For rPi though? Not sure they have an AES accelerator, and if they don’t then it’s going to be a huge cost to performance.
Not only because USB is using a CPU core to operate (because USB uses CPU not dedicated hardware like FireWire) but also because it has to transparently translate and encrypt every access.
It seems like the raspberry actually has zero crypto extensions anyway: https://www.raspberrypi.org/forums/viewtopic.php?t=207888
The ARM chips in the all of the Raspberry pis do not have AES accelerators. Encrypting your pis drive is going to be a serious hit on performance like you said. I don't recommend it.
If you really really really want to encrypt your Rpi then you need to use a disk cipher like Adiantum. It is based off of ChaCha12 and was made specifically for low end CPUs that lack AES accelerators.
That's why it's an interesting thing to measure, how much the competition between boot tasks and AES encryption affect the boot. It may not be much because I suspect boot is IO bound, but I don't know.