3 ms·
most systems for encrypting large amounts of data (e.g. a whole hard drive) don't use the user-derived key directly for encryption; the data is encrypted with a
by Hello71 3y ago
most systems for encrypting large amounts of data (e.g. a whole hard drive) don't use the user-derived key directly for encryption; the data is encrypted with a content encryption key (Microsoft) or master key (LUKS), which is then encrypted with the user-derived key and stored in the encryption header. this allows the user passphrase to be changed by reencrypting the CEK/MK rather than the whole drive.