[Pkg-cryptsetup-devel] Bug#477203: Bug#477203: cryptsetup: LUKS passphrase sometimes in cleartext

Jonas Meurer jonas at freesources.org
Fri Jun 13 15:31:12 UTC 2008


On 21/04/2008 Daniel Blaschke wrote:
> I have an encrypted /home partition and usplash is installed. Whenever I'm
> not quick enough entering the LUKS passphrase, usplash times out and in
> order to continue the boot process I need to switch to tty 8 where I can
> enter the passphrase. And here's the security problem: As I type, the
> passphrase appears as cleartext on the screen...

Hello Daniel,

Could you try whether cryptsetup 1.0.6-2 fixes the bug? The way how the
initramfs prompts for the passphrase has been changes in 1.0.6-2, an
external binary called askpass has been introduces by David Härdeman and
is used now for passphrase retrieval.

We hope that askpass fixes the issue you described here.

greetings,
 jonas





More information about the Pkg-cryptsetup-devel mailing list