mandos
play

Mandos Disk encryption without passwords Teddy Hogeborn, Bjrn - PowerPoint PPT Presentation

Mandos Disk encryption without passwords Teddy Hogeborn, Bjrn Phlsson 2020-01-29 When to use Mandos? 1. Physical/bare metal hardware? 2. More than just one physical machine? 3. Want to use full-disk encryption? You should use Mandos!


  1. Mandos Disk encryption without passwords Teddy Hogeborn, Björn Påhlsson 2020-01-29

  2. When to use Mandos? 1. Physical/bare metal hardware? 2. More than just one physical machine? 3. Want to use full-disk encryption? You should use Mandos!

  3. Don’t already use full-disk encryption? You should!

  4. What is Mandos? One running machine sends password to other rebooting machine Two (or more) machines can keep each other up No interactivity needed ◮ Reboot while you sleep ◮ Kernel upgrade ◮ Kernel panic ◮ Power glitch ◮ Watchdog ◮ etc.

  5. Noninteractivity Vital feature! Set it and forget it; reboot normally

  6. Mandos Features Supports major initramfs image builders: ◮ initramfs-tools ◮ dracut, both with and without systemd Server controllable by D-Bus ◮ D-Bus API fully documented ◮ Command-line utilities provided

  7. But anyone could just. . . No they couldn’t. ◮ TLS-encrypted communication (with PFS) ◮ OpenPGP-encrypted payload

  8. But what if. . . Threat model? ◮ Smash & grab Fails safe!

  9. Threat models (continued) What is your realistic threat model? Mandos will always be better than no encryption!

  10. OK, but in theory, you could. . . Yes, OK, you could. ◮ But again, what is your threat model? Sophisticated attackers? ◮ Could just as well do a cold-boot attack Mandos can ask for manual approval for every boot

  11. Installing Mandos apt install mandos-client Then, read /usr/share/doc/mandos-client/README.Debian.gz apt install mandos Latest version (recommended): Instructions at https://www.recompile.se/mandos

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend