3 ms·
Author of eCryptfs and EXT4 encryption chiming in. "Series of issues?" Really? There were 3, and they were all scored "Low" by the authors for exploitability a
by MikeHalcrow 8y ago
Author of eCryptfs and EXT4 encryption chiming in.
"Series of issues?" Really? There were 3, and they were all scored "Low" by the authors for exploitability and security impact.
That said, I generally agree FDE is the way to go if your platform's constraints allow for it -- but only for security. Native EXT4 encryption will give you equal or better performance than FDE primarily because the file system metadata isn't encrypted. Which isn't to say that's a good tradeoff -- it's just the nature of the beast.
Because of performance and functionality issues (file name length, possibility of page cache inconsistency) eCryptfs shouldn't be used for anything any more.
- shittyadmin 8y agoAh, you're right, I had it confused with a similar analysis on EncFS which had more significantly damaging findings. https://defuse.ca/audits/encfs.htm https://defuse.ca/audits/encfs.htm I wasn't even aware Ext4 had native encryption support though! I'll definitely have to give that a go. Thanks for the tip.
- colint 8y agoAccording to Michael Halcrow's LinkedIn [1], he was heavily involved on the EXT4 encryption: "I was also the project lead for encryption in EXT4, which is now available as the mechanism implementing file-based encryption on Android." [1] https://www.linkedin.com/in/michael-halcrow-1880601 https://www.linkedin.com/in/michael-halcrow-1880601