Re: Re: Loop-AES and Twofish on 64-bit CPU

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



* Peter_22@xxxxxx wrote:

> Ok, I suppose this is good news! My knowledge about attacks on
> ciphers and galois fields is quite faint, but I seriously hope the
> maintanance of loop-aes will go on. Since many tutorials and
> websites focus on loop-aes I deem it the right choice. Knoppix

I've also seen that many tutorials focus on dm-crypt because it
allegedly is easier to set up, is more modern, has a future, and such
buzzwords. The only argument of using dm-crypt is its presence in
mainline and thus hassle-free updating for the ordinary user; and
that's a funny one too because dm-crypt does not focus on security
first, as its author stated some time ago. dm-crypt's mission mantra
seems to be "let's replace messy mainline loop-stuff, get it stable,
then worry about better security."

That's not a bad thing, because the (still) unmaintained mainline
loop-support is going to be dropped completely as far as I know. They
just should tell the story more clearly, and pretty please, with a
cherry on top, not drop loop-support completely.


> disadvantage. Clemens Fruhwirth seemed to be a wise guy but
> unfortunately he didn??t suggest a patch or some working files.

Actually, he did try to get his stuff included in mainline but made
the same experience as Jari did: Not Gonna Happen. The kernel gurus'
main concern is about maintainability and such.


> Other mainline projects like truecrypt or parts of the standard
> linux kernel might be backdoored. The loop-aes readme could include
> advice on how to remove partition table and boot sector and some
> plugin for k3b to burn encrypted cd/dvd on-the-fly would be
> excellent, too.

I suppose by mainline projects you mean standalone projects.
Backdoors are always possible of course but with open source... let's
just say it would not be a smart idea to put a backdoor into an open
source programme.

I second the addition of the partitiontable-less setup magic to the
readme. And about that k3b plugin, I guess its author provides some
kind of plugin-howto for users who like to contribute. My programming
skills are rather rusty and I also lack the time for such a little
fun project (who doesn't these days?)

-- 
left blank, right bald
winter wanted, NOW!

Attachment: pgp5ti9HMVDUi.pgp
Description: PGP signature


[Index of Archives]     [Kernel]     [Linux Crypto]     [Gnu Crypto]     [Gnu Classpath]     [Netfilter]     [Bugtraq]
  Powered by Linux