accessed/unencrypted/mounted > (whatever the semantics) on login and recrypted/unmounted on logout. > > Have swap and /tmp encrypted too. Also, perhaps per-user $TMP > directories if go with plan 2, above. > > I think I want root to be able to mount/access the directories so that > the data can be included in a backup set (which is then piped through > openssl for encryption) on a file-by-file basis rather than just backing > up a filesystem image and risking the whole thing if that image becomes > corrupted. > > Ideas? What do others do to secure /home? I read on undeadly an idea > of putting the /home filesystem on a removable drive and putting it into > a safe but then you have to have the safe mounted securely. > > Doug. > >
--
http://www.felipe-alfaro.org/blog/disclaimer/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
new home box for secure data storage
, Douglas A. Tutty
, (Wed Oct 29, 1:14 pm)
Re: new home box for secure data storage
, Almir Karic
, (Wed Oct 29, 1:41 pm)
Re: new home box for secure data storage
, STeve Andre'
, (Wed Oct 29, 1:59 pm)
Re: new home box for secure data storage
, Ted Unangst
, (Wed Oct 29, 2:56 pm)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Wed Oct 29, 6:41 pm)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Wed Oct 29, 6:45 pm)
Re: new home box for secure data storage
, patric conant
, (Wed Oct 29, 7:09 pm)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Wed Oct 29, 7:27 pm)
Re: new home box for secure data storage
, Guido Tschakert
, (Thu Oct 30, 12:38 am)
Re: new home box for secure data storage
, Michiel van Baak
, (Thu Oct 30, 1:34 am)
Re: new home box for secure data storage
, Felipe Alfaro Solana
, (Thu Oct 30, 3:53 am)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Thu Oct 30, 7:40 am)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Thu Oct 30, 7:44 am)
Re: new home box for secure data storage
, Douglas A. Tutty
, (Thu Oct 30, 7:45 am)
Re: new home box for secure data storage
, eric-list-openbsd-misc
, (Thu Oct 30, 8:59 am)
Re: new home box for secure data storage
, new_guy
, (Fri Oct 31, 5:01 pm)
Navigation
Create content
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Paul Turner
[tg_shares_up rewrite v4 11/11] sched: update tg->shares after cpu.shares write
Mr. James W. Laferriere
Re: Linux 2.6.25-rc1 , syntax error near unexpected token `;'
Linus Torvalds
Linux 2.6.34-rc4
Colin Cross
[PATCH 12/21] ARM: tegra: Add suspend and hotplug support
Chuck Ebbert
Re: PCI: Unable to reserve mem region problem
git
:
Ralf Wildenhues
[PATCH] Fix typos in the documentation
Wink Saville
How-to combine several separate git repos?
Denis Bueno
Git clone error
pradeep singh
git-update-server-info may be required,cannot clone and pull from a remote reposit...
Steven Grimm
Re: Git User's Survey 2007 unfinished summary continued
linux-netdev
:
Jamie Lokier
Re: POHMELFS high performance network filesystem. Transactions, failover, performa...
Kurt Van Dijck
Re: [PATCH net-next-2.6 1/2] can: add driver for Softing card
Jarek Poplawski
Re: socket api problem: can't bind an ipv6 socket to ::ffff:0.0.0.0
David Miller
Re: [PATCH v2] net: typos in comments in include/linux/igmp.h
Eric Dumazet
Re: [PATCH net-next-2.6] net: Introduce skb_orphan_try()
git-commits-head
:
Linux Kernel Mailing List
ASoC: fix registration of the SoC card in the Freescale MPC8610 drivers
Linux Kernel Mailing List
drivers/acpi: use kasprintf
Linux Kernel Mailing List
nfsd41: sanity check client drc maxreqs
Linux Kernel Mailing List
bnx2x: Moving includes
Linux Kernel Mailing List
Linux 2.6.26-rc3
openbsd-misc
:
Sevan / Venture37
Re: This is what Linus Torvalds calls openBSD crowd
Netmaffia.hu
Tini Lányok AKCIÓBAN OTTHON
Siju George
This is what Linus Torvalds calls openBSD crowd
Darrin Chandler
Re: OT: Python (was Re: vi in /bin)
frantisek holop
Re: splassert: vwakeup: and friends
Colocation donated by:
Syndicate