[Bug 1928860] Re: Recovery key is low-entropy

2021-08-08 Thread Jean-Baptiste Lallement
ubiquity (21.10.4) impish; urgency=medium [ Didier Roche ] [ Jean-Baptiste Lallement ] * Make the recovery key a 48 digits password by default (LP: 1928860) * Recovery key is editable and optional. * Show the recovery key during manual partitioning. * Display a warning if recovery

[Bug 1928860] Re: Recovery key is low-entropy

2021-07-23 Thread Brian Murray
** Changed in: ubiquity (Ubuntu Impish) Milestone: None => ubuntu-21.10 ** Changed in: ubiquity (Ubuntu Impish) Milestone: ubuntu-21.10 => ubuntu-21.10-beta -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-28 Thread Alex Murray
Thanks jibel! -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928860 Title: Recovery key is low-entropy To manage notifications about this bug go to:

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-27 Thread Jean-Baptiste Lallement
This is being worked on. In summary the following changes will be done in 21.10: - The length of the generated numerical key will be increased to 48 digits (like bitlocker) - It will be optional - It will be editable and accept letters, digits and special characters. ** Changed in: ubiquity

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-27 Thread Jean-Baptiste Lallement
** Changed in: ubiquity (Ubuntu Impish) Assignee: (unassigned) => Jean-Baptiste Lallement (jibel) -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928860 Title: Recovery key is low-entropy To

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-27 Thread Brian Murray
** Tags removed: rls-ii-notfixing ** Also affects: ubiquity (Ubuntu Impish) Importance: High Status: Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928860 Title: Recovery key

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-27 Thread Brian Murray
** Tags removed: rls-ii-incoming ** Tags added: rls-ii-notfixing -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928860 Title: Recovery key is low-entropy To manage notifications about this bug go

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-20 Thread Madars
Hi all, LUKS2 (in zys-format invocation of the corresponding cryptsetup version) uses Argon2i password-based key deriviation function and automatically tunes the iteration count/memory cost to be under 2000 milliseconds. Note that this is timed on the target's machine, and attacker's machines

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-20 Thread Seth Arnold
Thanks Sebastian for the reference; I hunted around the Internet to try to find references for current 'best' cracking speed for luks2 without much success. Alex's results are suddenly the best I've seen. 200 years sounds like a long time in isolation but that's also just spinning up 2000 cloud

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-20 Thread Sebastien Bacher
Thanks, there are also some discussions on https://discourse.ubuntu.com/t/ubuntu-21-04-encryption-recovery-key about the key security which concluded that a brute force attack would take a very long time to success. Could you give some details on the 'within capabilities of offline brute-force

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-19 Thread Seth Arnold
Excellent, thanks Madars. I think you're right, something closer to 80 bits would probably make more sense, and if it were output with base64 rather than a decimal string it might not be significantly harder to work with. Thanks -- You received this bug notification because you are a member of

[Bug 1928860] Re: Recovery key is low-entropy

2021-05-19 Thread Seth Arnold
** Information type changed from Private Security to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1928860 Title: Recovery key is low-entropy To manage notifications about this bug