From owner-freebsd-questions@FreeBSD.ORG Wed Mar 22 08:42:45 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 93F2216A401 for ; Wed, 22 Mar 2006 08:42:45 +0000 (UTC) (envelope-from norgaard@locolomo.org) Received: from strange.daemonsecurity.com (59.Red-81-33-11.staticIP.rima-tde.net [81.33.11.59]) by mx1.FreeBSD.org (Postfix) with ESMTP id 294AA43D45 for ; Wed, 22 Mar 2006 08:42:44 +0000 (GMT) (envelope-from norgaard@locolomo.org) Received: from [172.24.8.84] (generic.atosorigin.es [212.170.156.200]) by strange.daemonsecurity.com (Postfix) with ESMTP id 9307D2E047 for ; Wed, 22 Mar 2006 09:42:50 +0100 (CET) Message-ID: <44210DFC.6000308@locolomo.org> Date: Wed, 22 Mar 2006 09:42:36 +0100 From: Erik Norgaard User-Agent: Thunderbird 1.5 (X11/20060118) MIME-Version: 1.0 To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Subject: encrypted drives X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 22 Mar 2006 08:42:45 -0000 Hi: 1) I was thinking, what is the performance penalty of storing data on an encrypted device? Sure, for writing documents, coding and stuff, I guess the performance loss is insignificant, but for music and video which then needs to be decrypted and then decoded, is this a problem? 2) One thing is to create an entire encrypted device for /home. But that have the unfortunate consequence that other user's data is unencrypted once the system is up. What would be more appropriate is a solution where each home-dir is an encrypted mfs which is decrypted and mounted when the user log in, is this possible? If not, then the alternative would be to have a private mfs in the user's home dir which is mounted after login, but I think yet the user needs root access to mount encrypted devices. Is there any possibility for users to mount their own encrypted mfs? Thanks, Erik -- Ph: +34.666334818 web: www.locolomo.org S/MIME Certificate: www.daemonsecurity.com/ca/8D03551FFCE04F06.crt Subject ID: 9E:AA:18:E6:94:7A:91:44:0A:E4:DD:87:73:7F:4E:82:E7:08:9C:72 Fingerprint: 5B:D5:1E:3E:47:E7:EC:1C:4C:C8:3A:19:CC:AE:14:F5:DF:18:0F:B9