Encrypted private directories coming to Ubuntu

| | Comments (0) |

Encrypted private directories are the one thing that would get me to upgrade to Ubuntu 8.10 this October. Ubuntu's Dustin Kirkland explains it all:

How does it work?

The underlying technology is a cryptographic virtual filesystem in the Linux kernel called eCryptfs, authored by Michael Halcrow of IBM.

When a user logs into an Ubuntu Intrepid system, their login passphrase is automatically used to decrypt a randomly generated mount passphrase. This mount passphrase will then cryptographically mount ~/.Private onto ~/Private. As long as ~/Private is mounted, the user can read and write sensitive data to files and directories under the virtual filesystem on ~/Private. The actual files stored in the underlying filesystem are encrypted, and located in ~/.Private. The only passphrase required is obtained when logging in (via console, ssh, gdm, etc). And the only files encrypted are those that the user consciously places in ~/Private. The user can then incrementally backup the encrypted ~/.Private directory to off-site storage.

I'd really, really, really like to see a backport of this to Ubuntu 8.04 LTS so I can keep the current version of the distro if I so choose.

I'll be looking at Ubuntu Backports and GetDeb to see if installing it in Hardy is possible. ... or I may just upgrade to Intrepid.

More information:

  • The Ubuntu Wiki on encrypted private directories
  • Leave a comment

    Tech Talk column

    Steven Rosenberg's weekly Tech Talk column, which appears Saturdays in the Los Angeles Daily News, is now available on the Daily News Technology page.

    About this blog

    Comments are back: Comments have returned to Click, but due to the thousands of spam comments clogging up the system each day, commenters must now log in. To comment, either create a Movable Type account when prompted, or create and use a Typekey account. Movable Type, as configured on this blog, allows commenters to create a Movable Type account, verify it via e-mail and then sign in to comment. Other methods of verification are OpenID, Live Journal and Vox.




    Steven Rosenberg aims to learn what he does not know. He writes about it here.



    About this Entry

    This page contains a single entry by Steven Rosenberg published on August 7, 2008 9:00 AM.

    Virtualization: It's Greek(or geek) to me was the previous entry in this blog.

    Fat lady sings, and Opera is officially my new favorite browser (this week anyway) is the next entry in this blog.

    Find recent content on the main index or look in the archives to find all content.

    Recent Comments

    Powered by Movable Type 4.21-en

    Advertisement

    Other blogs

    Day 30: 30 baseball books in 30 days of April, '09: Let's keep this thing going in Farther Off the Wall
    The Sol's Mother's Day Incentive in 100 Percent Soccer
    Morning Buzz in Inside USC with Scott Wolf
    Slow car sales take a toll in The Sausage Factory
    TRACK AND FIELD: Big day for Saugus seniors in Daily News High School Spotlight