This forum has been archived. All content is frozen. Please use KDE Discuss instead.

Why unlocking KWallet on login require disabling autologin?

Tags: None
(comma "," separated)
kmph
Registered Member
Posts
1
Karma
0
If full disk encryption is being used, it seems redundant to have to to enter password on login as well. Apparently, this is not my idea. From Security StackExchange, question Is automatic login with full disk encryption a risk?

Question wrote:I use full disk encryption on Linux and wonder whether there is any security risk ob having automatic login on the Linux itself. In case somebody breaks the encryption of the drive, they can read all the data directly, they would not have to log in to my Linux user account on the machine.

So is there any reason I should not use automatic login (into KDE) on a machine with FDE?
Answer wrote:No risk at all. A login prompt is only for preventing physical access to the computer. This protection role has been replaced by the FDE and the accompanying PBA (which is much more secure), so any attacker that would break or somehow bypass the FDE could bypass your OS login too. (...)


Yet, AFAIK, KDE Wallet requires autologin to be disabled if it is to unlock automatically on login. However, unlocking KWallet is still necessary to connect to known WiFi networks. As a result, booting such a computer requires: (a) Typing in FDE password; (b) Typing in user account password; (c) Typing in KWallet password if one uses GPG since, (correct me if I'm wrong), autounlocking wallet on login is incompatible with GPG.

Having to enter 2 to 3 passwords each time one boots their desktop seems redundant, tedious and unnecessary. Given that FDE, seemingly, is becoming the general advice for all people, including "Average Joes" (to help protect against otherwise likely catastrophic consequences of device theft), I'm not sure if requiring entering two passwords on each boot is needed or productive.

What am I failing to understand and why does KWallet enforce that?


Bookmarks



Who is online

Registered users: bartoloni, Bing [Bot], Google [Bot], q.ignora, watchstar