( dash | 2015. 01. 24., szo – 19:31 )

" Plain format is just that: It has no metadata on disk, reads all parameters from the commandline (or the defaults), derives a master-key from the passphrase and then uses that to de-/encrypt the sectors of the device, with a direct 1:1 mapping between encrypted and decrypted sectors.

Primary advantage is high resilience to damage, as one damaged encrypted sector results in exactly one damaged decrypted sector. Also, it is not readily apparent that there even is encrypted data on the device, as an overwrite with crypto-grade randomness (e.g. from /dev/urandom) looks exactly the same on disk."

https://code.google.com/p/cryptsetup/wiki/FrequentlyAskedQuestions

------------------------------------------------------------------------------
www.woodmann.com/searchlores/welcome.htm