Re: Default system encryption key size is XTS 256 bits and not 512 bits

[email protected]
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
On 25. März 2015 07:41:17 MEZ, John Ashcroft <[email protected]> wrote:
>Hello,
>
>I installed OpenSUSE 13.2 with the default YaST encryption settings. 
>When examining the final product with "cryptsetup luksDump /dev/sda2" 
>the encryption used was aes xts-plain-64 with a MK bits (key size) of 
>256 bits. Which is effectively 128 bits for XTS mode. There was no GUI 
>way to change this in the installer.
>
>Most of the other distributions (Debian Jessie, Fedora 21, Ubuntu 14, 
>CentOS 7) are shipping with a default key size of 512 bits (effectively
>
>256 bits) for aes xts-plain-64 in their installers.
>
>Is this an omission in OpenSUSE or is there a policy for keeping system
>
>encryption at 256 (effectively 128) bits?
>
>Apologies if I couldn't pinpoint a prior message about this in the
>list.
>
>Thanks

John, I'd rather worry more about AES/Rijndael than key length. 128 bit is okay for the next 20 years ore more. Personally I use Twofish wherever I can.

-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.