Fedora is considering the possibility of implementing FS encryption by default

Owen Taylor, the creator of GNOME Shell and the Pango library, who is part of the Fedora Workstation development group, has proposed a plan for default encryption of system partitions and user home directories in Fedora Workstation. The advantages of switching to default encryption include data protection in case of laptop theft, defense against attacks on unattended devices, maintaining privacy and integrity out of the box without requiring additional steps.

According to the drafted plan for encryption, Btrfs fscrypt is expected to be used. For system partitions, encryption keys are planned to be stored in the TPM module and linked to digital signatures used to verify the integrity of the bootloader, kernel, and initrd (i.e., during the system boot, the user will not need to enter a password to decrypt the system partitions). When encrypting home directories, keys are intended to be generated based on the user's login and password (the connection to the encrypted home directory will occur at user login).

The implementation timeline for the initiative depends on the distribution's transition to a unified kernel image (UKI), which combines the boot handler for loading the kernel from UEFI (UEFI boot stub), the Linux kernel image, and the memory-loaded initrd environment into one file. Without UKI support, it is impossible to guarantee the integrity of the initrd environment where the keys for decrypting the filesystem are determined (for example, an attacker could replace initrd and simulate a password prompt, which requires a verified boot of the entire chain up to mounting the filesystem).

Currently, the Fedora installer offers an option for block-level encryption using dm-crypt, which employs a separate passphrase not tied to the user's account. This solution faces issues such as unsuitability for separate encryption in multi-user systems, lack of internationalization support, and accessibility tools, potential attacks via bootloader substitution (an installed attacker's bootloader could impersonate the original and request the decryption password), and the need for framebuffer support in initrd to display the password prompt.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster