Why exactly is "more options than any other disk encryption software" a good thing?
Why exactly is "more options than any other disk encryption software" a good thing?
After snowden people actually started to request non-american stuff like the old GOST standard... :(
You are correct, cascaded cyphers don't increase security except in exceptional circumstances, and can decrease security if wrongly implemented. But LibreCrypt doesn’t actually support cascaded cyphers, so the point is moot.
But then you'd need extra space for the MAC/authentication tag, and disk encryption often isn't placed somewhere in the driver stack where you can get away with, say, a 4080-byte logical sector for a 4096-byte physical sector. Nothing expects that. Performance problems, stuff complains, even crashes, as anyone messing with 2352 byte sectors on CD-ROMs has maybe experienced. (Has anyone tried doing it anyway in more recent years? The last time I tried to implement it was back when ckt was working on PGPdisk, and it didn't go well.)
You could put the authentication tag somewhere else, but you have to be very careful with that, and it also means seeking: you could do that better if you were a filesystem, but as a transparent block device filter, as basically all FDE is, XTS is probably about as good as you're going to get - but remember that it is helpless against malleability or historical snapshots.
It's terrible. Disk encryption in the cloud is going to be so easy to break though I suppose its better than nothing? whelp
According to Google Trends, JFS is the third most popular file system on Linux, and Reiser is #1. F2FS is pretty big too, and it's the fastest on Linux 4 / SSD:
http://www.phoronix.com/scan.php?page=article&item=linux-40-...
The advantage is that if a flaw is discovered in an algorithm, then it is possible to switch to another without changing tools.
In my zuluCrypt project[1],i started with no options because i thought the default options for each supported format was "good enough for everybody" and not long afterwards,the more frequently requested feature was to add more options.
I think more options is good.
We will say the same about chacha20 in 25 years. It will probably still be secure, but there will be better choices.
Anyway, before the AES competition most block ciphers had blocks that size and RC5 is still very much patented.
Blowfish was not a bad choice. I stand by that.
It is listed under features, and it doesn't state that it is good or better than other software. Whether it is a good or not is a subjective decision.
In my opinion it is good because you have more choices available.
It appears to be an open source project. Is your question relevant in the first place?
Saying you support more features in non-security software might be a great thing but saying you support more ciphers, encryption algorithms, etc... than the competition just means a higher probability you're supporting weak/broken security algorithms and/or that the implementations are not well audited.
That, and the overwhelming majority of users are going to have no idea what the actual difference is between all the options nor are going to take the time to investigate what exactly is the difference between RIPEMD-320 & SHA-512. Nor should they have to for that matter.
The goal here is to implement high quality security software. The more features you support, the more code is in your product, and the harder it is to ensure that your code is in fact delivering the security you're aiming for.
They don't, they can just leave the defaults.
As far as implementation bugs, supporting many options means more users will pick the wrong options, and the attack surface becomes larger so that the chance of implementation issues goes up.
> As far as implementation bugs, supporting many options means more users will pick the wrong options, and the attack surface becomes larger so that the chance of implementation issues goes up.
Application must prevent users from picking the wrong options.