On Tue, Sep 29, 2026 at 7:55 PM requiem. via 9fans <[email protected]> wrote:
> I am trying to use 9front on a laptop and I stumbled into the 'how do I
> store the wifi password securely without an auth server' issue.
>
> I know I am not the first to ask this, and I did read through the thread
> from December 2024 [1] on this, as well as relevant manpages, and
> other materials online. A lot of it is very helpful and it helped me
> understand how factotum and secstored work together _in theory_ but
> somehow it still doesn't entirely click for me; I am still not
> succeeding with storing and retrieving things from secstore locally, so
> I am wondering whether anyone could offer some clarification on the
> following:

An additional resource you didn't mention explicitly, but that may
help your mental model, is the paper, "Security in Plan 9" by Cox,
Grosse, and Pike. https://9p.io/sys/doc/auth.html

> - Without turning the laptop into a cpu/auth server, how do I
>   set up secstored? Where is it best invoked when the system boots, and
>   how do I make sure it is reachable on tcp!127.0.0.1!5356 ?

I think that running `secstored` on your laptop, just to protect your
WiFi password, is a bit overkill.  There is an `aescbc` command that
can be used for encrypting locally stored files; you could put your
WiFi password into a text file, encrypt it with some password/phrase
of your choosing, and decrypt/cat it into factotum when you startup
your laptop. Of course, you'd have to enter the password manually, and
the file is potentially vulnerable to offline dictionary attacks,
depending on the strength of the password you choose, but its probably
fine against all but state-level actors. I wrote a little program I
called "micro-secstore" to do just this back in the early 2000s; it
was just a wrapper around `aescbc` that used a provided a slightly
more convenient interface.

> - Related to the above; I don't think a loopback interface is set up on
>   9front by default; do I need to create it before starting secstored
>   for my scenario, and if yes, what is the correct way to do it? (I can
>   see the `ip/ipconfig loopback` commands in the manpage but where do I
>   put them -- perpaps /bin/termrc? Elsewhere?)

See above. If you want to set up a loopback interface anyway, however,
I'd do so in `/rc/bin/termrc.local` or `/cfg/$sysname/termrc`. You
could also start `secstored` from there, as well.

> - Is there a way to specify the secstored address globally, so I don't
>   have to specify it everytime I run `auth/secstore`? Do I just specify
>   an "auth" env variable in plan9.ini or similar? Wouldn't doing so
>   mess with other things that now presume I have an actual auth server
>   running somewhere?

Yes. `secstore` will look at `$secstore` if you don't explicitly
specify a store on the command line.

> - Do I have this all backwards? Instead of trying to run auth services
>   on a terminal machine; should I be looking at effectively turning the
>   machine into a CPU server and somehow run rio on it? If so, how,
>   without an active network connection (ie. before wifi is up)?

Probably not. There's nothing particularly special about a CPU server;
the differences compared to a terminal kernel are minor. Mostly it's
about what programs are started at boot, from /rc/bin/cpurc or
/rc/bin/termrc, respectively. If you really want to run `secstored`
locally, you can just run it locally, and assuming all the directories
it wants are created and writeable and so on, it should just work.
However, bear in mind that CPU servers are "supposed" to be physically
secure, and often steal e.g. an unused disk block to hold unencrypted
secrets.

One could imagine trying to leverage a TPM or something as a secure
enclave to hold secrets for boot, but as far as I know that
infrastructure doesn't exist, and again, the simplest route is
probably just to locally encrypt a text file.

        - Dan C.

------------------------------------------
9fans: 9fans
Permalink: 
https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M41c312165ae32e0fb18469ab
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

Reply via email to