logoalt Hacker News

teddyhyesterday at 1:12 PM2 repliesview on HN

You can reboot your full-disk-encryption server while you sleep. Obligatory plug: <https://www.recompile.se/mandos>

Disclosure: I am a co-author of Mandos.


Replies

prennertyesterday at 1:36 PM

Has this solution been audited? In particular, is it safe to replay attacks by actors listening in to the network traffic?

Also from the diagram it looks like the secret key is stored unencrypted on the server, or do I read it wrong?

show 1 reply
gerdesjyesterday at 4:20 PM

Thank you for this. I will almost certainly be deploying that.