6 ms·
Only if you don't use full-disk encryption, since the entire filesystem, including passwd/shadow, is editable. In fact, the same principle can be used to reset
by jake_the_third 8y ago
Only if you don't use full-disk encryption, since the entire filesystem, including passwd/shadow, is editable.
In fact, the same principle can be used to reset and extract windows user passwords. Something I did many times as an IT support technician.
- mirimir 8y agoSure. But how prevalent is FDE?
- newnewpdro 8y agoFDE is the norm for desktop/laptop users, we're well beyond that in the GNU/Linux world. The exception these days is leveraging secure boot and the tpm to ensure the kernel and initrd being booted and asking for your dmcrypt password can be trusted. That's our next challenge to make the standard.
- SteveNuts 8y agoMaybe it's just my experience but I haven't seen FDE be the norm within any of the companies I've worked for, and I've been in startup all the way to fortune 15...
- lathiat 8y agoI had an encryption requirement at both Oracle (for Windows) and Canonical (for Linux). For Windows they used some endpoint protection suite; for Canonical the functionality is built-in to the Ubuntu installer. Also since I own a Mac as my primary laptop, I've just always used filevault there and it helps me sleep a lot at night. Means I am not concerned if it gets stolen, my derpy photos won't be in someone elses hand. I don't care so much about the hardware.
- mirimir 8y agoFor Ubuntu, are you referring to LUKS or /home/user encryption?
- shandor 8y agoDoesn't matter, both of them are offered by the OS installer and are easy to set up.
- Klover 8y agoFYI: only full disk encryption is available now in 18.04: "The installer no longer offers the encrypted home option using ecryptfs-utils. It is recommended to use full-disk encryption instead for this release." https://wiki.ubuntu.com/BionicBeaver/ReleaseNotes#Other_base_system_changes_since_16.04_LTS https://wiki.ubuntu.com/BionicBeaver/ReleaseNotes#Other_base...
- kchr 8y agoIf you want protection from someone booting up your computer in single/rescue mode to read/modify files you'd have to encrypt the entire disk (using LUKS, for example).
- newnewpdro 8y agoAre you even talking about GNU/Linux? Most of the comments in this thread have been about MacOS and Windows, and I made no claim regarding those. FDE with LUKS/dmcrypt has been an out-of-box installer-supported mode in all the major distros for a long time now.
- mirimir 8y ago> FDE is the norm for desktop/laptop users, we're well beyond that in the GNU/Linux world. Huh? The norm? For what sorts of users? I mean, that's best practice, sure. But hardly the norm. Even, I bet, among HN users.
- conradev 8y agoIt's on by default for macOS and Windows users: https://www.theguardian.com/technology/2014/oct/17/apple-defies-fbi-encryption-mac-osx https://www.theguardian.com/technology/2014/oct/17/apple-def... https://www.howtogeek.com/173592/windows-8.1-will-start-encrypting-hard-drives-by-default-everything-you-need-to-know/ https://www.howtogeek.com/173592/windows-8.1-will-start-encr...
- logifail 8y agoIt's certainly not "on by default" for all Windows users, twice in the last month I've broken into machines for clients where users forgot their password, both times using nothing more than a USB stick (then replacing utilman.exe with cmd.exe) Both boxes had fairly recent hardware and were running Windows 10 Pro.
- kchr 8y agoSo maybe those two users opted out of FDE, or had company requirements that told them to.
- logifail 8y agoThey didn't opt out of FDE and there are no company policies/requirements either. I have three laptops on my desk right now, one HP Probook and two different Lenovo Ideapads. All three are running Windows 10 Enterprise (2x LTSB 2016, 1x 1803). NONE of them have FDE enabled or have ever asked asked me about it. Given the bold claim "[FDE is] on by default for (...) Windows users" - without mention of caveats re: login account types, domain memberships, or hardware requirements - it seems the counterexamples just keep coming.
- jake_the_third 8y agoI can't speak for others, but I always enable it on any installation I preform on my devices. Ubuntu is nice in that it makes it very trivial to enable during the installation process.
- lnx01 8y agochntpw has saved my bacon so many times I can't count