linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Ahmed Masud <masud@googgun.com>
To: "Jörn Engel" <joern@wohnheim.fh-wedel.de>
Cc: Yoav Weiss <ml-lkml@unpatched.org>,
	Linux Kernel Mailing List <linux-kernel@vger.kernel.org>
Subject: Re: encrypted swap [was: The disappearing sys_call_table export.]
Date: Wed, 14 May 2003 12:38:54 -0400 (EDT)	[thread overview]
Message-ID: <Pine.LNX.4.33.0305141236430.12212-100000@marauder.googgun.com> (raw)
In-Reply-To: <20030514162323.GB16093@wohnheim.fh-wedel.de>

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: TEXT/PLAIN; charset=X-UNKNOWN, Size: 855 bytes --]



On Wed, 14 May 2003, [iso-8859-1] Jörn Engel wrote:

> On Wed, 14 May 2003 12:13:03 -0400, Ahmed Masud wrote:
> >
> > The idea is to have encryption keys for the pages to be unique on a
> > per-uid per-process basis. So one user on the system cannot access (even
> > if they are root) parts of another's private data.  To achieve this,
> > different parts of swap device need to be encrypted with different keys.
>
> How do user *know* that root cannot simply bypass this security?
>
> Root, god, what's the difference? ;-)
>
> Jörn

Well :-) that's sorta true. In the new world the old gods will fall to
give rise to new ones.  worshippers of root will fade in the echos of the
past ... Rootshunting is possible if the kernel so chooses. Trusted Linux,
which is my perosnal and favourite focus for linux would be an environment
without root.


Ahmed.


  parent reply	other threads:[~2003-05-14 16:28 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-05-13 13:58 The disappearing sys_call_table export Yoav Weiss
2003-05-13 22:51 ` Ahmed Masud
2003-05-13 23:58   ` Yoav Weiss
2003-05-14 10:06     ` encrypted swap [was: The disappearing sys_call_table export.] Ahmed Masud
2003-05-14 12:43       ` Yoav Weiss
2003-05-14 14:02         ` Ahmed Masud
2003-05-14 15:12           ` Yoav Weiss
2003-05-14 14:06         ` Ahmed Masud
2003-05-14 15:20           ` Yoav Weiss
2003-05-14 15:57       ` Jörn Engel
2003-05-14 16:13         ` Ahmed Masud
2003-05-14 16:23           ` Jörn Engel
2003-05-14 16:32             ` Ahmed Masud
2003-05-14 16:38             ` Ahmed Masud [this message]
2003-05-14 18:59             ` Yoav Weiss
2003-05-15  7:24               ` Jörn Engel
2003-05-15 10:16                 ` Yoav Weiss
2003-06-12 23:20     ` The disappearing sys_call_table export Nigel Cunningham
2003-06-15 22:37       ` Yoav Weiss
2003-05-16  8:19 encrypted swap [was: The disappearing sys_call_table export.] (fwd) Ahmed Masud
2003-05-16 23:09 ` encrypted swap [was: The disappearing sys_call_table export.] Yoav Weiss
2003-05-16 23:39   ` Yoav Weiss
2003-05-17 16:32     ` Hugh Dickins

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.33.0305141236430.12212-100000@marauder.googgun.com \
    --to=masud@googgun.com \
    --cc=joern@wohnheim.fh-wedel.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=ml-lkml@unpatched.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).