Re: LUKS2 support for null/plaintext target

Chris Murphy <lists-zXQU9YWDTqjmlV4oE/1sFAC/[email protected]>
Newsgroups gmane.linux.kernel.device-mapper.dm-crypt
Message-ID <CAJCQCtSC20ocCM50KbOcFO7LwBv-EQyJH1HSySqMc3Q=51sMEw@mail.gmail.com>
On Sun, Dec 15, 2019 at 10:51 AM Jordan Glover
<Golden_Miller83-g/[email protected]> wrote:
>
> I think encrypting previously unencrypted data on the same disk
> doesn't guarantee that old data won't be recoverable especially
> on ssd/nvme which are ubiquitous today. Officially supporting
> such case on LUKS will give users false sense of security of
> their data.

This problem exists even in the backup and restore to LUKS encrypted
volume case. In fact it's less reliable because there's no assurance
with backup->restore method that all previously occupied LBAs are
overwritten, whereas an inplace conversion can assure that all LBAs in
the previous range are read and encrypted. It's a matter of
implementation, there's the potential for false sense of security
regardless.



-- 
Chris Murphy
_______________________________________________
dm-crypt mailing list
[email protected]
https://www.saout.de/mailman/listinfo/dm-crypt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.