|
From: Dean N. <di...@ti...> - 2003-11-29 22:56:44
|
>> > btw, i'm interested in this patch: >> > >> > http://loop-aes.sourceforge.net/loop-AES.README >> > >> > it provides a secure loopback system, so you could use the aes modules >> from >> > kernel to have an encrypted loop device. it is backwards compatible with >> > the classic loop command. >> >[...] >> > >> > anyone/someone/everyone against? agree? opinions? >> >> I would vote against the idea. >> >> While AES is a very good encryption system, I would have to reasons against >> integrating it into DL (for the loopback): >> o Extra CPU power would be required to handle the AES decryption - and that >> is on top of the CPU power required to handle the decompression that is >> already required! Remember - a lot of people run DL on some very old (and >> slow) processors. >> o Not sure I understand the need. What is it about the ISO image that you >> believe requires the encryption? I.e., what are you trying to protect? > > I don't think you understand. (or maybe I don't understand :) Well, it certainly wouldn't be the first time I didn't understand something! > > I believe it's for creating encrypted filesystems, on a hard drive. > I don't think it has anything to do with the DL ISO image. > I also think it's completely optional, so no extra CPU power is required > unless you actually setup an encrypted filesystem (in a loopback file). From Diego's original message: :loop support has to be disabled from kernel. a new loop.o module capable of aes :is build. : :then, a new mount/losetup is needed, so util-linux-2.12 has to be patched. : :so, because this is a big change, and its compatible, it won't have a configurable :entry on make menuconfig, and installed always on dl... Since he says that "loop support has to be disabled" and "a new loop.o module", I took this to mean it is a REPLACEMENT for the existing loop support. And since we now use the existing loop driver for the ISO image (or at least we will with V1.1 were it is already in place), that means that we would end up using the AES encrypted loopback file for the base DL ISO image (or at least that is what I took "...because this is a big change..." to also imply). And yes - I may completely misunderstand Diego's meaning. So let me respond this way: Diego - what are you proposing? To have the DL ISO image be AES encrypted, or to allow users to create AES encrypted file systems? Diego: Your turn! Dean Nedelman TimeLord Consulting |