I keep seeing this in your blog post: "Attackers could [rewrite] /bin/ls into a bindshell."
What does that mean? And how is it related to disk encryption?
What does that mean? And how is it related to disk encryption?
[1] https://en.wikipedia.org/wiki/Shellcode
On the other hand, if the attacker needs to create the connection, the shellcode is called a bindshell because the shellcode binds to a certain port on which the attacker can connect to control it.
This service if I remember encrypts files/container with user keys then they encrypt it again on their cloud backup with their key, so it's not an encrypted backup sitting on a dropbox server. Of course you have to trust their keys won't be stolen by somebody wanting at those XTS-AES encrypted backups.