-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 jerome etienne schrieb: > > if i understand what you ask, as far as i know, nobody implemented the sorry for being unclear. no, i meant "implementaion for crpto-filesystem with authentication", eg. "loop-aes with HMAC for the whole fs". > if you care about this attack, a little google search pointed me to > another way to automatically secure file, encfs, which seems to protect > against this attack. it provides "per-data block MAC authentication encfs describes itsself as "it works on files at a time, not an entire block device." and i was more looking for a implemenatation of your proposed fix, working in practice, aka "show me the code, fellow" ;-) Christian. - -- BOFH excuse #49: Bogon emissions -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org iD8DBQFB8GUk+A7rjkF8z0wRAvttAKCHwLyIJHUYxnfliB9cWi12Sh27HACeMJXC 25KMk9E67/nB7urc9nJVuRg= =o5Tq -----END PGP SIGNATURE----- - Linux-crypto: cryptography in and on the Linux system Archive: http://mail.nl.linux.org/linux-crypto/