Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 27 Jan 2010 14:46:59 +0000
From:      RW <rwmaillists@googlemail.com>
To:        freebsd-questions@freebsd.org
Subject:   Re: Does geli metadata contain sensitive information?
Message-ID:  <20100127144659.59f84863@gumby.homeunix.com>
In-Reply-To: <64c038661001270313v7990c0b9m6dff12504f04cfef@mail.gmail.com>
References:  <64c038661001270313v7990c0b9m6dff12504f04cfef@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 27 Jan 2010 04:13:42 -0700
Modulok <modulok@gmail.com> wrote:

> Does a geli metadata backup contain any sensitive information? Like...
> should apply the same precations as I do the key and password?

If you change the keyfile the metadata is changed and the old keyfile
becomes useless; but if the attacker also has the old metadata file
they can make use of the old keyfile. Likewise if someone has the
metadata you lose the ability to delete all copies of it making
the partition instantaneously unrecoverable.





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20100127144659.59f84863>