Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I use it with snapshots and ZFS send, and so far it’s been fine. Truenas users also may use it.

But I’m concerned reading these comments. Anyone else experiencing issues?



The fundamental issue with ZFS encryption is that the primary developer that created it is no longer contributing significantly to the project. It's good code, with good tests, but it's not getting any additional love.

The utilities and tooling surrounding encryption are also weak, and there are ways you can throw away critical, invisible keydata without realizing it, and no tool to allow the correction of the issue, even if you have the missing keydata on another system.


It’s interesting that there hasn’t been anyone since to continue developing Tom’s code. I wonder how long the situation might continue. If no one wants to take over in near future, they might have to remove the feature.


I've been using ZFS with native encryption (Ubuntu Server) but also ZFS with LUKS (Arch, Ubuntu Desktop). Zero issues (though inability to run latest kernel can be annoying, esp on rolling distro). Wouldn't surprise me if write cache has a role in this issue though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: