<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments on: Dear Fedora Developers</title>
	<link>http://blogs.gnome.org/hughsie/2007/11/26/dear-fedora-developers/</link>
	<description>My fiancee is like Windows Vista: Looks pretty, difficult to understand and sometimes unpredictable...</description>
	<pubDate>Sat, 30 Aug 2008 15:10:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
		<item>
		<title>By: Anonymous</title>
		<link>http://blogs.gnome.org/hughsie/2007/11/26/dear-fedora-developers/#comment-143</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 26 Nov 2007 17:08:35 +0000</pubDate>
		<guid>http://blogs.gnome.org/hughsie/2007/11/26/dear-fedora-developers/#comment-143</guid>
		<description>We&apos;re working on some bits for easier file system (well, really block device) encryption for Fedora 9 that will basically boil down to    [X] Encrypt and protect data that then prompts you to unlock at boot.  First anaconda bits landed about a week ago, but there&apos;s still quite a bit more work to do.   The problem with the "encrypt my home directory" case is that all of the encryption solutions are block device based.  And a separate block device per user home directory just doesn&apos;t scale.  Growing and shrinking filesystems online sucks (ie, you can&apos;t shrink) and you can&apos;t know a priori how much space each user is going to need.  So blah, losing. &lt;a href="http://ecryptfs.sf.net" rel="nofollow"&gt;eCryptFS&lt;/a&gt; is somewhat promising as an overlay filesystem, but alas, not nearly ready and progress is slow on things like separate encryption keys per fs subtree and allowing things like a ~/Public which _isn&apos;t_ encrypted (so that it can be access by apache which won&apos;t have access to your keyring and thus wouldn&apos;t be able to decrypt it)</description>
		<content:encoded><![CDATA[<p>We&apos;re working on some bits for easier file system (well, really block device) encryption for Fedora 9 that will basically boil down to    [X] Encrypt and protect data that then prompts you to unlock at boot.  First anaconda bits landed about a week ago, but there&apos;s still quite a bit more work to do.   The problem with the &#8220;encrypt my home directory&#8221; case is that all of the encryption solutions are block device based.  And a separate block device per user home directory just doesn&apos;t scale.  Growing and shrinking filesystems online sucks (ie, you can&apos;t shrink) and you can&apos;t know a priori how much space each user is going to need.  So blah, losing. <a href="http://ecryptfs.sf.net" rel="nofollow">eCryptFS</a> is somewhat promising as an overlay filesystem, but alas, not nearly ready and progress is slow on things like separate encryption keys per fs subtree and allowing things like a ~/Public which _isn&apos;t_ encrypted (so that it can be access by apache which won&apos;t have access to your keyring and thus wouldn&apos;t be able to decrypt it)</p>
]]></content:encoded>
	</item>
</channel>
</rss>
