LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 09-12-2010, 05:06 AM   #1
Molly
Member
 
Registered: Jan 2004
Distribution: Slackware, CentOS, Debian, OpenWRT, FreeBSD, OpenBSD, Solaris
Posts: 37

Rep: Reputation: 16
Question dm-crypt aes-xts-plain64 vs aes-cbc-essiv for volumes > 2TiB


I'm not a mathematician or cryptographer, only an end user of the technology trying to determine the "best" or safest future proof option to go with for long term archival while also maintaining reasonable performance with dual opteron ~2GHz or similar setup. I've noticed aes-cbc-essiv seems to be the default choice in various installers for reasons of backwards compatibility while others are moving towards XTS since the standardization. Feedback is appreciated and thanks in advance.

Last edited by Molly; 09-12-2010 at 05:15 AM. Reason: .
 
Old 09-13-2010, 05:24 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora, Lubuntu, FreeBSD
Posts: 3,930
Blog Entries: 5

Rep: Reputation: Disabled
Quote:
Originally Posted by Molly
... trying to determine the "best" or safest future proof option to go with for long term archival while also maintaining reasonable performance...
I'd mention that Rijndael was (arguably?) chosen as the Advanced Encryption Standard precisely because it's a good balance of secure + relatively quick.

I'll also add that there is no practical future-proof encryption. For now, AES-128 or AES-256 - with a strong key - is something I personally feel quite comfortable with.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
LUKS: xts-plain vs xts-essiv? phoenix_precedent Linux - Security 4 07-07-2013 03:31 PM
AES boobymonster Linux - Security 4 01-31-2009 09:04 AM
Loop-aes vs DM-crypt Frogular Linux - Security 3 12-26-2007 03:13 PM
using aes-i586 instead of just aes whysyn Linux - Security 0 03-07-2007 03:47 PM
loop-AES dm-crypt and Gentoo PrimusXPrimus Linux - Software 1 10-12-2004 05:18 PM


All times are GMT -5. The time now is 07:17 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration