DM-Crypt Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [dm-crypt] 1,5 TB partition: use cbc-essiv or xts-plain?
@ 2009-08-03 12:53 Henrik Theiling
  2009-08-03 14:34 ` Heinz Diehl
                   ` (3 more replies)
  0 siblings, 4 replies; 24+ messages in thread
From: Henrik Theiling @ 2009-08-03 12:53 UTC (permalink / raw)
  To: dm-crypt

Hi!

While trying to make a decision of how to encrypt a large disk, I
found no good answer yet.  What I am searching for is a site that
gives me a simple overview of pros and cons of the different choices
to be made when selecting LUKS algorithms.  Yet, I found nothing like
that.

In this particular case: for a 1,5 TB partition, should I use
cbc-essiv or xts-plain?

It seems cbc-essiv is susceptible to watermarking (according to
Wikipedia, which claims that no IV obfuscation algorithm protects
against this except in the initial block.  Unfortunately, I cannot
verify this, so it sounds bad to me.

And then, xts-plain is said to become weaker on large disks, and some
crypto implementations warn about this weakness for disks as small as
500GB.  So what's the alternative?  (If I understand correctly, LUKS
has no multi-key XTS option for large disks, right (in case that would
overcome the problem)?)

I don't seem to be able to make a decision on my own, so I'd like to
ask for help.  Which problem is worse?  Or are there ways to overcome
both problems?  I could probably split the disk and re-assemble the
xts-plain encrypted parts in a RAID, but that seems very complex.
There don't need to be simple answers -- I am willing to evaluate my
problem thoroughly, but so far I found no good comparison.

Bye,
  Henrik

^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2013-01-03 10:05 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-03 12:53 [dm-crypt] 1,5 TB partition: use cbc-essiv or xts-plain? Henrik Theiling
2009-08-03 14:34 ` Heinz Diehl
2009-08-03 16:16   ` Henrik Theiling
2009-08-03 17:34     ` Heinz Diehl
2009-08-03 17:37       ` Heinz Diehl
2013-01-03  9:50       ` Peter Pfundstein
2009-08-03 14:43 ` [dm-crypt] E3E-2A1 - 1, 5 " Heinz Diehl
2009-08-03 20:48 ` [dm-crypt] 1,5 " Moji
2009-08-04  7:42   ` Milan Broz
2009-08-04 13:01   ` Henrik Theiling
2009-08-03 21:46 ` Moji
2009-08-04 13:27   ` Henrik Theiling
2009-08-04 13:55     ` Moji
2009-08-06 11:02   ` Salatiel Filho
2009-08-06 14:32     ` Henrik Theiling
2009-08-06 15:24       ` Heinz Diehl
2009-08-06 16:00         ` Salatiel Filho
2009-08-06 16:02           ` Salatiel Filho
2009-08-07 12:16             ` Salatiel Filho
2009-08-07 12:20               ` Salatiel Filho
2009-08-07 16:00                 ` Salatiel Filho
2009-08-08  8:27                   ` Heinz Diehl
2009-08-08 10:03                     ` Salatiel Filho
2009-08-06 15:43       ` Sam

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox