Re: [Tails-dev] Ticket #5705, desktop integration of crypts…

Nachricht löschen

Nachricht beantworten
Autor: Marco Calamari
Datum:  
To: The Tails public development discussion list
Betreff: Re: [Tails-dev] Ticket #5705, desktop integration of cryptsetup TrueCrypt support
On Sat, 2013-10-05 at 14:43 +0200, intrigeri wrote:
> Hi,
>
> irregulator@??? wrote (05 Oct 2013 12:12:09 GMT) :
> > I made some simple tests in Debian testing to review desktop integration.
>
> Great, thanks! This was enough to motivate me to (procrastinate and)
> create tickets for the next steps.
>
> > A user can open a Truecrypt container using cryptsetup in command-line
> > with root privileges. I think that can be handled with sudo. Still, one
> > could say it's complicated for the average user to fire up command line
> > to open a Truecrypt container. That's a minus.


This is a great news! Average user that can understand giving an
optional boot parameter & manage Truecrypt panel, will not
have difficulties (IMO) using command line with some guide.

After this, there is always space to make things better and easier,
but this is a path than can be decided in a not-so-distant
future.

One doubt; a corrupted encrypted volume id a really bad thing; is
this feature stable from this standpoint?

> > Gnome Disk Utility seems not to recognize the Truecrypt volume as it
> > does with say a LUKS volume. It just shows an unknown format's file with
> > size equal to the Truecrypt volume, assigned at a loopback device.


AFAIK, Luks volumes start with a signature, that make a volume
recognizable.

Truecrypt volume header have no signature, and cannot be seen in any
way; it is indistiguishable from binary noise.
Truecrypts devices looks as unformatted empty devices or partitions,
or noise-filles files.

Thanks. Marco

>
> Added this info to the blueprint:
> https://tails.boum.org/blueprint/replace_truecrypt/
>
> So, it looks like the next thing to do is:
>
> #6337 - Add support for TrueCrypt volumes in udisks
>
> I've created this ticket in our bug tracker, and requested the feature
> upstream:
>
> https://bugs.freedesktop.org/show_bug.cgi?id=70164
>
> This upstream feature request has way more chance to be fulfilled if
> someone proposes a patch. Any taker?


--
+--------------- http://www.winstonsmith.org ---------------+
| il Progetto Winston Smith: scolleghiamo il Grande Fratello |
| the Winston Smith Project: unplug the Big Brother          |
| Marco A. Calamari marcoc@???  http://www.marcoc.it   |
| DSS/DH:  8F3E 5BAE 906F B416 9242 1C10 8661 24A9 BFCE 822B |

+ PGP RSA: ED84 3839 6C4D 3FFE 389F 209E 3128 5698 ----------+