Subject: CBC and LRW?
To: NetBSD Tech Security <tech-security@NetBSD.org>
From: Jan Danielsson <jan.danielsson@gmail.com>
List: tech-security
Date: 07/25/2006 14:43:01
This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig72E7E7B9FE6D1728FDD5F48D
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Hello all,

   This from the TrueCrypt site:

----------------------------------
New mode of operation implemented: LRW.

LRW mode is more secure than CBC mode and is suitable for disk
encryption. LRW mode is to become an IEEE standard for sector-based
storage encryption. (For more information on LRW mode, see chapter
Technical Details, section Modes of Operation in the documentation).

[---]

To prevent a recently discovered attack, which affects plausible
deniability, we strongly recommend that you move data from your
TrueCrypt volume to a new volume created by this version. Description of
the attack: If a series of certain plaintext blocks is written to a
mounted volume (i.e., if it is correctly encrypted), it is, with a very
high probability, possible to distinguish the volume from random data.
This affects volumes created by all versions of TrueCrypt prior to 4.1,
except volumes encrypted with AES-Blowfish or AES-Blowfish-Serpent.
----------------------------------

   As far as I can tell, NetBSD's cgd only uses cbc. Should it support LW=
R?

   I don't actually understand what CBC vs LWR that means, though. But
I'm going to assume that the TrueCrypt people do.

--=20
Kind Regards,
Jan Danielsson
Te audire non possum. Musa sapientum fixa est in aure.


--------------enig72E7E7B9FE6D1728FDD5F48D
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (MingW32)

iD8DBQFExhHZ8wBCTJQ8HEIRAvZ8AKCOXKXOIaNAEIEdBO+m0ZfUS70rCQCcC/87
RkZIOGXCqC8zvJmPYGqGycU=
=FAud
-----END PGP SIGNATURE-----

--------------enig72E7E7B9FE6D1728FDD5F48D--