tech-security archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: cgd and remote keys




To: tech-security%netbsd.org@localhost

Subject: Re: cgd and remote keys

From: "Martin J. Laubach" <mjl%NetBSD.org@localhost>

Date: Fri, 4 Jan 2008 13:31:23 +0000 (UTC)


|  Just additional note, it is possible to store /etc/cgd/* content on usb
|  memory, already tested. You just need to add a line into /etc/fstab. 

  I was thinking about that (keeping local data safe yet not be a
hassle on every reboot) some time ago and came up with three variants:

  - an USB storage on a cable, reasonably secured (ie. bolted to the
    wall, so an attacker is more likely to just plug it off)
  - a bluetooth device for key storage that could be hidden/securely
    mounted somewhere nearby the server
  - a remote server that only responds to the expected IP address
    (which causes pain when your internet connection goes down)

  Additional brownie points given for auto-destruction which seems
necessary wrt recent legislation in certain parts of the world ("Sorry,
I don't have the key, your [law enforcement] agents destroyed it when
they confiscated the server").

  Cheers,

        mjl




Follow-Ups:

Re: cgd and remote keys
From: Gavan Fantom


References:

Re: cgd and remote keys
From: Cem Kayali




Prev by Date: Re: cgd and remote keys

Next by Date: Re: cgd and remote keys

Previous by Thread: Re: cgd and remote keys

Next by Thread: Re: cgd and remote keys

Indexes:

reverse Date

reverse Thread

Old Index



Home | Main Index | Thread Index | Old Index