Hi All,

> Date: Mon, 18 Sep 2000 13:28:04 +1100 (EST)
> From: Howard Lowndes <[EMAIL PROTECTED]>
 
> What are ppls opinions on encrypted filesystems under Linux.

There's not many choices to be found...

> Is anyone currently using them, what success/problems are they having?

I'm using BestCrypt 0.4 on my work laptop.  The Bestcrypt tools create an 
encrypted "filesystem" by creating a single file, and then creating an 
encrypted ext2 filesystem within the file.  You then mount the filesystem within 
the file by using a "bctool mount" command.

It seems to be quite stable and very useable.  It uses either the Russian GOST 
encryption algorithm, blowfish (which, if my mind serves me correctly, was 
created by Bruce Schneier), twofish (which was also created by Mr Schneier), or 
DES.

When the drive is mounted, the private passphrase is prompted for.

> What are the recommendations for a corporate server?

I use this product to encrypt client information, as well as my own private 
information, on my laptop.  If I am sending/receiving confidential 
information over email, I'll mount another bestcrypt filesystem and receive 
the email direct onto that filesystem.  Pine doesn't mind if a folder appears 
and disappears automagically.  I'm sure there's more creative ways of using 
Bestcrypt.  I dunno what the maximum filesystem size is.

http://www.jetico.com

> The reason I ask is that an umbrella organisation of a site that I
> support had a major 'puter theft (not the ones I support I should add)
> with some sensitive info going out the door.

mmm.... Physical security....


Rebecca Richards, CCSA CCSE, Unix/Security Consultant, e-Secure Pty Ltd
"Secure in a Networked World"     Phone:  (02) 9438 4984 Fax: (02) 9438 4986
Suite 201, 2-4 Pacific Highway    Mobile: 0412 823 206
St Leonards NSW Australia         Email:  [EMAIL PROTECTED]
ACN 068 798 194                   http://www.e-secure.com.au


--
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
More Info: http://slug.org.au/lists/listinfo/slug

Reply via email to