Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not a good thing to do for two reasons.

Disk encryption is with XTS mode, also not authenticated. If the remote is not trusted, a number of attacks are possible.

Small changes in the LUKS container can trigger uploading the entire container. It seems, since Dropbox syncs deltas, it can get away with that by uploading changed blocks. That’s not the case with most cloud providers.

That was actually the motivation for per file encryption for cloud storage.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: