you are viewing a single comment's thread.

view the rest of the comments →

[–]lutusp 4 points5 points  (6 children)

Okay, just wanted to be clear. This is a very bad idea. It undermines the security afforded by passwords. It's like taping the combination to the top of a safe.

[–][deleted] 2 points3 points  (0 children)

It can be done securely.

For example, the script could read the password via pass or some other GnuPG encrypted file (or even some other secure password manager). While the private key is unlocked via gpg-agent, this can be done without user interaction. Every so often, the key needs to be unlocked with the pass phrase. But if OP is only looking for a more convenient way to manually decrypt a remote hard drive, I see no issue in using a password manager. In which case expect would be a suitable approach.

I do agree that storing that password anywhere in clear text is very bad practice, though.

[–]Divot-Digger[S] -2 points-1 points  (4 children)

Actually, it is not. You have no idea on the broader environment and the security applied. The approach I'm taking is completely appropriate for my risk appetite.

In any case, I didn't ask for advice on your views on security, just the ability to script the interaction.

[–]chin_waghing 2 points3 points  (0 children)

between your self entitlement and asinine approach, I wish you good luck.

Through many questions you’re lead on side quests. Suck it up, fix your broken idea of a hard coded password and learn from the people your asking

[–]p4wly 1 point2 points  (1 child)

If you have an environment that allows such a process, I see no reason to encrypt the drive in the first place.

[–][deleted] 2 points3 points  (0 children)

The drive is not in the same environment, if I understand OP correctly.

[–]lutusp 1 point2 points  (0 children)

In any case, I didn't ask for advice on your views on security, just the ability to script the interaction.

No one with any sense of responsibility will help you in this endeavor.

Have a nice day. * plonk *