On 6/28/05, Hubert Chan <[EMAIL PROTECTED]> wrote:
> > Isn't dm-crypt the new way of doing this?
> Yes and no.  dm-crypt is recommended over cryptoloop.  But there is also
> loop-AES, which is more secure (in some modes) than dm-crypt (currently).

There is now support for both LRW-AES and ESSIV in the mainstream kernel.
With ESSIV the security should be the same as loop-aes and with
LRW-AES potentially better.

For the highest security you should also use the LUKS cryptosetup
because it provides hardening for passwords.

Reply via email to