<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://www.linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Sun May 26, 2013 5:44 am by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Sun May 26, 2013 5:44 am</pubDate>
  <lastBuildDate>Sun May 26, 2013 5:44 am</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://www.linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101471#101471</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2264'&gt;JoeyC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Sep 05, 2011 12:14 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Yes.. that more or less settles it. I wrongly assumed that you cannot reconstruct data from 2 of the 4 disks, but if a file is small enough then that fails. Also, half the mail is readable, should it be on the array.&lt;br /&gt;
&lt;br /&gt;
Hm..&lt;br /&gt;
&lt;br /&gt;
J</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101471#101471</comments>
                                        <author>JoeyC</author>
                                        <pubDate>Mon Sep 05, 2011 12:14 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101471#101471</guid>
                                      </item>
                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101470#101470</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=5'&gt;nelz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Sep 05, 2011 11:14 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;JoeyC wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;But, again, the question is: how secure is 2/4 encryption?&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
Not very if your sensitive data falls on the unencrypted disks. Bear in mind that things like password files are small and often fit in a single disk block. So you have a 50% chance of the whole file being unencrypted.&lt;br /&gt;
&lt;br /&gt;
If your data is important enough to encrypt, it is important enough to encrypt securely.</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101470#101470</comments>
                                        <author>nelz</author>
                                        <pubDate>Mon Sep 05, 2011 11:14 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101470#101470</guid>
                                      </item>
                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101465#101465</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2264'&gt;JoeyC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Sep 05, 2011 10:18 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Yep, valid points.. My current setup suffers from encryption, but it's and auld yoke, from a time way back when they used weird spelling.&lt;br /&gt;
&lt;br /&gt;
The new one is going to be &lt;a href=&quot;http://ark.intel.com/products/49490/Intel-Atom-processor-D525-%281M-Cache-1_80-GHz%29&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;this atom&lt;/a&gt; (without aes extention) on &lt;a href=&quot;http://www.mini-itx.com/store/?c=47#JNF99-525&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;this Jetway&lt;/a&gt; board with 4GB memory in it.&lt;br /&gt;
I think I'll just play with it a bit, see what it does. I'll see what the difference is between 2/4 and 4/4 encryption, as you suggested.&lt;br /&gt;
Also, I'm planning to encrypt the data disks, not the disk containing the os (which will be an SSD, budget permitting).&lt;br /&gt;
&lt;br /&gt;
But, again, the question is: how secure is 2/4 encryption?&lt;br /&gt;
&lt;br /&gt;
J</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101465#101465</comments>
                                        <author>JoeyC</author>
                                        <pubDate>Mon Sep 05, 2011 10:18 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101465#101465</guid>
                                      </item>
                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101462#101462</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=5'&gt;nelz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Sep 05, 2011 9:26 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      So you're building a RAID on top of three block devices, two of which are encrypted and one is a disk device? That sounds both horrible and pointless. Even if there were a performance hit when using encryption (which there isn't usually, any half decent processor can handle the encryption far faster than the disk and transfer the data without breaking sweat) you are still doing 2/3 of the encryption work.&lt;br /&gt;
&lt;br /&gt;
If you really want to reduce the encryption load, put LVM on top of an unencrypted RAId5 then only encrypt the filesystems that contain sensitive data - usually /var on a server. There is no point in encrypting the likes of /usr, which only contains publicly available files.</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101462#101462</comments>
                                        <author>nelz</author>
                                        <pubDate>Mon Sep 05, 2011 9:26 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101462#101462</guid>
                                      </item>
                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101461#101461</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2264'&gt;JoeyC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon Sep 05, 2011 9:03 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      The question is not 'can you do it', I'm doing it. No reason why you couldn't use the block device created by cryptsetup in a raid array.&lt;br /&gt;
&lt;br /&gt;
The question is, how (in)secure is it?&lt;br /&gt;
&lt;br /&gt;
J</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101461#101461</comments>
                                        <author>JoeyC</author>
                                        <pubDate>Mon Sep 05, 2011 9:03 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101461#101461</guid>
                                      </item>
                                      <item>
                                        <title>Re: half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101460#101460</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=14187'&gt;Dutch_Master&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun Sep 04, 2011 11:48 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Not gonna happen: it's either encrypt all or nothing. That's part of the RAID5 setup I'm afraid. But if you use 4 disks instead, try a RAID1+0, on which the RAID1 is clear but the RAID0 encrypted.&lt;br /&gt;
&lt;br /&gt;
(in a RAID, forget about individual disks, they are addressed with their RAID device, mdX)</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101460#101460</comments>
                                        <author>Dutch_Master</author>
                                        <pubDate>Sun Sep 04, 2011 11:48 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101460#101460</guid>
                                      </item>
                                      <item>
                                        <title>half encrypted raid 5</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=101457#101457</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2264'&gt;JoeyC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun Sep 04, 2011 10:22 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      All,&lt;br /&gt;
&lt;br /&gt;
I'm building a home LAMP server with a raid5 array (using mdadm) for my data. I want my data to be encrypted so that it can only be accessed if you know the password. Encryption (md-crypt) is going to slow down stuff, as is raid 5.&lt;br /&gt;
&lt;br /&gt;
But here's a thought. What if I only encrypt 2 disks and use the resulting two /dev/mapper/whatever block devices in the array next to, say, 2 'normal' partitions? Only half of the data needs to be encrypted which should give me some speed benefit and the data cannot be reconstructed by mdadm without knowing the passwords.&lt;br /&gt;
&lt;br /&gt;
But how insecure is this? I'm thinking, if anyone nicks the server and sells it on to some nerd like me with too much time (and more brains), is he going to be able to recover some files?&lt;br /&gt;
&lt;br /&gt;
For arguments sake, not that the data is all that important (except to me).&lt;br /&gt;
&lt;br /&gt;
Any thoughts?&lt;br /&gt;
&lt;br /&gt;
J</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=101457#101457</comments>
                                        <author>JoeyC</author>
                                        <pubDate>Sun Sep 04, 2011 10:22 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=101457#101457</guid>
                                      </item></channel></rss>