Commit 53947dc8 authored by Maarten de Waard's avatar Maarten de Waard 🤘🏻
Added limitations based on page from cryptops docs

parent 3a917221
End points:
\item \texttt{GET} /encryption
\item \texttt{POST} /encryption/init
\item \texttt{POST} /encryption/remove
\item \texttt{POST} /encryption/unlock
\item \texttt{POST} /encryption/selfdestruct
\item \texttt{GET} /encryption/keys
\item \texttt{POST/PUT} /encryption/keys/{slot}
\item \texttt{DELETE} /encryption/keys/{slot}
\item \texttt{GET} /ssh/keys
\item \texttt{POST/PUT} /ssh/keys/
\item \texttt{DELETE} /ssh/keys/{key}
\begin{frame}{Possible reasons to use CryptOps}
\item Make it harder for hoster to view your data on disk
\item An easy way to cut off hoster's access to your data
% maybe when they change owners, or when you anticipate that they are
% forced by some authority to grant access to your data.
\item Be safe when hoster's disks get confiscated, stolen, or discarded
without shredding.
\item You want your data to be encrypted at rest.
\begin{frame}{\emph{Invalid} reasons to use CryptOps}
\item No trust in hoster, because they can:
\item Install a modified version of CryptOps that doesn't really encrypt
\item Man-in-the-middle your ssh connection to the server running in the
initrd, capturing your encryption password when you enter it
\item Access your data in memory while your vps is active
\item Various other methods
\begin{frame}{Possible reasons \emph{not} to use CryptOps}
\item Increased chance of data loss by losing password
\item Increased downtime of your vps (locked state)
\item Some applications support encryption
% which may be the more convenient choice for your data security
\item App for unlocking? Sky is the limit with the API
\item Encrypted RAM?
