[go: up one dir, main page]

|
|
Log in / Subscribe / Register

Preventing information leaks from ext4 filesystems

Preventing information leaks from ext4 filesystems

Posted Apr 27, 2021 23:58 UTC (Tue) by gus3 (guest, #61103)
Parent article: Preventing information leaks from ext4 filesystems

Ext4 and f2fs already have native support for encrypting files (and filenames). I don't understand why this is a problem.


to post comments

Preventing information leaks from ext4 filesystems

Posted Apr 28, 2021 6:59 UTC (Wed) by ibukanov (subscriber, #3942) [Link] (3 responses)

As others have already pointed out above, encryption does not help with possible future malware infection that will look at deleted information.

Preventing information leaks from ext4 filesystems

Posted Apr 28, 2021 7:50 UTC (Wed) by comicfans (subscriber, #117233) [Link] (2 responses)

To my knowledge, if a malware can look at deleted information even with encryption enabled (as said 'encryption does not help ') , it must be a running time attack (since encryption prevent cold attack), and if it can bypass OS fs layer restriction (because you can not access a already deleted file info through normal fs api), it must gain raw disk read permission (at least some level administrator permission, for example access debugfs ). in such situation, if without encryption , malware can parse whole filesystem already, no just a filename. with encryption enabled, malware at least need to obtain encryption key (otherwise encryption still worked). and if malware can obtain encryption key (no matter from kernel, or from a bad-placed-plain-text-password), then whole system already being cracked (almostly). that means: if such malware do exist and make encryption useless, then whole os already insecure. it can leak much more than just a filename. encryption at least makes crack harder.

Preventing information leaks from ext4 filesystems

Posted Apr 28, 2021 21:46 UTC (Wed) by ibukanov (subscriber, #3942) [Link] (1 responses)

I was talking about defense against future infection that can recover deleted information.

Preventing information leaks from ext4 filesystems

Posted Apr 28, 2021 22:10 UTC (Wed) by gus3 (guest, #61103) [Link]

Thanks to both of you for your comments. I see your points.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds