11 ms·
cryptsetup -c serpent-xts-plain64 -s 512 -h sha512 -i 123456 luksFormat /dev/ice /path/to/8M/dev/urandom/keyfile (serpent wasn't chosen by NSA because it's the
by cryptXTS 6y ago
cryptsetup -c serpent-xts-plain64 -s 512 -h sha512 -i 123456 luksFormat /dev/ice /path/to/8M/dev/urandom/keyfile
(serpent wasn't chosen by NSA because it's the best, if you want inferior AES, then change serpent to AES.)
- SAI_Peregrinus 6y agoI disagree that serpent is superior to AES. The evidence that it's secure is much flimsier than that for AES. It's seen far less analysis, and suffers from many of the same implementation issues as AES (hard to make both constant time and fast without hardware support, and has no hardware support). I'd have agreed with you 10 years ago, but there have been a lot more (failed) attack attempts on AES in the intervening decade than there have been on Serpent, which increase my confidence in AES.