<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Encrypting file systems</title>
	<link>http://www.kstaken.com/archives/74_encrypting-file-systems.html</link>
	<description>Kimbro Staken exploring creative use of technology and whatever else happens to seem interesting.</description>
	<pubDate>Fri, 29 Aug 2008 19:32:22 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0</generator>

	<item>
		<title>by: Jonas</title>
		<link>http://www.kstaken.com/archives/74_encrypting-file-systems.html#comment-369</link>
		<pubDate>Tue, 10 Oct 2006 07:50:41 +0000</pubDate>
		<guid>http://www.kstaken.com/archives/74_encrypting-file-systems.html#comment-369</guid>
					<description>dm-crypt has had security problems in the past, so I'd recommend loop-aes (http://loop-aes.sf.net).

You're still required to enter a passphrase when you mount the encrypted file system, because as Steve Holden said, otherwise it's not worth doing (you also have to make sure you use a secure passphrase, of course).

This is no problem with key management, but a problem of convenience. You can still build a *highly available* system by putting redundancy in the right places, though.</description>
		<content:encoded><![CDATA[<p>dm-crypt has had security problems in the past, so I&#8217;d recommend loop-aes (http://loop-aes.sf.net).</p>
<p>You&#8217;re still required to enter a passphrase when you mount the encrypted file system, because as Steve Holden said, otherwise it&#8217;s not worth doing (you also have to make sure you use a secure passphrase, of course).</p>
<p>This is no problem with key management, but a problem of convenience. You can still build a *highly available* system by putting redundancy in the right places, though.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Steve Holden</title>
		<link>http://www.kstaken.com/archives/74_encrypting-file-systems.html#comment-366</link>
		<pubDate>Mon, 09 Oct 2006 06:41:40 +0000</pubDate>
		<guid>http://www.kstaken.com/archives/74_encrypting-file-systems.html#comment-366</guid>
					<description>That's a feature, not a bug. If the key is on the system then it can be stolen along with the media, and your encrypting filesystem then just becomes an expensive way to burn CPU cycles with no security value whatsoever.</description>
		<content:encoded><![CDATA[<p>That&#8217;s a feature, not a bug. If the key is on the system then it can be stolen along with the media, and your encrypting filesystem then just becomes an expensive way to burn CPU cycles with no security value whatsoever.
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
