On Wed, 30 Sep 2026 09:27:10 -0400
Dan Cross <[email protected]> wrote:

> An additional resource you didn't mention explicitly, but that may
> help your mental model, is the paper, "Security in Plan 9" by Cox,
> Grosse, and Pike. https://9p.io/sys/doc/auth.html

Amazing, thank you, I will add this to the reading list!
> > - Without turning the laptop into a cpu/auth server, how do I
> >   set up secstored? Where is it best invoked when the system boots,
> > and how do I make sure it is reachable on tcp!127.0.0.1!5356 ?  
> 
> I think that running `secstored` on your laptop, just to protect your
> WiFi password, is a bit overkill.  There is an `aescbc` command that
> can be used for encrypting locally stored files; you could put your
> WiFi password into a text file, encrypt it with some password/phrase
> of your choosing, and decrypt/cat it into factotum when you startup
> your laptop. Of course, you'd have to enter the password manually, and
> the file is potentially vulnerable to offline dictionary attacks,
> depending on the strength of the password you choose, but its probably
> fine against all but state-level actors. I wrote a little program I
> called "micro-secstore" to do just this back in the early 2000s; it
> was just a wrapper around `aescbc` that used a provided a slightly
> more convenient interface.

Thank you very for the pointer to it. 

I did figure this out meanwhile. 

Although I had little luck with IPV4, I realised that IPV6 comes to the
rescue in this situation. I simply set secstored to listen on the
default IPV6 address for the machine that was available in
/net/ipselftab on boot without any other connections. This way I could
get factotum to work on its own.

So I added:
        secstore=tcp!fe80::a9e:1ff:fe34:c497!5356
to plan9.ini,

And then, after the usual secstore setup (creating dirs in /adm,
installing a secstore user, etc) in termrc I added:
        auth/secstored -s $secstore
as well as adding 'secstored' to the final 'dontkill' command at the
end. (I am not quite sure I need to do this but looked like a good
idea?)

I still have to feed keys manually into factotum with `auth/secstore -G
factotum` but I can now automate that at boottime or before rc starts.

What I don't know tho -- if I subsequently add new keys to factotum with
"echo ... > /mnt/factotum/ctl", how do those make it back into secstore
this way?

> One could imagine trying to leverage a TPM or something as a secure
> enclave to hold secrets for boot, but as far as I know that
> infrastructure doesn't exist, and again, the simplest route is
> probably just to locally encrypt a text file.

Thank you -- I think there were suggestions of using cryptsetup
partitions and thumbdrives in the earlier thread; or I suppoes a
yubikey or similar could also be a solution. But this is "good enough"
for me at the moment.

> ------------------------------------------
> 9fans: 9fans
> Permalink:
> https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M41c312165ae32e0fb18469ab
> Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

------------------------------------------
9fans: 9fans
Permalink: 
https://9fans.topicbox.com/groups/9fans/Tcf9c4dd764d4b456-M28a2b637ba3f153a10ef3975
Delivery options: https://9fans.topicbox.com/groups/9fans/subscription

Reply via email to