memfd_secret() in 5.14
memfd_secret() in 5.14
Posted Aug 7, 2021 9:35 UTC (Sat) by mb (subscriber, #50428)In reply to: memfd_secret() in 5.14 by khim
Parent article: memfd_secret() in 5.14
>Usually it's encrypted with the key which can be found in kernel memory somewhere
I use the kernel key management for disk + swap (hibernate) encryption.
Doesn't that wipe the key cache (after some timeout)?
I understand that hibernation reduces the security of memfd_secret().
However disabling hibernation or killing random apps does completely destroy the UX and it will prevent the widespread adoption of this security feature.
Let the user decide whether the risk of having an (encrypted) hibernation image is Ok or not.
