|
|
|
|
|
by tptacek
4350 days ago
|
|
No, it's not simple oversight. Here's my best stab at an explanation: http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/ Regarding information leakage: both schemes leak some degree of information (for reasons I get into in that post, XTS is deterministic). But because encrypted filesystems don't have to respect strict block boundaries, they can do a variety of things to limit or eliminate leakage. It's much harder for block device crypto to solve this problem. Naive encrypted filesystems don't, of course. Like I said, I'd have a hard time making a recommendation between Truecrypt and EcryptFS. |
|