news.volyx.in

Since Linux 6.9, LUKS suspend stopped wiping disk-encryption keys from memory (mathstodon.xyz)

539 points by IngoBlechschmid · 57 days ago · 226 comments on HN

Article summary

The article discusses an issue with Linux kernel 6.9 where LUKS suspend no longer wipes disk-encryption keys from memory. This has implications for security and data protection. The discussion revolves around the trade-offs between different encryption solutions, including BitLocker, FileVault, and Veracrypt. The conversation highlights the complexities of managing encryption in enterprise environments.

Main themes

  • Linux kernel security
  • Encryption solutions
  • Enterprise management
  • Data protection
  • User experience

What commenters say

  • The LUKS suspend issue in Linux kernel 6.9 poses a significant security risk by not wiping disk-encryption keys from memory.
  • BitLocker is a suitable encryption solution for enterprise environments due to its ease of management and integration with Windows.
  • Some users argue that BitLocker's closed-source nature and potential for Microsoft to access recovery keys are significant drawbacks.
  • FileVault is considered a more user-friendly encryption solution, but its optional iCloud Keychain escrow feature can be a concern for some users.
  • The choice of encryption solution depends on the specific needs and priorities of the user or organization, with trade-offs between security, ease of use, and manageability.
  • Enterprise environments often require a balance between security and usability, with some arguing that BitLocker strikes a good balance, while others prefer alternative solutions like Veracrypt.
  • The security of encryption solutions is not just about the technology itself, but also about the user experience and the potential for human error or misuse.
  • Some users prioritize the ability to control their own encryption keys and recovery processes, rather than relying on third-party services or cloud-based solutions.