Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Mount security
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
pgray
n00b
n00b


Joined: 23 Apr 2002
Posts: 51

PostPosted: Tue Nov 16, 2004 4:40 pm    Post subject: Mount security Reply with quote

I am currently engaged in a project putting together a computer that will likely be sold to the general public. I am grappling with an issue at the moment, and since it will be running Gentoo, I was hoping someone here could help. The computer needs to be protected against someone with a LiveCD booting it and mounting the HDD (DRM/protected media will be present on the HDD). Of course standard procedures like locking the BIOS and turning off CD booting will be taken, but I am looking for something a little more severe. Is there some way to either encrypt the filesystem, or require the kernel/program that mounts it to be registered in some way? I was looking at dm-crypt in the 2.6.3-mm kernel, but I don't want the user to have to enter a password at each boot. This machine will be a HTPC, so it will likely be missing a keyboard and mouse most of the time. Is there any advice you can give me on how to make a partition completely unmountable unless its from the intended kernel/distro/program? Ideally a solution to this problem would not involve processor intensive encryption, but feel free to respond with solutions that do. Thank you.

pgray
_________________
life is just a dream, you know? it's neverending.
Back to top
View user's profile Send private message
liber!
Tux's lil' helper
Tux's lil' helper


Joined: 05 Aug 2004
Posts: 123
Location: EU, Antwerp

PostPosted: Tue Nov 16, 2004 7:58 pm    Post subject: Reply with quote

You can encrypt the partitions:
http://www.frech.ch/howto/HOWTO/html_single/Cryptoloop-HOWTO/
and in the Documentation, Tips and Tricks: look at: Howto gpg encrypt your root using udev,cryptsetup,dm-crypt
I don't know how processor intensive it is...

it are both different techniques and I don't have much experience with any of them, but I'm studying the subject.

Greets,
Nathan
Back to top
View user's profile Send private message
evilben
Tux's lil' helper
Tux's lil' helper


Joined: 14 Jun 2004
Posts: 128
Location: GA, USA

PostPosted: Wed Nov 17, 2004 5:18 am    Post subject: Reply with quote

I've seen motherboards that come with an encryption module for the hard drive, and require that one of the included USB keys be plugged in for the computer to boot. Couldn't find a link for one, though...
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum