From owner-freebsd-questions@FreeBSD.ORG Wed Jul 25 18:57:33 2012 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52]) by hub.freebsd.org (Postfix) with ESMTP id 3A8261065677 for ; Wed, 25 Jul 2012 18:57:33 +0000 (UTC) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Received: from wojtek.tensor.gdynia.pl (wojtek.tensor.gdynia.pl [89.206.35.99]) by mx1.freebsd.org (Postfix) with ESMTP id 896A08FC21 for ; Wed, 25 Jul 2012 18:57:32 +0000 (UTC) Received: from wojtek.tensor.gdynia.pl (localhost [127.0.0.1]) by wojtek.tensor.gdynia.pl (8.14.5/8.14.5) with ESMTP id q6PIvVfm009820 for ; Wed, 25 Jul 2012 20:57:31 +0200 (CEST) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Received: from localhost (wojtek@localhost) by wojtek.tensor.gdynia.pl (8.14.5/8.14.5/Submit) with ESMTP id q6PIvU0W009817 for ; Wed, 25 Jul 2012 20:57:31 +0200 (CEST) (envelope-from wojtek@wojtek.tensor.gdynia.pl) Date: Wed, 25 Jul 2012 20:57:30 +0200 (CEST) From: Wojciech Puchar To: freebsd-questions@freebsd.org Message-ID: User-Agent: Alpine 2.00 (BSF 1167 2008-08-23) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; format=flowed; charset=US-ASCII X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.2.7 (wojtek.tensor.gdynia.pl [127.0.0.1]); Wed, 25 Jul 2012 20:57:31 +0200 (CEST) Subject: geli - selecting cipher X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 25 Jul 2012 18:57:33 -0000 i need high speed disk encryption (many disks running in parallel, lots of data movement). i have processor with AES-NI. geli give 150MB/s performance (tested from/to md ramdisk) using default and recommended AES-XTS and ca 400MB/s read and 700MB/s write using AES-CBC. I'm not cryptography expert, is CBC somehow "less secure", and if so is it really a problem?