LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-23-2013, 12:57 PM   #1
jimbo1954
Member
 
Registered: Oct 2006
Location: High Wycombe, Bucks, UK.
Distribution: Debian and Fedora Core in equal measure
Posts: 264

Rep: Reputation: 33
Question Securing an SDHC card by Encryption


Simple question, probably a hard answer

I have a small headless Linux wheezy system running off an SDHC card.

It's too easy to "borrow" an SDHC and copy it and I want to keep my files secure...

Is there any way I can encrypt the software on the SDHC using something like the Ethernet MAC address or some other system-unique string as the key, with no need to enter a passphrase (which I can't easily do because its a headless rig)?

Alternatively, is there some kind of active socket encryption device I can place between the SDHC card and its system socket, or some other way of doing this I haven't thought of?
 
Old 08-24-2013, 04:04 PM   #2
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
Quote:
Originally Posted by jimbo1954 View Post
Simple question, probably a hard answer

I have a small headless Linux wheezy system running off an SDHC card.

It's too easy to "borrow" an SDHC and copy it and I want to keep my files secure...

Is there any way I can encrypt the software on the SDHC using something like the Ethernet MAC address or some other system-unique string as the key, with no need to enter a passphrase (which I can't easily do because its a headless rig)?

Alternatively, is there some kind of active socket encryption device I can place between the SDHC card and its system socket, or some other way of doing this I haven't thought of?
The easy answer is yes ..and no.

You can easily encrypt the card using LUKS as if it were any other storage device. What you need to do is rather than using a passphrase (thought setting one up is a wise backup) you need to use a keyfile. Since you want this standalone, and immune to local theft, the keyfile source will need to reside on a separate system, for example another server accessible over the network. This will require setting the system up so that it boots and is network ready before starting the decryption process.

For the second you're back to remotely locating the key device since you are trying to prevent local theft/intrusion while maintaining remote startup.

One way around all of it is to have the machine boot the necessary system software and then mount a remote encrypted volume thus separating the secured data from the potentially vulnerable server itself.
 
1 members found this post helpful.
Old 08-26-2013, 03:49 PM   #3
jimbo1954
Member
 
Registered: Oct 2006
Location: High Wycombe, Bucks, UK.
Distribution: Debian and Fedora Core in equal measure
Posts: 264

Original Poster
Rep: Reputation: 33
Thanks for the Help!

Your suggestion of LUKS was enough to get me started, and now I've found a LUKS howto, so I'm off and running!

Many Thanks!
 
  


Reply

Tags
linux encryption



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Problems with openSUSE 11.1 recognizing Dazzle* Multi-Card reader and 8G SDHC card chubbs Linux - Newbie 0 02-20-2010 10:49 PM
problem in reading my SDHC card ! beta-tester Linux - Hardware 1 09-28-2009 08:44 PM
SD card reader doesn't recognize 8 gig SDHC card crystaldon Linux - Software 4 07-12-2009 08:05 AM
Unable to see 16 sdhc card in card reader craigevil Linux - Hardware 1 02-18-2009 05:25 PM
How do I clone a 4Gb SDHC Card to another 4Gb SDHC Card lothario Linux - Software 3 07-22-2008 09:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration