← Back to team overview

ecryptfs team mailing list archive

[Bug 277894] Re: anyone with a livecd can acces data on ubuntu -- encrypt home directories

 

I've fixed this upstream in ecryptfs-utils-66, which supports encryption
of all of home directories.

I'm leaving the Ubuntu task open for now, as there's a bit more work to
be done at the distribution level, to get this working in the installer,
etc.

:-Dustin

** Also affects: ecryptfs
   Importance: Undecided
       Status: New

** Changed in: ecryptfs
       Status: New => Fix Released

-- 
anyone with a livecd can acces data on ubuntu -- encrypt home directories
https://bugs.launchpad.net/bugs/277894
You received this bug notification because you are a member of eCryptfs,
which is a direct subscriber.

Status in eCryptfs - Enterprise Cryptographic Filesystem: Fix Released
Status in “ecryptfs-utils” source package in Ubuntu: In Progress

Bug description:
all of my personal files i store in ubuntu can be accessed by anyone with a livecd without knowing my password. mac actually locks your personal data by default so if you put a livecd in and try to access them it will prompt you for the password. ubuntu does not have this. this renders all of my personal files insecure. this seems pretty serious to me.

try using a livecd to read data from your home folder on a mac and see what happens. this is what should happen in ubuntu.

once again, seeing as this applies to everyone on a default setup and how it allows anyone to see all of the files on the computer without a password, including extremely private and critical ones, and seeing as how you can eveen delete these files too, it seems pretty serious to me.