It would be nice to have native ZFS encryption. I currently use ZFS on Linux on top of a LUKS container. I’m not quite bold enough to add in the encryption patches and use that on my primary data store yet. :)
Reading the mailing list thread on this CFT. It looks like the implementation might suffer from the same watermarking vulnerabilities that the Oracle implementation suffers from. More research needed.
It would be nice to have native ZFS encryption. I currently use ZFS on Linux on top of a LUKS container. I’m not quite bold enough to add in the encryption patches and use that on my primary data store yet. :)
Reading the mailing list thread on this CFT. It looks like the implementation might suffer from the same watermarking vulnerabilities that the Oracle implementation suffers from. More research needed.
Is this still vulnerable to watermark attacks?
I’ll just stick to GELI encrypting all my drives…
edit: looks like yes https://lists.freebsd.org/pipermail/freebsd-current/2018-August/070860.html