/srv/irclogs.ubuntu.com/2010/03/28/#ubuntu-us-mn.txt

* Obsidian1723 Hi all...03:10
h00kOHAI THAR03:11
h00kI smell like hot tub03:12
* Obsidian1723 *grumbles about this "IT company" that messed things up - badly*03:32
TakyojiI'm curious how many here use an encrypted /home partition21:48
_diabloTakyoji: I don't. I don't see a big purpose. Why not just use truecrypt if you actually care about it?23:07
_diabloI trust that encryption far more than whatever unspecified thing Ubuntu has decreed is best23:07
_diabloDo you know off hand what type of encryption algorithms they use?23:07
rlaagerI have an encrypted ~, which is what I assume you mean.23:22
rlaagerThe big advantage of ecryptfs is that I can efficiently rsync my data to a backup server and have it be *encrypted* on that backup server.23:23
rlaagerIf I had a block-level encryption solution, I'd have to rsync the whole block device, including unused space.23:23
_diablorlaager: ah, that makes sense. But rsync keeps the encryption intact?23:28
rlaager_diablo: Yes. Here's what "mount" returns for me: /home/rlaager/.Private on /home/rlaager type ecryptfs23:29
_diablohmmm, couldn't you do the same backup from one container to another container while having both mounted?23:30
rlaagerFor each regular file in my home directory, there is a corresponding file in /home/rlaager/.Private. So, excluding filename encryption (which ecryptfs has now, but didn't used to), /home/rlaager/.ssh/id_dsa would be /home/rlaager/.Private/.ssh/id_dsa, which would be encrypted.23:30
_diabloahhh23:30
rlaagerYes, you could, but then you'd have to mount the encrypted container on the remote server. This way, I don't have to trust the remote server with my data. All it ever sees is encrypted data.23:30
_diablohmmmm, makes sense. okay, I see a potential advantage then.23:31
rlaagerI'm moving from one backup server to another right now, but both of them are systems I'm sharing with co-workers. (I work at a small ISP, so we can just colo there.)23:31
rlaagerEspecially now, with new disks... I'm using only 50% of my drive at the moment. So I only need to sync that 50%, not the whole disk.23:31
rlaagerPlus, I can easily exclude certain things. For example, I exclude ~/ubuntu-*.iso.23:32
rlaagerThis used to be easier than it is now that there's filename encryption (i.e. I used to be able to exclude /home/rlaager/.Private/ubuntu-*.iso.) I know how to write the script to do that; I just need to get it going.23:33
_diabloyeah, fair enough23:41

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!