From: Arno Wagner <arno@wagner.name>
To: dm-crypt@saout.de
Subject: Re: [dm-crypt] Re : Re : Re : Poor performances with nfs and Kernel 3.x
Date: Sun, 26 Feb 2012 22:39:31 +0100 [thread overview]
Message-ID: <20120226213931.GA2280@tansi.org> (raw)
In-Reply-To: <1330291771.886.YahooMailNeo@web29603.mail.ird.yahoo.com>
On Sun, Feb 26, 2012 at 09:29:31PM +0000, Mickael wrote:
>
[...]
>
> PS: about point 3: Have you ever thinking adding an option to cryptsetup
> to do a benchmark like this: http://www.truecrypt.org/screenshots2 (I
> guess everyone build his own one) In fact, with the speed, it will be
> great to have an idea about the security level of? each cipher too. But
> is it possible to calculate such index ? For example, is the slowest
> cipher the most secure ?
Unfortunately, no. Ciphers get broken overt time and at some point
they become practiclly insecure, depending on attacker model.
This means cipher security is always an expert opinion as not all
people working on breaking a cipher will publish their results.
Then there is another factor: If somebody can break a cipher,
for what kind of informatin will they admit they can (by using
that nformaton)? And to make matters more complicated, once somebody
adits to being able to break a certain cipher, they may also
use that capability for things of far lesser worth.
Cyrrent advice is to use AES for everything that needs to be
secure. The other AES-finalists should also be pretty good and
some may be more secure than AES in fact. Not that it matters
at this time.
Also note that TrueCrypt ffers cobinaton of ciphers where
(hopefully) all have to be broken to access the secrets.
dm-crypt does not do that, byt you can manyally layer diffent
ciphers if you want it.
Arno
--
Arno Wagner, Dr. sc. techn., Dipl. Inform., CISSP -- Email: arno@wagner.name
GnuPG: ID: 1E25338F FP: 0C30 5782 9D93 F785 E79C 0296 797F 6B50 1E25 338F
----
One of the painful things about our time is that those who feel certainty
are stupid, and those with any imagination and understanding are filled
with doubt and indecision. -- Bertrand Russell
next prev parent reply other threads:[~2012-02-26 21:39 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-02-06 22:28 [dm-crypt] Poor performances with nfs and Kernel 3.x Mickael
2012-02-07 8:11 ` Arno Wagner
2012-02-07 8:33 ` Arno Wagner
2012-02-08 15:04 ` [dm-crypt] Re : " Mickael
2012-02-08 15:26 ` Arno Wagner
2012-02-08 17:55 ` [dm-crypt] Re : " Mickael
2012-02-09 7:37 ` Arno Wagner
2012-02-09 9:34 ` Matthias Schniedermeyer
2012-02-09 10:19 ` Milan Broz
2012-02-09 12:04 ` Arno Wagner
2012-02-26 21:29 ` [dm-crypt] Re : " Mickael
2012-02-26 21:39 ` Arno Wagner [this message]
2012-02-08 14:55 ` [dm-crypt] " Mickael
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120226213931.GA2280@tansi.org \
--to=arno@wagner.name \
--cc=dm-crypt@saout.de \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.