On 6/28/05, Hubert Chan <[EMAIL PROTECTED]> wrote: > > Isn't dm-crypt the new way of doing this? > Yes and no. dm-crypt is recommended over cryptoloop. But there is also > loop-AES, which is more secure (in some modes) than dm-crypt (currently).
There is now support for both LRW-AES and ESSIV in the mainstream kernel. With ESSIV the security should be the same as loop-aes and with LRW-AES potentially better. For the highest security you should also use the LUKS cryptosetup because it provides hardening for passwords.