<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://lug.mtu.edu/w/index.php?action=history&amp;feed=atom&amp;title=Minutes_2025-01-23</id>
	<title>Minutes 2025-01-23 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://lug.mtu.edu/w/index.php?action=history&amp;feed=atom&amp;title=Minutes_2025-01-23"/>
	<link rel="alternate" type="text/html" href="https://lug.mtu.edu/w/index.php?title=Minutes_2025-01-23&amp;action=history"/>
	<updated>2026-05-14T11:17:40Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.17</generator>
	<entry>
		<id>https://lug.mtu.edu/w/index.php?title=Minutes_2025-01-23&amp;diff=7784&amp;oldid=prev</id>
		<title>D2wn at 02:00, 15 February 2025</title>
		<link rel="alternate" type="text/html" href="https://lug.mtu.edu/w/index.php?title=Minutes_2025-01-23&amp;diff=7784&amp;oldid=prev"/>
		<updated>2025-02-15T02:00:16Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 02:00, 15 February 2025&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 74:&lt;/td&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 74:&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The new bamboo update introduces DRM and firmware locks, dont update.&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;* The new bamboo update introduces DRM and firmware locks, dont update.&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Meeting Minutes]]&lt;/div&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Meeting Minutes]]&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
  &lt;td colspan=&quot;2&quot; class=&quot;diff-empty diff-side-deleted&quot;&gt;&lt;/td&gt;
  &lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;
  &lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;__NOEDITSECTION__&lt;/div&gt;&lt;/td&gt;
&lt;/tr&gt;

&lt;!-- diff cache key lug_wiki:diff:wikidiff2:1.12:old-7769:rev-7784:1.13.0 --&gt;
&lt;/table&gt;</summary>
		<author><name>D2wn</name></author>
	</entry>
	<entry>
		<id>https://lug.mtu.edu/w/index.php?title=Minutes_2025-01-23&amp;diff=7769&amp;oldid=prev</id>
		<title>D2wn: Created page with &quot;= LUKS and Disk Encryption =  By: Noah Holland  === Brief overview on disk Encryption ===  ==== Symmetric vs Asymmetric ====  ==== Full-Disk Encryption ====  * There is Bitlocker for Windows and LUKS for Linux #### Filesystem-level Encryption * APFS * FSCrypt(ext4 (added recently), F2FS, CephFS, etc..) * ZFS Not recommended for personal use  === Pros and cons of each approach ===  ==== Issues with FDE ====  * Not east with multiple users ** either decrypt the disk with a...&quot;</title>
		<link rel="alternate" type="text/html" href="https://lug.mtu.edu/w/index.php?title=Minutes_2025-01-23&amp;diff=7769&amp;oldid=prev"/>
		<updated>2025-02-14T22:39:25Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;= LUKS and Disk Encryption =  By: Noah Holland  === Brief overview on disk Encryption ===  ==== Symmetric vs Asymmetric ====  ==== Full-Disk Encryption ====  * There is Bitlocker for Windows and LUKS for Linux #### Filesystem-level Encryption * APFS * FSCrypt(ext4 (added recently), F2FS, CephFS, etc..) * ZFS Not recommended for personal use  === Pros and cons of each approach ===  ==== Issues with FDE ====  * Not east with multiple users ** either decrypt the disk with a...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= LUKS and Disk Encryption =&lt;br /&gt;
&lt;br /&gt;
By: Noah Holland&lt;br /&gt;
&lt;br /&gt;
=== Brief overview on disk Encryption ===&lt;br /&gt;
&lt;br /&gt;
==== Symmetric vs Asymmetric ====&lt;br /&gt;
&lt;br /&gt;
==== Full-Disk Encryption ====&lt;br /&gt;
&lt;br /&gt;
* There is Bitlocker for Windows and LUKS for Linux #### Filesystem-level Encryption&lt;br /&gt;
* APFS&lt;br /&gt;
* FSCrypt(ext4 (added recently), F2FS, CephFS, etc..)&lt;br /&gt;
* ZFS Not recommended for personal use&lt;br /&gt;
&lt;br /&gt;
=== Pros and cons of each approach ===&lt;br /&gt;
&lt;br /&gt;
==== Issues with FDE ====&lt;br /&gt;
&lt;br /&gt;
* Not east with multiple users&lt;br /&gt;
** either decrypt the disk with a shared password or TPM&lt;br /&gt;
* Data recovery can be a pain in the ass&lt;br /&gt;
* Chicken-and-egg problem&lt;br /&gt;
&lt;br /&gt;
==== Issues with FS-level Encryption ====&lt;br /&gt;
&lt;br /&gt;
* Metadata leakage&lt;br /&gt;
** NSA Director: “We Kill people based on Metadata”&lt;br /&gt;
* Evil maid attacks Requires FS to support it&lt;br /&gt;
** more moving parts&lt;br /&gt;
&lt;br /&gt;
=== How To Use? ===&lt;br /&gt;
&lt;br /&gt;
==== LUKS ====&lt;br /&gt;
&lt;br /&gt;
* cryptsetup luksFormat /dev/&amp;lt;device&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== ext4 ====&lt;br /&gt;
&lt;br /&gt;
* enable encrypt feature flag&lt;br /&gt;
* crypt encrypt &amp;lt;directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== ZFS ====&lt;br /&gt;
&lt;br /&gt;
zfs create -o encryption=on -o keylocation=prompt -o keyformat=passphrase &amp;lt;zpool&amp;gt;/&amp;lt;dataset&amp;gt; - zfs load key -r &amp;lt;zpool&amp;gt;/&amp;lt;dataset&amp;gt; - zfs mount (more info on slides)&lt;br /&gt;
&lt;br /&gt;
Noah uses a key file on the root that unlocks his computer on startup.&lt;br /&gt;
&lt;br /&gt;
=== How LUKS works ===&lt;br /&gt;
&lt;br /&gt;
* LUKS is composed of its header and then multiple key slots that stand between the user and the encrypted data&lt;br /&gt;
* dread pirate Ross got caught with his drive unencrypted, so to avoid this have a drive plugged in that when removed wipe access to the encrypted system altogether.&lt;br /&gt;
&lt;br /&gt;
=== LUKS recovery ===&lt;br /&gt;
&lt;br /&gt;
* make backups&lt;br /&gt;
* pain in the ass to recover&lt;br /&gt;
&lt;br /&gt;
=== Plausible Deniability ===&lt;br /&gt;
&lt;br /&gt;
* done via a LUKS detached header&lt;br /&gt;
* indistinguishable from random data&lt;br /&gt;
* can use a special command to separate the header and use it later #### VeraCrypt&lt;br /&gt;
* Like LUKS detached header but all the time&lt;br /&gt;
* downside - human operator needs to remember all settings&lt;br /&gt;
* fork of truecrypt - might be made by the feds or Vera might be made by the feds&lt;br /&gt;
* can set multiple decryption passwords for a dummy volume and your real volume&lt;br /&gt;
&lt;br /&gt;
=== Russain man script update ===&lt;br /&gt;
&lt;br /&gt;
* recap: I bought drives, but they ended up not working, but we found a Russian guy who could make them work for us using some script.&lt;br /&gt;
* got the script from him, need the firmware file.&lt;br /&gt;
* could someone break into the White House and trick Trump into pardoning them for breaking into the White House?&lt;br /&gt;
* The new bamboo update introduces DRM and firmware locks, dont update.&lt;br /&gt;
[[Category:Meeting Minutes]]&lt;/div&gt;</summary>
		<author><name>D2wn</name></author>
	</entry>
</feed>