5 ms·
In order to do filesystem encryption properly, it needs to be done at the file layer, not the block layer. Block-level encryption is not authenticated because t
by Titanous 10y ago
In order to do filesystem encryption properly, it needs to be done at the file layer, not the block layer. Block-level encryption is not authenticated because there are no extra bytes to add the authentication tag.
If a ciphertext is not authenticated, it can be trivially tampered with. This means that someone with access to the encrypted drive could add backdoors or otherwise tamper with the executables and data even though it is encrypted.
- black_knight 10y agoYou can perfectly fine divide the block device into a bit smaller chunks so that you can fit a MAC or similar at the end.
- Titanous 10y agoMy understanding is that in practice this is quite hard to do. As far as I know, none of the mainstream block-layer encryption systems (BitLocker, FileVault, dm-crypt) provide authenticated encryption. Here's a short thread about the problems with adding it to dm-crypt: http://comments.gmane.org/gmane.linux.kernel.device-mapper.dm-crypt/6689 http://comments.gmane.org/gmane.linux.kernel.device-mapper.d... I'm sure you can find more threads if you look around.
- black_knight 10y agoThanks! That’s good to know. Indeed, encryption without authentication is poor security.
- deleted 10y ago[deleted]
- mioelnir 10y agoThis is how FreeBSD's GELI (which has authenticated encryption for blockdevices) did it. For every 4k data block it presented up the stack, it consumed 9 512 sectors on disk. Each of them contained 480 bytes, the rest for MAC. With 4k native drives, this became completely impractical. To keep ratios similar, you would have to present 32k byte devices up the stack, which filesystems have troubles with. Or have 1 MAC sector per data sector or similar, cutting your storage in half.
- captainmuon 10y ago> If a ciphertext is not authenticated, it can be trivially tampered with. Shouldn't it be impossible to forge a plaintext without the key for a good encryption algorithm? I imagine a good algorithm not to be just key -> pseudorandom stuff that is XORed with data, but something that has cascading. Change a bit anywhere, and a whole block changes unpredictably. Include the physical position of the block in the key, so that it impossible to copy blocks around to duplicate data.