Live data from Hacker News

New Year's Resolution: Full Disk Encryption on Every Computer You Own

eff.org

51–60 of 187 posts

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#52

My system triple boots into OS X, Windows and Ubuntu. I have a home partition, formatted in HFS+. What would be the best strategy for me to use? Should I just encrypt the home volume using something cross-platform like TrueCrypt, or is it practical (an maintainable) to do full-disk encryption in such an environment? My home partition has very sensitive data and I've been putting off creating a TrueCrypt container for…

This is probably not answering your question but a possible solution is to switch to using OSX 100% of the time and then use Parallels/VMWare/VirtualBox to virtualize Windows and Ubuntu. It's much more practical than having to worry about partitions / boot volumes and general sharing problems. This way you can even encrypt your entire OS X volume and not use encryption on the VMs.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#53
post #14

It's sad we need encryption mostly for protection from not criminals, but our own government for even trivial data. What freaks me out most these days is how easily people fall into the belief that "oh well traveling is not a right so you have to give up rights when you fly or drive anywhere". No, if you are a citizen of the United States and unless you are actually crossing a border, you should have the unqualified…

First hacker rule when crossing a border: Wipe your disks or do not bring disks at all. This also applies to companies who do have strong competitors who work with the authorities (e.g. if you travel to china / US).

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#54
It's nice that computers are now powerful enough that full disk encryption is almost performance-neutral. But realistically, if they want your data then they can get it. Spear phishing works very well and if not, there's always indefinite detention.

Technology is only a small part of the solution to warrantless border searches.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#55
post #44

Earlier quoted context omitted.

I actually trust tarsnap more than setting up a host and having to maintain it: http://www.tarsnap.com/

Looks very interesting, as services go. For this kind of thing, I'm strangely less inclined to trust a slick-looking, well-designed and heavily-marketed backup "solution".. If I do fork out for a service, I would probably rather go with the kind of company that has as their tagline: "Online backups for the truly paranoid" , like them. Pricing's not a killer either.

This service is run by a long time hacker news user and security researcher cperciva. Read his stuff:

http://news.ycombinator.com/user?id=cperciva

http://www.daemonology.net/blog/

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#57
post #49

On OSX with Lion - there is no excuse http://osxdaily.com/2011/08/10/filevault-2-benchmarks-disk-e...

Have you noticed crashes and general instability on OS X Lion + Filevault 2? We've tried it on a Core2Duo Macbook Pro (early 2007) and MacBook (Mid 2010). We've seen lots of OS crashes (Macbook) and general performance issues when running XCode (Macbook Pro). We're also running virtualization software on the Macs (Parallels and VMWare) - I'm not sure if they're interacting with Filevault 2 (shouldn't be). Just wonder…

I use it on a 2011 Air and Mini without problems, and I'm just about always in Parallels on both machines.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#58
post #29

If you go full disk encryption with TrueCrypt, make sure you look into their Hidden OS feature as well. A judge may be able to order you to give up the decryption key to the OS when accessing the drive prompts for one (last I checked the precedent is still somewhat shaky), because while they can't know what's being encrypted they can infer something readable is. They can't prove the existence of a Hidden OS, though,…

The RIP Act in the UK allows for jail time for refusing to give a key.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#59

do most people really have private information on their computer? I don't think I do ...

depends what you consider private. for me, everything is private as long as i don't put it online consciously. yes, even that photo of me sitting on a chair.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#60
post #41

Earlier quoted context omitted.

No, if you are a citizen of the United States and unless you are actually crossing a border, you should have the unqualified protection against unreasonable searches, especially without warrants. I agree. Practically speaking, the government can only search what you're physically carrying over the border. That means if you boot from something like a live CD and store all your data in the cloud, you're safe from searc…

I'm not sure the cloud is as difficult to access as you may think. Many cloud services have built-in law enforcement interfaces (LEI) to make searching the data self-service and easier for law enforcement as well as the cloud providers. Source: http://news.cnet.com/8301-13578_3-10446503-38.html

The answer is, of course, to store your data online and encrypt it.
Post reply on HN