TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Cracking LUKS/dm-crypt passphrases

105 点作者 dvaun超过 5 年前

5 条评论

loeg超过 5 年前
Maybe it goes without saying, but for this to work, your password must be bad to begin with. Or at least, the article does not point to any significant design weaknesses in LUKS; it instead documents a variety of ways to get passphrase-encrypted secrets into existing tools for bruteforcing passwords. The article suggests it is about backup or data recovery, but I think it is probably more interesting to people in the business of digital forensics.
评论 #21792455 未加载
评论 #21794980 未加载
评论 #21792735 未加载
评论 #21792907 未加载
Aardwolf超过 5 年前
I admit I didn&#x27;t read the entire article, I&#x27;ve been reading only the text around instances of argon and PBKDF, but:<p>can someone ELI5 how they do 882 hashes per second if PBKDF2 is set up to take 2 seconds, for example? What&#x27;s so broken about PBKDF2 that they get a &gt; 1000x speedup?
评论 #21793760 未加载
评论 #21794996 未加载
评论 #21792950 未加载
评论 #21793254 未加载
quotemstr超过 5 年前
Sure. That&#x27;s why I wish I could do LUKS authentication via TPM, which can do hardware rate-limiting. Is this kind of setup possible these days?
评论 #21793908 未加载
luksflux超过 5 年前
Good luck with people like me. As ypu know, luks per default allows over 8 megabytes of key, so, i just make a dev&#x2F;urandom file that is up to the byte filling the top default keysize, which means a password of over 8 million characters, of which none or very few at best are found via the keyboard. I use at the minimum 8 million chars on all my luks devices. And I&#x27;ve set the key stretching to take above 15 mins to unlock, even with the right password, so good luck with John the ripper.
评论 #21793784 未加载
评论 #21792941 未加载
评论 #21792599 未加载
评论 #21793064 未加载
评论 #21792820 未加载
AdmiralAsshat超过 5 年前
I peaked at some of the stats regarding his brute force attempt, but I couldn&#x27;t figure out how much progress he was making and whether a bf was actually feasible with LUKS. Is it something to be concerned about at this stage?
评论 #21793724 未加载