google / fscrypt

Go tool for managing Linux filesystem encryption
Apache License 2.0
886 stars 99 forks source link

Adjust recovery passphrase generation #315

Closed ebiggers closed 3 years ago

ebiggers commented 3 years ago

As per the feedback at https://github.com/google/fscrypt/issues/115 where users didn't understand that the recovery passphrase is important, restore the original behavior where recovery passphrase generation happens automatically without a prompt. This applies to the case where 'fscrypt encrypt' is using a login protector on a non-root filesystem.

However, leave the --no-recovery option so that the recovery passphrase can still be disabled if the user really wants to. Also, clarify the information provided about the recovery passphrase.

Update https://github.com/google/fscrypt/issues/115

ebiggers commented 3 years ago

@josephlr any feedback on this?