[arch-general] LUKS emergency self-destruct
havoc at defuse.ca
Mon Jan 13 15:48:23 EST 2014
-----BEGIN PGP SIGNED MESSAGE-----
On 01/13/2014 03:57 AM, Paladin wrote:
> Hi, does anyone know if there is plan to implement this:
> http://www.kali.org/how-to/emergency-self-destruction-luks-kali/ in
> Patch https://github.com/offensive-security/cryptsetup-nuke-keys is
> not too big and IMHO it would be great to have this option..
> Patch is for 1.6.1 but it cannot be that difficult to port it to
> 1.6.3 which we have.
If you use this, be careful that you're using it for the right thing.
Unfortunately the way it's implemented makes it seem like it's purpose
is something that it's not.
The intent is for it to be an easy and fast way to destroy the key
information (and optionally recover it if you have a backup), when you
are in a SAFE environment. A convenient alternative to manually doing
it with dd and a live CD.
It's not intended to be an "If I'm tortured I can enter the duress
password and it will destroy the keys" feature. Obviously, your
torturers (or law enforcement (they can be the same thing)), will
clone the disk and make you enter your password into the cloned system.
Just a warning.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
-----END PGP SIGNATURE-----
More information about the arch-general