5 ms·
Many things... here are the ones I care about: - you can have different keys for all your "partitions" without having to pre-allocate them - you can send encr
by nextgens 8y ago
Many things... here are the ones I care about:
- you can have different keys for all your "partitions" without having to pre-allocate them
- you can send encrypted incremental snapshots to a host that doesn't have the key (for backups for instance)
- it's using authenticated encryption (as opposed to LUKS with XTS)
- frutiger 8y ago> you can send encrypted incremental snapshots to a host that doesn't have the key (for backups for instance) Isn't this possible already by encrypting the incremental snapshots with a key of your choice, and then just storing that on the remote host?
- nextgens 8y agoSure, but you can't "consolidate" them without re-transferring everything (typically differential snapshots)... whereas with native encryption, you just delete the snapshot.
- jolmg 8y agoCan't these things be done with eCryptfs or EncFS? > you can have different keys for all your "partitions" without having to pre-allocate them I imagine its possible to create multiple encrypted directory hierarchies with different keys as they are needed. > you can send encrypted incremental snapshots to a host that doesn't have the key (for backups for instance) You can just rsync the encrypted directory hierarchy. > it's using authenticated encryption (as opposed to LUKS with XTS) From my quick search, do I understand that "authenticated encryption" is basically hashing or signing the ciphertext or plaintext to make sure that it wasn't altered?
- Quekid5 8y ago> Can't these things be done with eCryptfs or EncFS? Possibly, but ZoL/ZFS offers an integrated solution without any setup, etc. That's very appealing for most people. As an admin I really don't want to have to write a big pile of scripts to do what I could trivially do with ZFS by just setting some zpool or zfs options. EDIT: I don't know why, but people who haven't "lived" it keep underestimating just how much the convenience of "integration" means. This is not a slight, I just think that it's one of those things that you have to experience to appreciate just how much of a difference it makes.
- xyzzy123 8y agoAlso how futzing with disk arrays so often causes data loss. Storage is unforgiving and you absolutely want the simplest thing to set up - for data safety. The problem is that when you go to do recovery, maybe years after the thing was set up, it turns out the software has moved on and works differently and your storage media are in a state where at least one has failed and maybe more are dodgy, and if you have set something up with a few different interacting layers it is super easy to do the wrong thing and lose data. I’ve lost data to “clever” storage setups before and now I stick to the “happy path” (only run the most common, well tested configurations).
- Quekid5 8y agoThis is an excellent point. When working with the ZoL tools I really get the impression that they want to make the easy and safe(!) things easy, and the dangerous things near-impossible. I don't have that much experience with ZFS/ZoL (truly-)edge cases, but it's very reassuring that they had the right mindset when designing the tools.
- e12e 8y agoIt also has real potential as a cross platform, encrypted file system. Initially Linux/bsd - but potentially also windows and os x.