Re: LUKS2 support for null/plaintext target
Chris Murphy <lists-zXQU9YWDTqjmlV4oE/1sFAC/[email protected]>
| Newsgroups | gmane.linux.kernel.device-mapper.dm-crypt |
|---|---|
| Message-ID | <CAJCQCtSC20ocCM50KbOcFO7LwBv-EQyJH1HSySqMc3Q=51sMEw@mail.gmail.com> |
On Sun, Dec 15, 2019 at 10:51 AM Jordan Glover <Golden_Miller83-g/[email protected]> wrote: > > I think encrypting previously unencrypted data on the same disk > doesn't guarantee that old data won't be recoverable especially > on ssd/nvme which are ubiquitous today. Officially supporting > such case on LUKS will give users false sense of security of > their data. This problem exists even in the backup and restore to LUKS encrypted volume case. In fact it's less reliable because there's no assurance with backup->restore method that all previously occupied LBAs are overwritten, whereas an inplace conversion can assure that all LBAs in the previous range are read and encrypted. It's a matter of implementation, there's the potential for false sense of security regardless. -- Chris Murphy _______________________________________________ dm-crypt mailing list [email protected] https://www.saout.de/mailman/listinfo/dm-crypt