Re: "here strings" and tmpfiles

From: Daniel Kahn Gillmor
Subject: Re: "here strings" and tmpfiles
Date: Thu, 11 Apr 2019 10:42:52 -0400

On Thu 2019-04-11 10:04:02 +0200, Andreas Schwab wrote:
> On Apr 10 2019, Daniel Kahn Gillmor <address@hidden> wrote:
>> data written to the local filesystem can be discovered by someone
>> analyzing the disk controller data path, or by someone with access to
>> the underlying storage medium.
> Do you have swap enabled?

The machines i use that have swap have it enabled via dmcrypt with an
ephemeral key, so no cleartext RAM is ever written to disk.

This is pretty standard practice afaict.


