[dm-crypt] Re : Re : Re : Poor performances with nfs and Kernel 3.x

Arno Wagner arno at wagner.name
Sun Feb 26 22:39:31 CET 2012

On Sun, Feb 26, 2012 at 09:29:31PM +0000, Mickael wrote:
> PS: about point 3: Have you ever thinking adding an option to cryptsetup
> to do a benchmark like this: http://www.truecrypt.org/screenshots2 (I
> guess everyone build his own one) In fact, with the speed, it will be
> great to have an idea about the security level of?  each cipher too.  But
> is it possible to calculate such index ?  For example, is the slowest
> cipher the most secure ?

Unfortunately, no. Ciphers get broken overt time and at some point
they become practiclly insecure, depending on attacker model.
This means cipher security is always an expert opinion as not all
people working on breaking a cipher will publish their results.
Then there is another factor: If somebody can break a cipher, 
for what kind of informatin will they admit they can (by using
that nformaton)? And to make matters more complicated, once somebody
adits to being able to break a certain cipher, they may also
use that capability for things of far lesser worth.

Cyrrent advice is to use AES for everything that needs to be 
secure. The other AES-finalists should also be pretty good and 
some may be more secure than AES in fact. Not that it matters
at this time.

Also note that TrueCrypt ffers cobinaton of ciphers where
(hopefully) all have to be broken to access the secrets.
dm-crypt does not do that, byt you can manyally layer diffent
ciphers if you want it. 
