BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] NAS: encryption
- Subject: [Discuss] NAS: encryption
- From: warlord at MIT.EDU (Derek Atkins)
- Date: Tue, 07 Jul 2015 13:14:16 -0400
- In-reply-to: <BY1PR0401MB1641117906253C39D8075681DC940@BY1PR0401MB1641.namprd04.prod.outlook.com> (Edward Ned Harvey's message of "Sun, 5 Jul 2015 13:34:48 +0000")
- References: <5596D8DA.2000201@gmail.com> <55980A9F.4020007@gmail.com> <BY1PR0401MB1641117906253C39D8075681DC940@BY1PR0401MB1641.namprd04.prod.outlook.com>
"Edward Ned Harvey (blu)" <blu at nedharvey.com> writes: >> From: Discuss [mailto:discuss-bounces+blu=nedharvey.com at blu.org] On >> Behalf Of Tom Metro >> >> I imagine it would be challenging to pull off encryption well with >> appliance hardware. The first problem is getting the software to do it. >> (Plus all the automation you've previously discussed to set up the keys >> on boot.) The second challenge is having the horsepower to perform the >> encryption. Not impossible if they chose their embedded CPU well, but >> unlikely to be optimized for that. > > You seem to think there's an obstacle which isn't really real - > Encryption is very cheap computationally, so cheap indeed it can be > done by the disks themselves. Yes, it's absolutely possible for > appliances to utilize disk encryption, either by using its own CPU, or > by offloading to the disks. I cannot speak to the specifics of any > particular appliance actually doing it though, as I don't use any of > them. I don't trust my disks to do the encryption, mostly because there's really no way to verify that it's doing it correctly, and the key management gets a lot harder. I'd rather use dm-crypt (or the equivalent). In either case you still need to figure out how your keys are going to get provided when the system boots. -derek -- Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory Member, MIT Student Information Processing Board (SIPB) URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH warlord at MIT.EDU PGP key available
- Follow-Ups:
- [Discuss] NAS: encryption
- From: abreauj at gmail.com (John Abreau)
- [Discuss] NAS: encryption
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] NAS: encryption
- References:
- [Discuss] NAS: buy vs. build
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] NAS: encryption
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] NAS: encryption
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] NAS: buy vs. build
- Prev by Date: [Discuss] Distributed file systems
- Next by Date: [Discuss] NAS: lots of bays vs. lots of boxes
- Previous by thread: [Discuss] NAS: encryption
- Next by thread: [Discuss] NAS: encryption
- Index(es):