Encryption (Filenames/metadata, what to encrypt, resizing)

I've already decided to use an unencrypted root, either loop-aes or LUKS/dm-crypt to encrypt my swap (I will benchmark to decide), loop-aes/EncFS/LUKS to encrypt /tmp (or I will use tmpfs, since I have 6GB of RAM... any opinions?), and either LUKS, loop-aes, or TrueCrypt for my personal /home. /var/tmp will be an EncFS.
First, as mentioned above, any advice from those with experience on making a separate /tmp to encrypt with traditional methods vs. using tmpfs for /tmp (6GB RAM)? What kinds of operations use /tmp the most (I know optical disc writing does) (this will help to benchmark with/without tmpfs), and to what extent? Same questions for /var/tmp? I know tmpfs will automatically move lesser-used stuff to swap instead of main RAM - does it do this well, and does it adjust how much it does that depending on how much free RAM there is?
Second, I know TrueCrypt will encrypt filesystem metadata (the important thing being file names), and EncFS does since late last year. I'm pretty sure LUKS/dm-crypt and loop-aes also do, but I'm not 100% sure. Is anyone certain they do?
Third, any comments on how I've decided to set up my system? Are there any places I'm missing to encrypt?
And fourth, any info on resizing any of the above encryption setups (on block devices on LVM) would be very much appreciated.
Thanks!!
NOTE: I'm also considering just encrypting everything except probably /usr... it would be simpler, that's for sure. We'll have to see what the damage is in terms of speed.
NOTE 2: I will definitely post my results so others can see when I'm done. I will be running the benchmarks on both a quad-core with 7,200rpm hard drives and an elderly ThinkPad with a Pentium M Banias and a 5,400rpm drive. I'll also do a few quick benches to see whether the differences between file system change when encryption is used.... this'll be "fun".
I'm also asking these questions here, for any reading this that are also interested.

If someone takes it, puts it into another computer, and looks at each sector.
I know some encryption methods don't encrypt filesystem metadata, which means filenames, permissions, etc.. eCryptfs didn't until recently, for example. I know TrueCrypt does, but I'm not 100% sure that LUKS and Loop-AES work.
And to you, I recommend you find a way to encrypt /var/tmp and /tmp... if you burn something to DVD, for example, that's on your encrypted partition, the temp files will be stored in /tmp. Now your encrypted stuff has been written unencrypted to your hard drive, and can be recovered at least partially without too much trouble. /tmp can be a tmpfs (swap and RAM are used), but /var/tmp needs to be persistent -  a separate encrypted partition, or eCryptfs (might be too slow).
Last edited by Ranguvar (2009-02-17 20:12:56)

Similar Messages

  • What happens on resize (and how can I force it to happen without resizing)?

    Hello everybody!
    After running into this for the umpteenth time, I have decided to ask somebody who knows better. So, here goes:
    Often, when I change something in the layout of an applet or an application (e.g. removing a JComponent and replacing it with another one), it doesn't get updated. I need to resize the Application window or the AppletViewer window, and then the change is correctly displayed and everything works fine. For Applets, I figured out that I can pack() as a workaround, but this can have some nasty side effects. I haven't been able to find anything for Applets though (an Applet doesn't have a pack() method).
    So, does anyone know what exactly happens when I resize that window and why then my changes to the layout are applied? And, more importantly, what I have to do to reproduce this effect without resizing?
    Thanks a lot in advance,
    Wojtek

    Thanks for the reply! Doesn't work though (invalidate-revalidate was one of my first tries...):
    - Applet has no revalidate().
    - If I put all my stuff into an extra JPanel that I add to the Applet, and revalidate() the JPanel after changing the stuff in it, nothing happens, I still need to resize.
    Any other ideas?

  • What steps to resize a datafile

    Dear all,
    One of datafile is very huge, and i want to resize it and make it smaller, how can i do? what is the steps?

    Hi Aman/All ,
    * IMP request to the person who posted this , please dont try this without getting suggestions from the experts. I am just putting forward a query on the replies *
    Sir ,
    I had read somewhere that the HWM can me moved and then the tablespace can be reduced.
    I rechecked this link :
    http://sysdba.wordpress.com/2006/04/28/how-to-adjust-the-high-watermark-in-oracle-10g-alter-table-shrink/But then it has a restriction that it can be done only when the database is under ASSM.
    Do we know if the person who has posted this query is with ASSM ?I was gng through docs on ASSM , it says from 10g onwards its the default.
    A user can see the status by this query :
    SELECT tablespace_name, extent_management, segment_space_management
       FROM dba_tablespaces;Please suggest
    Thanks and Regards
    Kk

  • What does allow resizing mean in options?

    what does the allow resizing option mean?

    John,
    please explain in details what you mean by this? i am not able to figure out in which context you mean resizing. Also do tell which application you using and on what platform?
    -Garry

  • What effect does resizing temp file on primary have on standby database?

    We have a weekly job on Primary that resizes the temp tablespace.
    STANDBY_FILE_MANAGEMENT='AUTO' so am I correct in the assumption that the changes will be passed on and replicated on standby, even though they are temp files?
    I am going live with DG in 2 weeks and keep thinking about questions such as this!
    Thanks

    Writes to tempfiles aren't logged, so aren't shipped to the standby database. Writes to the tempfile on the primary causing the tempfile to extend won't cause the tempfile on the standby to extend. Tempfiles on the standby can be added/dropped/resized independently to the primary, even with STANDBY_FILE_MANAGEMENT='AUTO'.
    If the standby is purely for disaster recovery and left permanently in managed recovery mode, then the standby won't even need a tempfile until after it has been activated in a failover/switchover situation.

  • Aperture Metadata - What is the difference between a view & a preset?

    I'm setting up my Metadata for importing and I'm following bagelturf's guide: [http://archive.bagelturf.com/aparticles/library/libinadv/index.php]
    But I'm having trouble understanding the difference and function between Metadata Presets and Metadata Views.

    Sure -
    Go to the metadata tab in the inspector show the "other fields", notice that at the top of the
    "other" field list that you can enter new custom field names, just add a field name with no value.
    Now choose any metadata view that you wish (the drop down at the top of the metadata tab) to use when you import like "caption and copyright" or make a new one.
    From the "other" list just check the box next to the custom named field that you just added. That will now show up in whatever view you chose.
    When you import just choose that view in the import panel and the field will be there empty for you to fill in for whatever you are importing.
    RB

  • Can I make a metadata-based watermark (e.g. - filename) in LR3?

    I would like to use filename metadata as part of a watermark in LR3.  I am hoping I can do this for building client review web galleries in LR3 so clients can easily identify image selects.  Is this possible?

    There's a work-around: Add the file name into the fields for caption or for title. In the web-module you can specify to add title or caption or both - In the web module right side in the panel <Image Info>.
    Or you can add the file name into the field for Contact info. Naturally all this has to be done manually for each image. So it's only workable for a few images.
    WW

  • HTML Gallery, metadata and image download

    hi,
    I find Bridge collections really useful and output to html gallery template pretty good looking as a quick way to show prospect clients themed presentations of my work. There are two issues though which I hope someone can help with, or that Adobe would change if  listening in on this.
    Whereas the html gallery template reads the metadata like description, title and filename,  metadata is being stripped from the image when image is downloaded from gallery. 
    That the image can be downloaded and that meta data is stripped from the image files are two reasons not to use what otherwise could have been an excellent product.
    I would prefer the coding of this html gallery to prevent download of individual image files and as content providers we totally rely on metadata being contained with image file. Are there ways I can change this without going to script amendements?
    If the solution should not be with adobe, could anyone suggest another product that could cater for this need?
    Many thanks in advance.
    Torunn

    Amendments (and apologies for errors in my original post. Copyright status, -notice and -url are indeed contained in metadata for downloaded image, so not so bad then Wish list thus shortended to description field and the IPTC contact data. Though why not all?

  • Original Filename not saved if renaming during original import - Why?

    From what I have read online and what I have seen personally, it seems the concept of "Original Filename" is different depending on whether one renames during import vs after the fact.
    The files I renamed after the fact can be restored to the true filename from the camera card.  Subsequent renaming operations seem to use the true original name for pieces like original number suffix.
    Files that I renamed during import have a totally different idea of the original file name ... I think it is what I renamed it to during the import.
    Can you please confirm what I am saying is true?  If so, does anyone know why this is and how I can get my "true original filenames" back?
    I am new to LR and was experimenting with naming formats thinking I could change them around willy nilly.  Apparently this is not the case for the files I imported.  Those names are looking pretty screwed up.
    Thanks,
    Mike

    Original filename is what file is named upon import. If renamed before import (or during importing), then original filename will be as renamed - as you've experienced...
    What I do is to use the original file number as part of the renamed filename, thus I can always "recompute" the original card filename, if need be (on-the-fly, in my head, in Lightroom or out, via external software or plugins...).
    for example, if Nikon files are named {date-time}_{original-file-number}.ext upon import, then the original original raw filename was:
    * DSC_{original-file-number}.NEF, or
    * _DSC{original-file-number}.NEF.
    Depending on exif metadata "sRGB", or "AdobeRGB".
    If you need or want to rename them, in Lightroom, back to original card name, you can use a template like this:
    Granted, you'll need to have a different one for each mfr., to get the signature prefix right, and one for each colorspace...
    (if you don't know the (jpeg preview) colorspace, you'll need ExifMeta, or some such...)
    Cheers,
    Rob.

  • Getting 'Preserved Filename' to appear on InDesign contact sheet

    i'm using Bridge to manage/catalogue a large client image library. On occasion, i need to send out a PDF catalogue of this library. The built-in tool 'Create InDesign Contact Sheet' works perfectly for this, and i've been able to customize it somewhat, using an Indesign template i created.
    One thing i can't quite seem to figure out, however, is how to get the 'Preserved Filename' metadata onto my contact sheets as well. In the contact sheet dialog box, there is an option to 'Define' captions, and what additional information (other than filename) is displayed.
    Is this possible? When i do a 'File Info' on one of the images, the preserved filename information i need appears under the 'Advanced' category, 'xapMM: PreservedFileName'

    Yes, I did. The way it seems to be set up is like this:
    Each page of the contact sheet has 6 images, 2 rows by 3 columns. Each image is contained within it's own set of frames with a title. So I'm on a page that has 6 separate objects on it.
    If I select nothing and go to the object styles window, and make changes, nothing happens.
    If I select an individual image (with its surrounding frames) and make changes in object styles it affects that one thumbnail.
    If I select "select all" then all 6 frames on the page (or 12 if it's facing pages) are selected and the changes I make in object styles are applied to the selected items.
    But I can't seem to select more than one set of facing pages at a time.
    I'm obviously missing something - just don't know what?
    Actually, having just tried it again, I DO seem to be able to make some changes to the whole thing... ok - so it looks like I'm not editing the right things in object styles then.
    Thanks - I'll persevere and try to figure out what does what - there are so many variations of what you can tick or untick...

  • Dynamic Filename in Fileadapter

    Hi all,
    I like to use the new feature (SP15) of the "Adapter Specific Message Properties" but with out success. I have read Michaels Blog "XI: The same filename from a sender to a receiver file adapter - SP14" but it give me not a clue how to use these properties during the normal receiver configuration and also the manual is not very clear about it. I have set a Variable with "FileName    message:FileName" (I have tried also "message:File_Name") Than I have used this filename Variable in the field "Filename Schema" like %FileName%. But I allways got this error: com.sap.aii.adapter.file.varsubst.VariableDataSourceException: Unknown message header category 'FileName' for variable 'FileName'.
    What have I missed out here?
    Thankx
    Manfred Schmidt-Voigt

    Hi Manfred,
    The dynamic filename generation concept is as follows.
    In your filename field. just give a variable with % symbols. (eg: %file% ).
    Now, under the option Variable Name Substitution, you can give how the value has to be created.
    It can be your interface name, sender service name, etc or it can be some value dynamically from your payload.
    For the former, your give
    message:interface_name ,etc
    and for the payload part you give,
    Payload: "your element root which u wanna acecss"
    Just check this link out,
    http://help.sap.com/saphelp_nw04/helpdata/en/bc/bb79d6061007419a081e58cbeaaf28/content.htm
    And read the contents under variable substitution and it will help you understand the concepts better.
    If you have any clarifications, do get back,
    Regards,
    Bhavesh

  • Where can I find a macro I can use in Project Properties to generate PDB files of different filenames each build?

    Found a better solution. The answer is given at the very bottom of this post.
    I'm looking for $(Random), %(Date), %(Time), or some %(Value) that I can put in the "Generate Program Database File" entry.
    Like "$(TargetDir)_%(CreateTime).pdb".
    But the problem is, %(CreateTime), %(ModifiedTime), and %(AccessTime) has colons in them, making them useless when putting them into the filenames.
    What other ways can I generate PDB files of different file names? Or, how do you modify %(CreateTime) so that I can remove the colons and just obtain the numeric values?

    Hi Tom_mail78101,
    It seems that there is no built-in macro for renaming the PDB files randomly.
    You could submit this feature request:
    http://visualstudio.uservoice.com/forums/121579-visual-studio
    The Visual Studio product team is listening to user voice there. You can send your ideas/suggestions there and people can vote.
    I agree with Viorel. The possible way to rename the PDB files is that you write your own script to rename the PDB file after building the project and put the script to Post-Build event in Build Event. As for whether this way can accomplish it, you can try
    to consult on: MSBuild
    forum like this thread: https://social.msdn.microsoft.com/Forums/vstudio/en-US/bcf39fd6-0e0c-4486-9438-7a724ded44de/postbuild-event-command?forum=msbuild
    Best regards,
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • Getting Filename without Path in a CFC

    Hi All,
    I'm attempting to use a CFC/Event Gateway to get the filename of a file that has landed in a directory.
    What I'm getting instead is the full path with the filename.
    <cfcomponent>
    <cffunction name="onAdd" access="public" returntype="void" output="false">
    <cfargument name="CFEvent" type="struct" required="true">
    <cfset var data = arguments.CFEvent.data>
    <cfset var filename = arguments.CFEvent.data.filename>
    </cffunction>
    </cfcomponent>
    I know that the above code isn't complete, but I think it's what 'counts' here.
    The value that I'm getting back for the 'filename' variable is similar to this:
    C:\WebSite\Some_Directory\Another_Directory\filename.ext
    What I want is just the filename  (filename.ext) part of that line.
    It appears that arguments.CFEvent.data.filename doesnt do it, and I've tried all kinds of combinations like  'filename', 'serverfile.filename', 'data.filename' and so on, but I must just be missing it.
    I found a workaround for what I'm trying to do with the CFC,  but it would be a lot easier if I just knew what I need to use in the code to just pull the filename of the file that was dropped into the directory.  (Using the DirectoryWatcher)
    If anyone can help out with how to do this,  it would be appreciated
    I've been at this for ten hours and feel like Captain Noob right about now.
    Thanks!
    CFML_MANIAC

    CFML_MANIAC wrote:
    The value that I'm getting back for the 'filename' variable is similar to this:
    C:\WebSite\Some_Directory\Another_Directory\filename.ext
    What I want is just the filename  (filename.ext) part of that line.
    It appears that arguments.CFEvent.data.filename doesnt do it, and I've tried all kinds of combinations like  'filename', 'serverfile.filename', 'data.filename' and so on, but I must just be missing it.
    You're missing nothing. It is simply that ColdFusion stores the file in the CFEvent struct as an absolute path. It makes sense, of course. The functionality is directory-watcher, so one should be able to derive information about the directory structure of the added file.

  • How to not append '.PART' to the file name of the currently downloading file, and just download the file with its normal filename

    In Windows, when Firefox (I'm currently using 7.0) downloads a file, it appends ''.PART'' to the file name of the currently downloading file and just renames it to its original file name after it finishes downloading.
    I sometimes like to watch a currently downloading video file, so it will be better if Firefox just downloads the file to its actual filename (like what Opera does), so I can easily double click the incompletely downloaded file and watch it with the video player assigned to that file extension, rather than the awkward ''Right click -> Open With -> Choose Default Program'' route with .part files.
    Does anyone know how to set Firefox to do this?

    It is possible that your anti-virus software is corrupting the downloaded files or otherwise interfering with downloading files by Firefox and prevents Firefox from renaming the .part file.
    Try to disable the real-time (live) scanning of files in your anti-virus software temporarily to see if that makes downloading work.
    See "Disable virus scanning in Firefox preferences - Windows"
    * http://kb.mozillazine.org/Unable_to_save_or_download_files

  • Filenames and the £ character

    hello,
    is the £ symbol supported in filenames on the command line? if not, how are files with £ characters in the name dealt with, or by what name are they given?
    i have a zip file containing a file whose file name contains a £ character, and i am unable to extract this file (using unzip on the command line)
    on other unix based systems the file can be extracted and the £ is usually replaced by a ? or something.
    nb - i'm not after a way to extract the file, i am trying to find out why the system won't let me extract it
    cheers
    jon

    Hi Jon,
       This is an ill-posed question. What character set does the filename use? In what encoding is that character set encoded? The default HFS character set is unicode in canonical, decomposed form and the encoding is UTF-8. What was it on the system from which the file was copied? You can read about "canonical, decomposed form" in the Apple reference, Technote 1150: HFS Plus Volume Format: Unicode Subtleties.
       With what utility are you trying to read that filename? What shell are you using? What terminal are you using? Support for unicode, particularly in "canonical, decomposed form," varies considerably between utilities and even between different versions of each. A precise explanation would require all of this background information, would require considerable analysis on the part of a rather knowledgeable individual and would require a fair amount of typing to treat thoroughly. So unless you have lots of time and find someone capable, you'll have to settle for, "sometimes it works and sometimes it don't." For what it's worth, there are errors in the display more often than there are errors in the way the utilities actually function. I've seen utilities work perfectly when the command output looked like garbage.
       In this case, use an asterisk instead of a question mark and if every other character matches the filename, the command should work as expected. Use an "mv" command to rename the file.
    Gary
    ~~~~
       The greatest griefs are those we cause ourselves.
             -- Sophocles

Maybe you are looking for

  • Error Message "Some content on the PDF is too large to fit on a single page.

    I get the below error when I try to download a response as a .pdf: Some content on the PDF is too large to fit on a single page. Please go to the "Design Tab" and adjust the contents, the font-size, or divide the flagged items into multiple elements.

  • Need Help with the General Understanding WebUtil's Configuration

    We resently installed the following software so that we could migrate our 6i client-server forms to 10g web forms: 1) Oracle Developer Suite 10.1.2.0.2 for Windows (B24499-01, B24500-01) 2) Oracle Oracle Application Server Forms and Reports Services

  • Pass Language report is being run in to RDF as parameter

    I need to figure out how to pass what language was selected when a user runs a report to the rdf file as a parameter. For example, my user default language is English, but I want to run the report in French. When I run the report in French, all of th

  • Problem with CONTAINS query

    Hello, When keyword is coming as "female" then the following query displays "male" keyword as well. Please advise " select c.name, nationality, gender, dob, cvName, j.cv_id "+                               " from users a, cvProperties b, cvDetails c,

  • AIR 3.7 Feedback

    With the new IOS loading abilities introduced in 3.6 & 3.7, I find them pretty limited for a couple of reasons: The fact that the complier strips AS code from the external swf files and embeds it in the main swf file means that anytime my assets chan