Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here. |
| Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
|
07-18-2026, 02:44 PM
|
#16
|
|
Member
Registered: Sep 2025
Distribution: Pop!_OS
Posts: 321
Rep: 
|
Quote:
Originally Posted by slackjawedyokel
Hmm well I have low RAM at only 4GB. Running just a single vm and if I forget and open a single browser instance this can lock my machine forcing me to long press the power button to shut it down.
So turning it off completely would not be an option I think.
|
I agree. With only 4GB of RAM, running a VM without swap is bound to cause system freezes. It could theoretically work if your host is idle and you use a lightweight desktop environment without opening multiple browser tabs, but for your use case, disabling swap is probably not practical.
Quote:
Originally Posted by slackjawedyokel
It is emmc for the main one with supplemental sdcard so both kinda ssd?
|
Yes, they are both forms of flash storage. However, eMMC and SD cards have a higher chance of successful chip-off data recovery than modern SSDs. That said, it is still a highly difficult laboratory feat, and successful data extraction is not guaranteed.
Quote:
Originally Posted by slackjawedyokel
Yes it is low, but still it makes me feel more comfortable to wipe and not have stuff hanging around indefinitely in an unencrypted state. Similar to how probably nothing would happen if you kept all your passwords in an unencrypted text file in your home directory but you still want to encrypt them for mental comfort.
|
This really isn't a fair comparison. If a password is left in plaintext in your home directory, any basic local malware or unauthorized physical user can steal it instantly. Physical chip-off recovery, on the other hand, requires an adversary to physically steal your device, desolder the NAND flash chips, and utilize specialized forensic lab tools costing thousands of dollars.
Furthermore, you shouldn't have highly sensitive data like primary passwords landing in the VM's swap anyway, especially if you are using the VM for basic isolation or testing operating systems. The attack vector you are worried about is completely hypothetical and unrealistic for an average user (and I would argue even for most high-profile targets). Anyone with the resources to pull off hardware-level forensics would just use much cheaper, easier, and more effective attack vectors to compromise your data.
Quote:
Originally Posted by slackjawedyokel
Encrypted swap sounds like a good choice for simple peace of mind.
|
If it gives you peace of mind, go ahead and use it. Just keep in mind that on low-spec hardware such as yours, the added CPU overhead might slightly degrade performance.
|
|
|
1 members found this post helpful.
|
07-18-2026, 02:50 PM
|
#17
|
|
Member
Registered: Jul 2021
Location: Arcadia
Distribution: LFS, (Slackware-15.0 backup)
Posts: 736
Rep: 
|
Quote:
Originally Posted by slackjawedyokel
Hmm well I have low RAM at only 4GB. Running just a single vm and if I forget and open a single browser instance this can lock my machine forcing me to long press the power button to shut it down.
So turning it off completely would not be an option I think.
It is emmc for the main one with supplemental sdcard so both kinda ssd?
Yes it is low, but still it makes me feel more comfortable to wipe and not have stuff hanging around indefinitely in an unencrypted state. Similar to how probably nothing would happen if you kept all your passwords in an unencrypted text file in your home directory but you still want to encrypt them for mental comfort.
Encrypted swap sounds like a good choice for simple peace of mind.
EDIT: Btw, does simply putting the OS to USB stick instead avoid the issue entirely? I guess so, for example with TAILS OS, which is made for that and that is what they say on their advice against using it in a VM, that their security features are meant for VM only. Interestingly I read a thread on whonix forums that it too suffers from these same vulnerabilities but they are not clearly highlighted like they are on TAILS yet that OS is made to run in vms specifically.
The encrypted swap sounds a good solution though in either case if running vm or avoid the issue in the case of TAILS by just running from USB like you are meant to. For my low threat model though firing up a vm is more convenient, with the encryption of swap seems preferable.
Good discussion so far though! I have learned from the replies, similar to the other thread (which viel claims not to have referenced but obviously did but wouldn't admit it, lol).
|
Well encrypt sounds fine because .. depending your SDD
Quote:
|
If it's an SSD, you would have to turn swap off, delete the file, and run fstrim, then recreating the swap file.
|
Will not delete data ...
EDITED: I'm sorry, I admit this is unnecessary. I couldn't resist. I hope you'll accept the joke.
EDITED2: And yes that lasat joke was about you.
EDITED3: @slackjawedyokel I am curious about what are you doing that need delete the swap ... don't do bad things man ...
Last edited by viel; 07-19-2026 at 01:28 AM.
|
|
|
|
07-19-2026, 02:19 AM
|
#18
|
|
Member
Registered: Oct 2025
Posts: 217
Original Poster
Rep:
|
Quote:
Originally Posted by Nirel Gurtesnten
If it gives you peace of mind, go ahead and use it. Just keep in mind that on low-spec hardware such as yours, the added CPU overhead might slightly degrade performance.
|
Then what is your suggestion? just forget about the issue and carry on without encrypting due to low threat level?
|
|
|
|
07-19-2026, 03:24 AM
|
#19
|
|
LQ Addict
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 26,460
|
Quote:
Originally Posted by slackjawedyokel
Then what is your suggestion? just forget about the issue and carry on without encrypting due to low threat level?
|
And why do you think anybody reading this thread won't try to attack you and your host?
The security of your devices depend on you, exactly and only you. Nobody can tell you what is the best for you (but you). Anyway, no solution will be perfect if you don't know what have you made, how does it work and what will it do for you. Security is a continuous activity, not a switch that can be set to on/off. (otherwise it would be on everywhere, and there were no issues).
I explained in my previous post (#8) whatever storage/ram/... you use the security aspects will be almost the same, regardless if it is an rpi, a laptop, or anything else. Also the type of the storage is irrelevant (if it is ssd, disk, sd card or anything else), either you will leave traces or not. (Obviously cleaning these traces may differ).
You can also have swap on another host, in its ram, if you wish, that also may help on slow hosts.
Also, if you overload your host, it won't work properly, no amount of ram/swap/whatever will help it, the only thing that will help is if you simply don't do it.
And one more thing: no matter how you protect your swap/storage/RAM, if there's a way to collect your important data without them due to another vulnerability, you're lost. No matter how well you protect them.
|
|
|
1 members found this post helpful.
|
07-19-2026, 06:55 AM
|
#20
|
|
Member
Registered: Sep 2025
Distribution: Pop!_OS
Posts: 321
Rep: 
|
Quote:
Originally Posted by slackjawedyokel
Then what is your suggestion? just forget about the issue and carry on without encrypting due to low threat level?
|
I suggested that if encrypting your swap gives you peace of mind, you should go ahead and test it out.
You won't truly know the CPU overhead cost until you try it yourself.
However, if you are already using Full Disk Encryption, which is far more critical than just encrypting swap, then your swap file is already protected by your drive encryption.
Setting up a separate encryption layer for swap is completely redundant.
If an attacker cannot bypass your primary password, they cannot read your swap.
If they have the physical access and advanced forensic capabilities required to execute chip-level data recovery, separate swap encryption will not stop them anyway.
Perfect security is impossible. It is much more practical to ensure your most common threat vectors are covered first.
If you are worried about risks at the level of swap inspection, I would argue that you would get more real-life security by using the Mullvad Browser or Tor Browser with the safest security settings (which include disabling JavaScript).
Protecting yourself against browser-based exploits defends against a higher common threat vector, even though it breaks most modern websites and harms your browsing experience.
Hardening an unencrypted swap partition, on a physically secure and encrypted machine, would protect against a nearly non-existent threat.
|
|
|
|
07-19-2026, 12:11 PM
|
#21
|
|
Member
Registered: Oct 2025
Posts: 217
Original Poster
Rep:
|
Quote:
Originally Posted by Nirel Gurtesnten
I suggested that if encrypting your swap gives you peace of mind, you should go ahead and test it out.
You won't truly know the CPU overhead cost until you try it yourself.
However, if you are already using Full Disk Encryption, which is far more critical than just encrypting swap, then your swap file is already protected by your drive encryption.
Setting up a separate encryption layer for swap is completely redundant.
If an attacker cannot bypass your primary password, they cannot read your swap.
If they have the physical access and advanced forensic capabilities required to execute chip-level data recovery, separate swap encryption will not stop them anyway.
Perfect security is impossible. It is much more practical to ensure your most common threat vectors are covered first.
If you are worried about risks at the level of swap inspection, I would argue that you would get more real-life security by using the Mullvad Browser or Tor Browser with the safest security settings (which include disabling JavaScript).
Protecting yourself against browser-based exploits defends against a higher common threat vector, even though it breaks most modern websites and harms your browsing experience.
Hardening an unencrypted swap partition, on a physically secure and encrypted machine, would protect against a nearly non-existent threat.
|
We still haven't really explored what is actually in this mysterious leftover stuff in the swap? What exactly are the contents going to be? the whole browser sessions text files and such in plain view for anyone to see somehow or what?
Also what about how long it hangs out in there if not encrypted.
As I noted threat level is low but also spare resources on this machine are low too so it is whether it is worth doing anything at all for it? I mean even if they hang around indefinitely it is extremely unlikely anyone will ever see them anyway right?
I am not doing anything immoral or reprehensible I can say that.
If I was doing anything I thought was very bad with considerable consequences I wouldn't have made the post on a public forum to begin with.
Not clear about your Tor browser recommendation? That would be run in whatever vm/distro as standard.
Last edited by slackjawedyokel; 07-19-2026 at 12:24 PM.
|
|
|
|
07-19-2026, 12:36 PM
|
#22
|
|
Member
Registered: Jul 2021
Location: Arcadia
Distribution: LFS, (Slackware-15.0 backup)
Posts: 736
Rep: 
|
Quote:
Originally Posted by slackjawedyokel
We still haven't really explored what is actually in this mysterious leftover stuff in the swap? What exactly are the contents going to be? the whole browser sessions text files and such in plain view for anyone to see somehow or what?
Also what about how long it hangs out in there if not encrypted.
As I noted threat level is low but also spare resources on this machine are low too so it is whether it is worth doing anything at all for it? I mean even if they hang around indefinitely it is extremely unlikely anyone will ever see them anyway right?
I am not doing anything immoral or reprehensible I can say that.
If I was doing anything I thought was very bad with considerable consequences I wouldn't have made the post on a public forum to begin with.
Not clear about your Tor browser recommendation? That would be run in whatever vm/distro as standard.
|
Code:
[root@dirty test.mbp]# free
total used free shared buff/cache available
Mem: 32731716 3197640 12085664 183072 18043160 29534076
Swap: 5242876 0 5242876
[root@dirty test.mbp]#
[root@dirty test.mbp]#
[root@dirty test.mbp]# dd if=/dev/zram0 bs=1G count=5 | hexdump -C
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
00000400 01 00 00 00 ff ff 13 00 00 00 00 00 fd 10 00 28 |...............(|
00000410 3c 22 40 74 a0 55 6d 02 a3 c9 41 75 00 00 00 00 |<"@t.Um...Au....|
00000420 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
00000ff0 00 00 00 00 00 00 53 57 41 50 53 50 41 43 45 32 |......SWAPSPACE2|
00001000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
5+0 records in
5+0 records out
5368709120 bytes (5.4 GB, 5.0 GiB) copied, 10.568 s, 508 MB/s
140000000
[root@dirty test.mbp]#
EDITED: DIY  enjoy..
Last edited by viel; 07-19-2026 at 12:37 PM.
|
|
|
|
07-19-2026, 01:27 PM
|
#23
|
|
LQ Guru
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 7,126
|
Quote:
Originally Posted by slackjawedyokel
Hmm why is it called zswap, just because it is compressed? As above I have only 4GB so I was also looking to increase my swap files so while looking to encrypt I may look to increase as well.
|
You would have to ask the team. They named their utilities ZRAM and ZSWAP. I suggest you look them up and consider carefully, but they may either solve a problem for you or provide a more secure environment. Not, on a limited resource machine I would be very reluctant to run both at the same time. To secure your swap (and speed it up) use ZSWAP. To compress RAM and get more out of it, try ZRAM. Not both at once.
Quote:
|
The base emmc only has 4GB but I have not used the 256GB sdcard hardly at all so have many GB to play with there.
|
What is your CPU? Any time you talk about encryption, you must consider available FLOPS and how the encryption will load the CPU. Most modern (X86*) CPUs (and more significantly modern GPUs that can be leveraged to provide the crypt processing) handle a LOT. Some of the new lower power options can have load issues.
If you have the cycles, and want security, it pays to make it easy, transparent, and unbreakable. It also pays to be an unappealing target so criminal breakers will simply not bother with you. We do not all have those choices, but...
Last edited by wpeckham; 07-19-2026 at 01:30 PM.
|
|
|
2 members found this post helpful.
|
07-19-2026, 01:32 PM
|
#24
|
|
Member
Registered: Oct 2025
Posts: 217
Original Poster
Rep:
|
WTF!? it is an evidence you are hacking my machine!?
Quote:
Originally Posted by viel
Code:
[root@dirty test.mbp]# free
total used free shared buff/cache available
Mem: 32731716 3197640 12085664 183072 18043160 29534076
Swap: 5242876 0 5242876
[root@dirty test.mbp]#
[root@dirty test.mbp]#
[root@dirty test.mbp]# dd if=/dev/zram0 bs=1G count=5 | hexdump -C
00000000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
00000400 01 00 00 00 ff ff 13 00 00 00 00 00 fd 10 00 28 |...............(|
00000410 3c 22 40 74 a0 55 6d 02 a3 c9 41 75 00 00 00 00 |<"@t.Um...Au....|
00000420 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
00000ff0 00 00 00 00 00 00 53 57 41 50 53 50 41 43 45 32 |......SWAPSPACE2|
00001000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
*
5+0 records in
5+0 records out
5368709120 bytes (5.4 GB, 5.0 GiB) copied, 10.568 s, 508 MB/s
140000000
[root@dirty test.mbp]#
EDITED: DIY  enjoy..
|
|
|
|
|
07-19-2026, 09:06 PM
|
#25
|
|
Member
Registered: Jul 2021
Location: Arcadia
Distribution: LFS, (Slackware-15.0 backup)
Posts: 736
Rep: 
|
Quote:
Originally Posted by slackjawedyokel
WTF!? it is an evidence you are hacking my machine!?
|
It is evidence of how one can inspect one's own swap...
If your swap is not in RAM (like mine) you can inspect it by changing to the correct device...
EDITED: https://www.torproject.org/download/
Last edited by viel; 07-19-2026 at 09:18 PM.
|
|
|
|
All times are GMT -5. The time now is 06:27 PM.
|
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|