Bug 445641
| Summary: | RFE for removal and rethinking/rewrite of ask for password on encrypted partition dialog box | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Jóhann B. Guðmundsson <johannbg> |
| Component: | anaconda | Assignee: | David Lehman <dlehman> |
| Status: | CLOSED WONTFIX | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | rawhide | CC: | poelstra |
| Target Milestone: | --- | Keywords: | FutureFeature |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Enhancement | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2008-09-30 19:50:38 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Jóhann B. Guðmundsson
2008-05-08 08:40:28 UTC
bug 441018 is the originator of this RFE. As it happens, we are leaning in the other direction. We are moving to a single passphrase for all encrypted block devices within a given system. We are also encouraging users to add this passphrase to their pre-existing encrypted block devices to establish a system-wide passphrase. This can actually increase security since you can use a passphrase which is a great deal stronger (and therefore harder to remember) than you could if you had to remember five separate passphrases. 1. Could you elaborate how the security experts at redhat came to the conclusion that having a single passphrase for all your partions is securer then having a different passphrase on multiple partitions? Logic tells me that it would be harder and more secure to encrypt each partition separately with different password as in if one password on one partition is cracked the other partition would not be compromised? ( or atleast would slow down the cracker ) 2. Would it not then be better to support multiple passphrases ( For those of us that do not agree ) but recommend the single passphrase ( followed by a little info in the release notes on how you came to that conclusion ) hence serve both parties? I already explained that by having only one passphrase you can make it a stronger passphrase since you only have to remember one. If you insist on having different passphrases for different devices you can accomplish this with kickstart. You just supply a passphrase for each device instead of only one of them. Well atleast it has been confirmed that this is not coming from the security experts @ Redhat nor do I seriously doubt it that they would even suggest what your saying here. 1xtime strong pass phrases never beats 5xtimes 5xdifferent strong pass phrases. If the anaconda team does not have the time nor the resources to address this issue it's better to say so rather coming up with such an flawed logic. Unless this is an order from certain agency's. ( And the plot gets thicker.. ) I'm not insisting on anything I was merely pointing out to server both parties. |