Visit Jeremy's Blog.
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


  Search this Thread
Old 09-12-2010, 05:06 AM   #1
Registered: Jan 2004
Distribution: Slackware, CentOS, Debian, OpenWRT, FreeBSD, OpenBSD, Solaris
Posts: 38

Rep: Reputation: 21
Question dm-crypt aes-xts-plain64 vs aes-cbc-essiv for volumes > 2TiB

I'm not a mathematician or cryptographer, only an end user of the technology trying to determine the "best" or safest future proof option to go with for long term archival while also maintaining reasonable performance with dual opteron ~2GHz or similar setup. I've noticed aes-cbc-essiv seems to be the default choice in various installers for reasons of backwards compatibility while others are moving towards XTS since the standardization. Feedback is appreciated and thanks in advance.

Last edited by Molly; 09-12-2010 at 05:15 AM. Reason: .
Old 09-13-2010, 05:24 PM   #2
Senior Member
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
Originally Posted by Molly
... trying to determine the "best" or safest future proof option to go with for long term archival while also maintaining reasonable performance...
I'd mention that Rijndael was (arguably?) chosen as the Advanced Encryption Standard precisely because it's a good balance of secure + relatively quick.

I'll also add that there is no practical future-proof encryption. For now, AES-128 or AES-256 - with a strong key - is something I personally feel quite comfortable with.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
LUKS: xts-plain vs xts-essiv? phoenix_precedent Linux - Security 13 12-23-2014 02:31 AM
AES boobymonster Linux - Security 4 01-31-2009 09:04 AM
Loop-aes vs DM-crypt Frogular Linux - Security 3 12-26-2007 03:13 PM
using aes-i586 instead of just aes whysyn Linux - Security 0 03-07-2007 03:47 PM
loop-AES dm-crypt and Gentoo PrimusXPrimus Linux - Software 1 10-12-2004 05:18 PM > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:35 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration