>From what i've read this mode is faster than CBC due to some parallelism, and it's accelerated by newer Intel's PCLMUL instructions. But it seems that AES/GCM mode is used only with IPSEC and such. Is there any particular reason we cannot use it with disk encryption? -- С уважением, Igor mailto:igor@xxxxxxxx _______________________________________________ dm-crypt mailing list dm-crypt@xxxxxxxx http://www.saout.de/mailman/listinfo/dm-crypt