The UNIX and Linux Forums  
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.

Go Back   The UNIX and Linux Forums > Top Forums > UNIX for Dummies Questions & Answers
.
google unix.com



UNIX for Dummies Questions & Answers If you're not sure where to post a UNIX or Linux question, post it here. All UNIX and Linux newbies welcome !!

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Problem with GnuPG...need help manas_ranjan Shell Programming and Scripting 0 08-29-2007 05:09 AM
GnuPG (gpg command) BCarlson Shell Programming and Scripting 4 03-01-2006 09:35 AM

Closed Thread
English Japanese Spanish French German Portuguese Italian Dutch Swedish Russian Norwegian Hungarian Hebrew Danish Bulgarian Greek Powered by Powered by Google
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
  #1 (permalink)  
Old 09-15-2004
mile1982 mile1982 is offline
Registered User
  
 

Join Date: Sep 2004
Location: Down Under
Posts: 11
Gnupg

hey guys

i need to restrict access to the GNUPG program because of the possibility that sensitive data like encryption keys and passwords that it is using may be written into the virtual memory swap partition on the hard disk and thus be retrieved at a later date long after the program has erased these important values from memory and finished executing.

im a newbie to unix so the question might sound stupid. would be it be possible to somehow give access to a number of people without actually having the remove it from the system or remove the setuid permission?? feedback would be appreciated

mile1982
  #2 (permalink)  
Old 08-29-2008
morten44's Avatar
morten44 morten44 is offline
Registered User
  
 

Join Date: Apr 2008
Location: Crefeld NRW
Posts: 3
I remember I have seen this topic, also a journaling file system can be a security risk. There exists a solution about writing random garbadge into the swap file or swap partition. But Even if you destroy the entire hard disk, sensitive data can be recovered from RAM. I think Bruce schneier wrote about using dd to delete a swap partition. I have forgotten all details but It could be that truecrypt can help you.

Anyone with access physical to your machine IS a security risk.

Please use chmod chgroup and chown to hide your files. Or simply delete them and use a USB Memory stick.
  #3 (permalink)  
Old 08-31-2008
Perderabo's Avatar
Perderabo Perderabo is offline Forum Staff  
Unix Daemon
  
 

Join Date: Aug 2001
Location: Ashburn, Virginia
Posts: 9,119
This is an old thread, but now recent versions of gpg will complain loudly if they are run without being suid to root. The root priviledge is to address this issue by locking data into memory so no swapping is possible.
Closed Thread

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 11:52 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited. Language Translations Powered by .
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios
The UNIX and Linux Forums Content Copyright ©1993-2009. All Rights Reserved.Ad Management by RedTyger

Content Relevant URLs by vBSEO 3.2.0