memfd_secret() in 5.14
memfd_secret() in 5.14
Posted Aug 7, 2021 9:46 UTC (Sat) by khim (subscriber, #9252)In reply to: memfd_secret() in 5.14 by mb
Parent article: memfd_secret() in 5.14
> Let the user decide whether the risk of having an (encrypted) hibernation image is Ok or not.
How many times should we do the same mistake again and again? It doesn't work with security. Dancing pigs effect is very well known by now.
Case to the point:
> I use the kernel key management for disk + swap (hibernate) encryption. Doesn't that wipe the key cache (after some timeout)?You don't even know how the whole thing works yet presume to be able to do the right choice. Most users know even less than you. They only know that “no security” knob gives them dancing pigs and the other one doesn't. Thus they would choose the “no security” knob 10 times out of 10.
> However disabling hibernation or killing random apps does completely destroy the UX and it will prevent the widespread adoption of this security feature.That's fine. Unused feature doesn't waste any resources and can even be removed, eventually. “Security theatre” feature does waste the resources without providing any benefits. Thankfully Linux kernel is not developed by a corporation which would perceive security buzzwords more important than actual security thus they are not introducing features for press-releases, but for actual use.
