From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S266797AbUGVDa7 (ORCPT ); Wed, 21 Jul 2004 23:30:59 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S266799AbUGVDa7 (ORCPT ); Wed, 21 Jul 2004 23:30:59 -0400 Received: from mx1.redhat.com ([66.187.233.31]:1194 "EHLO mx1.redhat.com") by vger.kernel.org with ESMTP id S266797AbUGVDa6 (ORCPT ); Wed, 21 Jul 2004 23:30:58 -0400 Date: Wed, 21 Jul 2004 23:30:18 -0400 (EDT) From: James Morris X-X-Sender: jmorris@devserv.devel.redhat.com To: Andrew Morton cc: linux-kernel@vger.kernel.org Subject: Re: [PATCH] Delete cryptoloop In-Reply-To: <20040721230044.20fdc5ec.akpm@osdl.org> Message-ID: References: <20040721230044.20fdc5ec.akpm@osdl.org> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org On Wed, 21 Jul 2004, Andrew Morton wrote: > > which is buggy, unmaintained, and > > reportedly has mutliple security weaknesses. > > Doesn't dm-crypt have the same security weaknesses? Jari Ruusu claims that anything with on-disk cryptoloop compatibility is vulnerable to dictionary attacks and IV deduction. Fruhwirth Clemens claims that this is FUD, per the thread below. http://marc.theaimsgroup.com/?l=linux-kernel&m=108447509327847&w=2 It would be good if we could get some further review on the issue by an independent, well known cryptographer. - James -- James Morris