Thilo Jeremias <> writes:

> If I understand CFS correctly it hides/scrambles directory names from
> non root users, but it provides no protection against root while the
> directory is open,
> why is this then more secure than chmod 600 ?

1) The backup media will have ciphertext, not plaintext.

2) The ciphertext may be on a fileserver (NFS, coda, etc.) that is under
   the control of someone else.

3) Needing the key means that an attacker has to trojan something, or be
   there at the right time.  This isn't really comforting, but it's
   better than nothing.

