- WD Community
- :
- Network Devices
- :
- Network Product Ideas
- :
- Support disk encryption of /DataVolume partition
- WD Community
- News & Assistance
- Announcements
- New to Community
- Forum Feedback
- Off-Topic
- Software & Apps
- WD Software
- WD Mobile Apps
- Software & Accessory Ideas
- WD TV Live Streaming
- Live Streaming Discussions
- Live Streaming Firmware
- Live Streaming Ideas
- Live Streaming Issues
- WD TV Live Hub
- Hub Discussions
- Hub Firmware
- Hub Themes
- WD TV Live Hub Ideas
- WD TV Live Hub Issue Reporting
- WD TV Play
- WD TV Play
- Live & Live Plus
- Live Discussions
- Live Firmware
- Elements Play
- Elements Play
- External Drives
- Mac Externals
- PC Externals
- Portable Drives
- External Drive Ideas
- Network Devices
- Networking Devices
- Live Duo
- Sentinel
- My Book Live
- Other Network Drives
- Network Product Ideas
- Internal Drives
- Desktop & Portable
- Internal Drive Ideas
- Anuncios
- Noticias
- Nuevo a La Comunidad
- Los Productos de WD
- Software y Accesorios
- Reproductores Multimedia
- Unidades de Red
- Unidades Externas
- Unidades Internas
- Ankuendigungen
- Neuigkeiten
- Neu in der Community
- WD Produkte
- WD Programme
- WD TV Media Player
- Netzwerk Laufwerke
- Externe Laufwerke
- Interne Laufwerke
- Annunci
- Annunci e Novita'
- Nuovo per La Comunita'
- Prodotti WD
- Programmi & Accessori
- Riproduttori Multimediali
- Dischi di Rete
- Dischi Esterni
- Dischi Interni
- WD TV Legacy
- Hub Network
- Live Networking
- WD TV HD
- WD TV Mini
- Software
- WD Photos
- Other Software & Accessories
- Hard Drives
- WD ShareSpace
- Other Externals
- Other Internal Drives
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Email to a Friend
- Printer Friendly Page
- Report Inappropriate Content
Support disk encryption of /DataVolum e partition
Status:
Unplanned
|
Hello,
I would like to suggest that with the next firmware update, the Linux kernel inside the WD Mybook Live should include the non-hardware related modules such as encryption and loopback device modules which are available by default on normal Linux systems.
My goal is to encrypt the /DataVolume volume using the built-in Linux 2.6 full disk encryption and provide a way to unlock the volume once after boot. For me personally, a SSH login would suffice (using libpam-mount), but for most people, providing a way via e.g. WD Quick View would of course be more user friendly.
This way, all data is readable after unlocking it once, but becomes inaccessible once the device loses power (and has to be unlocked again). The Linux 2.6 crypto API provides ways to unlock using multiple passwords, so each user could (theoretically) use his own password to unlock the drive.
I have exactly this set up running in a G4 Mac Mini running Ubuntu, which was my former backup server, but this machine is limited to 250G of storage, and I would LOVE to see WD NAS disk encryption get enabled, with the low power usage it has it would be my definite future backup disk!
|
|
- Mark as Read
- Mark as New
- Bookmark
- Highlight
- Email to a Friend
- Report Inappropriate Content
- Mark as Read
- Mark as New
- Bookmark
- Highlight
- Email to a Friend
- Report Inappropriate Content
Hopefully posting this isn't thoroughly out of order. Following this suggestion probably voids your warranty.
I strongly suspect this is possible for an end user. The source code is available, and a guide on installing a crosscompiler is available on a wiki that I probably shouldn't link to. Using this I have built a loop.ko module, installed it, and now have encfs working beautifully on a my book live.That provides an encrypted folder, but not an entire partition.
Whole partition encryption is slightly different, and it's (considerably) inconvenient that the default settings use a 64kB block size for the ext4 DataVolume. If you're willing to reformat the DataVolume partition (I'll be testing this shortly, but haven't yet) and build a suitable module then whole partition encryption, unlocked over ssh, is well within reach.
- Mark as Read
- Mark as New
- Bookmark
- Highlight
- Email to a Friend
- Report Inappropriate Content
@WDTony,
are those business reasons legally motivated (not being able to sell devices which support encryption in some countries)?
@Jonj678,
how is your progress regarding encrypting the /DataVolume partition?
Also, how do WD's custom made scripts cope with such changes, ie. if /DataVolume cannot be mounted during boot, will it be reformatted automatically?
If I can SSH into the box and follow instructions like these
https://we.riseup.net/debian/automatically-mount-e
(of course, adapted for /DataVolume instead of /home), then I am happy.
I tried doing this but failed (because I could not get the cross compiling kit to run), and thus returned my MyBook Live to Amazon.
Also, I'd like to know whether the Linux kernel uses the ARM CPU's AES hardware supports. This would make using dm_crypt and similar modules really fast.
Regards
- Mark as Read
- Mark as New
- Bookmark
- Highlight
- Email to a Friend
- Report Inappropriate Content
I'd be interested to know whether the AES is hardware accelerated or not, but I do not know how to find out. Any hints would be appreciated ![]()
The restory to factory settings scripts reformat /DataVolume. At some point xfs must have been considered, as that's commented out, but the weird blocksize is passed in the script. Changing to ext3 and bs=4k would be very simple if running a factory restore, otherwise one can just reformat it. I haven't but some other people have had success with parted (resizing partitions in particular).
You certainly can ssh into the box. I can't persuade it to compile modules locally, but have got a crosscompiler running as advised on a wiki. The required dm-mod, dm-crypt, cryptoloop compile and insert with no bother, and the device is then quite happy creating an encrypted volume on loopback. I'm certain it'll encrypt /dev/sda4 quite happily once I find the enthusiasm to pull all the data off, reformat, and push the data back on.
Cheers
You must be a registered user to add a comment here. If you've already registered, please log in. If you haven't registered yet, please register and log in.
For a list of our Idea Exchanges, please click here.
Idea Statuses explained here.
-
defdef
on:
My Net 750 - Limiting power consumptio
n of attache... -
Zumfidl
on:
Functional "WOL" implementa
tion - RocketScience on: WD MyNet parental control features
- Ben342018 on: [Request] Shutdown / Reboot Button next to Logout ...
- Comm2000 on: Port Triggering for MyNet N900
- mirkokid on: File & Folder mail Link sharing from WD2go app as ...
- panga on: MBL / Twonky Changes
- nicopizza on: windows 8 is fast coming...
- iammike on: Access my I-tunes library and view m4v files
-
timsbuck2
on:
Remove mediacrawl
er from MyBook Live
- Provide different level of access to Folder and Su...
- Auto turn off
- Remove "Shared Videos" folders
- MACs / LAN networks (WD MyNet 900 Central).
- Log-out time.
- Solve the problem of wrong character copy for SAFE...
- To be able to put proxy parameters
- Access web GUI from wireless option
- Truecrypt
- add function to n750 and n900
-
Auto-Logout Dashboard
(1) -
backup
(1) -
BIG hard drive
(1) -
BT
(1) -
Channel Width
(1) -
compare
(1) -
Copy Manager
(1) -
Data loss
(1) -
dlna
(2) -
DLNA server
(1) -
download
(1) -
Feature
(1) -
file
(1) -
firmware
(1) -
firmware updates
(1) -
folder
(2) -
internet download
(1) -
iTunes
(1) -
link
(1) -
local
(1) -
mail
(1) -
Map
(1) -
mediacrawler
(1) -
MKV
(1) -
My Book Live
(3) -
Mybook Live
(4) -
N750
(1) -
NAS
(1) -
network control
(1) -
network drive
(1) -
newsreader
(1) -
nfs
(1) -
NFS4
(1) -
on My
(1) -
performance
(1) -
playlists
(1) -
power management
(1) -
power saving
(1) -
protokoll
(1) -
Proxy parameters
(1) -
Raid
(1) -
RAID-5
(1) -
recovery
(1) -
Remote
(1) -
Request
(1) -
RSYNC
(1) -
Schedule Power Up Down for My Book World Edition
(1) -
SFTP
(1) -
shares
(1) -
Sharespace
(2) -
sharing
(2) -
Sort order in MyBook Live twonky media server
(1) -
sub folder
(1) -
time machine
(1) -
torrent
(1) -
UPNP
(1) -
usenet newsgroups
(1) -
validation
(1) -
WD MYBook LIVE Apps
(1) -
wd2go
(2) -
wd2go.com
(1) -
WebOS
(1) -
Wireless Setup
(1) -
WOL
(1)
- New (93)
- Acknowledged (32)
- Duplicate Idea (5)
- Unplanned (37)
- In Review (3)
- Pending (0)
- Implemented (5)
| Forums | Ideas | News and Announcements | Register | Sign in | Help | Forum Guidelines | |


