LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-01-2023, 09:53 PM   #1
stoorky
Member
 
Registered: Sep 2015
Posts: 63

Rep: Reputation: Disabled
How to refresh decoy data on a plausible deniability dm-crypt scheme ?


I just read this discussion between Linus Torvalds and (among others) Milan Broz, one of dm-crypt's maintainers.

I am intrigued by the the following part of the discussion :

Quote:
Linus Torvalds:
I thought the people who used hidden ("deniable") things didn't actually ever *use* the outer filesystem at all, exactly so that they can just put the real encrypted thing in there and nor worry about it.

Milan Broz:
Well, they actually should "use" outer from time to time so the data looks "recent" and for the whole "hidden OS" they should be even able to boot to outer decoy OS on request, just to show that something working is there.
In theory, I agree with Milan's statement, using the decoy data is a good thing to do to increase credibility. But how do you achieve that in practice ? E.g., how can you write to the outer volume without risking to overwrite the inner volume ?

I am using hidden LUKS volumes for years now, combining detachable headers and data offset. Usually I start by creating a small LUKS-encrypted outer volume (let's say 20 GB), I fill it with decoy data, then I increase this outer volume's size (to for example 500 GB), and I create the inner volume with an offset of 25GB for example.

And after that I do what Linus said, I religiously avoid to touch the outer volume's decoy data, out of fear of damaging the inner volume's data.

Is there a way to refresh the outer volume's data, without risking to damage the inner volume's data ? E.g., is there a tool to write specifically on the 20 first Gigs of the outer volume, making sure to not mess with the 480 following gigs ?

I am using both HDDs and SSDs, so the question applies to both.
 
  


Reply

Tags
dm-crypt, luks



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux alternative to Win+VeraCrypt FDE & Hidden OS (+decoy)? Time4Linux Linux - Security 2 02-05-2018 03:56 PM
Deniability of hidden data when all versions are available to adversary Ulysses_ Linux - Security 16 12-23-2013 05:23 PM
Encryption and plausible deniability lroy1978 Linux - Security 5 04-02-2009 12:48 PM
Password generation failed for scheme {CRYPT}: scheme not recognized olva Linux - General 0 11-05-2006 11:21 AM
Decoy Scans w/ Nmap robeb Linux - Networking 1 10-14-2002 06:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration