4 Sep 2004 00:43
Re: gbde blackening feature - how can on disk keys be "destroyed" thoroughly?
David Kreil <kreil <at> ebi.ac.uk>
2004-09-03 22:43:56 GMT
2004-09-03 22:43:56 GMT
Hi, >From what I can see so far, they are simply overwritten with zeros - is that right? If so, the blackening feature would be much weakend, as once can read up to 20 layers of data even under random data (and more under zeros). I would be most grateful for comments, or suggestions of where/how one could extend the code to do a secure wip of the key areas. Also, I know practically nothing of how I could to best get FreeBSD to physically write to disk (configurability of hardware cache etc permitting). With best regards, David. > > Hello, > > I was wondering whether someone knowledgable about gbde internals could tell > me how the keys are being destroyed on request under the "blackening feature". > Ideally, I'd like them to be overwritten with random data at least 20 times > independently, but I suspect it may well be done in a different way. I'd be > grateful for learning how the blackening works (and why!). > > With many thanks for your help in advance, > > David Kreil. > ------------------------------------------------------------------------(Continue reading)
I guess my main point is: If there is a blackening feature which is designed
to give users peace of mind about disclosing their password under pressure,
and it is known that data can be recovered underneath simple overwrites for a
RSS Feed