On Wed, 30 Sep 2026 09:27:10 -0400 Dan Cross <[email protected]> wrote:
> An additional resource you didn't mention explicitly, but that may > help your mental model, is the paper, "Security in Plan 9" by Cox, > Grosse, and Pike. https://9p.io/sys/doc/auth.html Amazing, thank you, I will add this to the reading list! > > - Without turning the laptop into a cpu/auth server, how do I > > set up secstored? Where is it best invoked when the system boots, > > and how do I make sure it is reachable on tcp!127.0.0.1!5356 ? > > I think that running `secstored` on your laptop, just to protect your > WiFi password, is a bit overkill. There is an `aescbc` command that > can be used for encrypting locally stored files; you could put your > WiFi password into a text file, encrypt it with some password/phrase > of your choosing, and decrypt/cat it into factotum when you startup > your laptop. Of course, you'd have to enter the password manually, and > the file is potentially vulnerable to offline dictionary attacks, > depending on the strength of the password you choose, but its probably > fine against all but state-level actors. I wrote a little program I > called "micro-secstore" to do just this back in the early 2000s; it > was just a wrapper around `aescbc` that used a provided a slightly > more convenient interface. Thank you very for the pointer to it. I did figure this out meanwhile. Although I had little luck with IPV4, I realised that IPV6 comes to the rescue in this situation. I simply set secstored to listen on the default IPV6 address for the machine that was available in /net/ipselftab on boot without any other connections. This way I could get factotum to work on its own. So I added: secstore=tcp!fe80::a9e:1ff:fe34:c497!5356 to plan9.ini, And then, after the usual secstore setup (creating dirs in /adm, installing a secstore user, etc) in termrc I added: auth/secstored -s $secstore as well as adding 'secstored' to the final 'dontkill' command at the end. (I am not quite sure I need to do this but looked like a good idea?) I still have to feed keys manually into factotum with `auth/secstore -G factotum` but I can now automate that at boottime or before rc starts. What I don't know tho -- if I subsequently add new keys to factotum with "echo ... > /mnt/factotum/ctl", how do those make it back into secstore this way? > One could imagine trying to leverage a TPM or something as a secure > enclave to hold secrets for boot, but as far as I know that > infrastructure doesn't exist, and again, the simplest route is > probably just to locally encrypt a text file. Thank you -- I think there were suggestions of using cryptsetup partitions and thumbdrives in the earlier thread; or I suppoes a yubikey or similar could also be a solution. But this is "good enough" for me at the moment. > ------------------------------------------ > 9fans: 9fans > Permalink: > https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M41c312165ae32e0fb18469ab > Delivery options: https://9fans.topicbox.com/groups/9fans/subscription ------------------------------------------ 9fans: 9fans Permalink: https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M28a2b637ba3f153a10ef3975 Delivery options: https://9fans.topicbox.com/groups/9fans/subscription
