Re: Encrypted home directory

I've been running full disk encryption via LUKS since F8 with a 6 year
old laptop.  I don't see any noticeable performance loss.

Just to comment on the whole disk versus just a folder in the /home,
Windows did the same thing a number of years ago on XP (and since I
believe but I don't know).  You could select a folder and "encrypt" it.
 The crypto implementation was horrible and when people actually used it
they never realized that they weren't getting ALL the sensitive data
encrypted.  There will always be a cache or tmp file laying around in
the clear that will contain sensitive information.

The DoD didn't like the use of the folder level encryption and has sense
mandated full disk encryption for all portable devices.  It saves the
user from trying to figure out what is sensitive and what needs to be
encrypted and breaking their storage schema just to put a specific file
into a specific folder.  The user will ALWAYS miss something and will
ALWAYS be left vulnerable.

Eric Christensen
E-Mail: sparks fedoraproject org
GPG Key: D74908ED

