Ext4 encryption patches for Android
thread.gmane.org
thread.gmane.org
Interesting quote from dm-crypt dev:
> As the primary DM maintainer I've yet to see a single report about dm-crypt performance being a pain point for android. Yet ext4 developers have gotten to a point where AOSP changes were introduced to use their newly crafted encryption support. Amazing really.
ref: https://lwn.net/Articles/639736/
No real answers or benchmark data. Anyone know why I'd want to use this over dm-crypt?
- mixing unencrypted with encrypted data (why encrypting object files during bulk builds?)
- file-based, encrypted backups for free (including incremental jobs!)
- passwords/keys per directory
- passwords/keys per user
- passwords/keys per group
- (...)
People who like encfs/cryptfs will probably like this too.https://wiki.archlinux.org/index.php/Disk_encryption#Data_en...
In addition it compares encrypting partitions vs specific data.
Don't know if ext4 encryption supports it, but the filesystem could allocate extra space for checksums to verify files aren't being modified. It also could store different keys for each file or directory making it possible to lock and unlock portions of the filesystem separately.
That means having access to the block device itself, with the system in an unlocked state.
If you've reached that scenario, then it's game over for whatever data is being encrypted.