3 ms·
But this isn't disk encryption! Filesystems have metadata: which is where a MAC can go, next to the filename. There's just no way this should be unauthenticate
by qrmn 11y ago
But this isn't disk encryption! Filesystems have metadata: which is where a MAC can go, next to the filename.
There's just no way this should be unauthenticated XTS, this is simply the wrong mode to use, you should use an AEAD. ChaCha20_Poly1305 - RFC7539: https://datatracker.ietf.org/doc/rfc7539/ https://datatracker.ietf.org/doc/rfc7539/ - makes much more sense. Faster, too, on the target mobile devices which have poor crypt performance.
I don't think this should be merged early or as-is. Unauthenticated encryption is against good advice and a bad idea. Standardising that is an even worse idea.
Edit: I do see that they're intending this as a minimum viable patch for Android 'M' and they intend to add GCM support later (again, I'd point to CC20 as a newer, better alternative), they're just waiting on a transactional update first. I do question whether shipping it broadly with this design as-is should happen in the vanilla kernel, however: Android uses its own patches anyway. Maybe let this one mature a bit first before merging upstream?
- fulafel 11y ago> Filesystems have metadata: which is where a MAC can go, next to the filename. File-level MACs would require reading/writing the entire file in one go, andpreclude efficient in-place modification of files. The alternative, lots of per-block MACs stored in extended attributes, wouldn't work for ext4 because of the 4 kb extended attribute size limitation, and would also have problems that the grandparent listed (lots of seeks).
- qrmn 11y agoA fair point. btrfs would have a much easier time of it. We then have the interesting consequence that we can observe times and sizes of COW updates, but in truth SSDs have that anyway.
- caf 11y agoChaCha20 may be better in the abstract, but as a practical matter AES-GCM can take advantage of AESNI. I don't think a patch adding support for ChaCha20 would be particularly controversial anyway.