LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-13-2023, 11:12 AM   #1
citrate
LQ Newbie
 
Registered: Mar 2019
Location: Ukraine and Europe sometimes
Distribution: Mandriva, Ubuntu, Puppy Linux, Debian stable
Posts: 13

Rep: Reputation: Disabled
Salfe made token


Hello, Dear admins and Linux users!

Here is one article in russian, how to do self made token. You can google translate it.
https://we.easyelectronics.ru/STM32/...mi-rukami.html

I'm interesting to do token from UBB flash for OS Linux/Windows/Android using USB 2.0 + usb type C flash, without soldering.

Flash must be encrypting, can be open by programs installed on Linux/Windows/Android device and as key holder must be KeePass database inside encrypting in 3 or 2 copies, and KeePass is cross platform tool, instated on Linux/Windows/Android device or moving inside encrypting flash volume as portable soft.

1. Any suggestions about how to do such token from USB Flash?
2. How to encrypt usb volume to be opened under Linux/Windows/Android.
3. Is KeePass good enough to not be cracked? I have been used it since 2008-2009.
 
Old 09-13-2023, 12:39 PM   #2
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722
Token?
 
Old 09-13-2023, 12:42 PM   #3
citrate
LQ Newbie
 
Registered: Mar 2019
Location: Ukraine and Europe sometimes
Distribution: Mandriva, Ubuntu, Puppy Linux, Debian stable
Posts: 13

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wpeckham View Post
Token?
Yee... just like token - not the same. Hardware storage for passwords, not in clouds and without server.
 
Old 09-13-2023, 12:55 PM   #4
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722
Quote:
Originally Posted by citrate View Post
Yee... just like token - not the same. Hardware storage for passwords, not in clouds and without server.
Oh, a SECURITY token. The only one I have carried was RSA and had processing inside. Making your own would seem much less than secure.
 
Old 09-13-2023, 01:31 PM   #5
citrate
LQ Newbie
 
Registered: Mar 2019
Location: Ukraine and Europe sometimes
Distribution: Mandriva, Ubuntu, Puppy Linux, Debian stable
Posts: 13

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wpeckham View Post
Oh, a SECURITY token. The only one I have carried was RSA and had processing inside. Making your own would seem much less than secure.
Now I use KeePass on 4 computers with windows, 2 computers with Linux and 1 Android phone. The database in each case is on HDD/SSD of the equipment in 2 copies each, in my user directory. But somebody can steal database file and try password brute force hacking.

Im thinking stay KeePass database in encrypted flash.


If buy so proprietary Security token with its own microprogram , which will be good in security and price?
 
Old 09-13-2023, 01:42 PM   #6
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722
Quote:
Originally Posted by citrate View Post
Now I use KeePass on 4 computers with windows, 2 computers with Linux and 1 Android phone. The database in each case is on HDD/SSD of the equipment in 2 copies each, in my user directory. But somebody can steal database file and try password brute force hacking.

Im thinking stay KeePass database in encrypted flash.


If buy so proprietary Security token with its own microprogram , which will be good in security and price?
I am not sure, as I am not in the market and have not done that research. Having your passwords available on another portable device (that is more likely to fail) does not seem to me a more secure option!

Last edited by wpeckham; 09-13-2023 at 01:43 PM.
 
Old 09-13-2023, 01:55 PM   #7
citrate
LQ Newbie
 
Registered: Mar 2019
Location: Ukraine and Europe sometimes
Distribution: Mandriva, Ubuntu, Puppy Linux, Debian stable
Posts: 13

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by wpeckham View Post
I am not sure, as I am not in the market and have not done that research. Having your passwords available on another portable device (that is more likely to fail) does not seem to me a more secure option!
Yes, I agree - flash can be lost or destroyed, or simply fail.

Is it better to do virtual HDD encrypted volume by TrueCrypt (It was not updated from 2012 as I can remember), that can consist KeePass database inside?
 
Old 09-13-2023, 09:23 PM   #8
wpeckham
LQ Guru
 
Registered: Apr 2010
Location: Continental USA
Distribution: Debian, Ubuntu, RedHat, DSL, Puppy, CentOS, Knoppix, Mint-DE, Sparky, VSIDO, tinycore, Q4OS, Manjaro
Posts: 5,714

Rep: Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722Reputation: 2722
keepass data is already encrypted, and the highest level is crazy hard to crack.

The real question is "what are you doing that requires that level of encryption?", followed by "what is the threat that would attack using decryption tools rather than moving on to an easier target?"!

Rather than opting for more or stronger encryption of passwords, I would opt for something that adds security beyond the passwords level. Some kind of 2FA or authenticator based solution (or both).
 
Old 09-14-2023, 01:17 AM   #9
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,976

Rep: Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337Reputation: 7337
keepass has a feature to use a key file to open the database (that means it will ask for a password and will also check the key file). So you cannot do anything with that database without this key file, you can freely send the database to anywhere on the net. Just you need to take care of your key file and also you need to have a strong password.
(nobody can even identify both your database and key file, without help).
 
1 members found this post helpful.
Old 09-15-2023, 10:13 AM   #10
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,679
Blog Entries: 4

Rep: Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947Reputation: 3947
It’s handy to keep the password database file in your pocket. Since it is an ordinary file, simply keep a backup copy of it “somewhere else.”
 
  


Reply

Tags
android, linux, password manager, token, windows



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
slackware WP 1920 x 1080, b=cuz nobody made made new ones BW-userx Slackware 34 05-31-2023 04:53 AM
bash use refresh token to renew access token aristosv Linux - Newbie 3 03-13-2022 08:34 AM
Made CSR request but cannot find the public.key that is made bscho Fedora 6 12-01-2020 07:57 PM
[SOLVED] "Error: syntax before '@' token and Error: syntax at 'OTHER' token" bullrider Programming 2 07-27-2009 08:00 AM
Authentication Token Manipulation Error manfernandez Linux - Security 10 06-06-2008 11:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration