Live data from Hacker News

New Year's Resolution: Full Disk Encryption on Every Computer You Own

eff.org

71–80 of 187 posts

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#71
post #24

Unfortunately, the amount of time I spend running/breaking the development version of Ubuntu prohibits full disk encryption, but I do have /home encrypted. Is that "good enough"?

That's what I intend to do the next opportunity I get. Your swap space could still leak confidential information, though.

I'm willing to risk that since I rarely use any of my swap.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#72
post #56

On OSX with Lion - there is no excuse http://osxdaily.com/2011/08/10/filevault-2-benchmarks-disk-e...

Does it now play well with Time Machine?

Yeah, it's much cleaner vs. the old FileVault. The decryption happens at boot-time, as far as most of the OS is concerned (incl. TimeMachine) there's no encryption at all.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#73
post #61

Earlier quoted context omitted.

Looks very interesting, as services go. For this kind of thing, I'm strangely less inclined to trust a slick-looking, well-designed and heavily-marketed backup "solution".. If I do fork out for a service, I would probably rather go with the kind of company that has as their tagline: "Online backups for the truly paranoid" , like them. Pricing's not a killer either.

The reason I trust (to the extend I trust anything on this planet) Tarsnap is that Colin Percival (the creator) is a cryptographer and the FreeBSD security officer. Leading to me have a higher confidence in him than most of the other "secure" backup services I have seen.

Yeah that's what I mean - it looks more trustworthy than something over-designed with 5 carefully-crafted price plans. Think I'll give it a shot soon. Thanks!

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#74
post #58
post #29

If you go full disk encryption with TrueCrypt, make sure you look into their Hidden OS feature as well. A judge may be able to order you to give up the decryption key to the OS when accessing the drive prompts for one (last I checked the precedent is still somewhat shaky), because while they can't know what's being encrypted they can infer something readable is. They can't prove the existence of a Hidden OS, though,…

The RIP Act in the UK allows for jail time for refusing to give a key.

"RIP privacy", amirite??

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#75

Earlier quoted context omitted.

Does it? Even if you have a CPU with AES-NI instuctions like an Intel Core i5 or i7?

unfortunately yes, see http://blog.siyuz.net/2010/11/17/truecrypt-7-0a-fde-on-ssd/#

This case is only relevant to SSDs with a sandforce controller, however -- as (only) the sandforce controller compresses data for increased speed, which cannot be done with encrypted data.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#76
The feds and other serious folks are pretty careful these days not to turn off anything until they've had forensics evaluate the situation. And not just because of FDE, memory analysis very frequently yields the best evidence due to it's timely and overlooked nature. Since most encryption systems retain their keys during lock and sleep, unless you usually leave your system powered off I wouldn't count on being afforded much privacy if you're interesting enough to bother.

That said I still use it on both of mine and definitely suggest it, it's a very small performance penalty for what will be a godsend if your laptop turns up lost or stolen.

https://code.google.com/p/cryptsetup/ It's an excellent precaution against the much more mundane and common threats like loss or theft though

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#77
post #42
post #29

If you go full disk encryption with TrueCrypt, make sure you look into their Hidden OS feature as well. A judge may be able to order you to give up the decryption key to the OS when accessing the drive prompts for one (last I checked the precedent is still somewhat shaky), because while they can't know what's being encrypted they can infer something readable is. They can't prove the existence of a Hidden OS, though,…

Might look odd if none of the files on the decoy have been modified in the last 6 months - logging in to do this regularly and in a believably meaningful way seems like a burden. The good news is unless you're an international crime lord, it seems unlikely there will be anyone on hand in the court to make this kind of leap (not a lawyer so that guess could be way off though).

An automated update of the decoy would be a good addition to such software.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#78
post #60
post #41

Earlier quoted context omitted.

I'm not sure the cloud is as difficult to access as you may think. Many cloud services have built-in law enforcement interfaces (LEI) to make searching the data self-service and easier for law enforcement as well as the cloud providers. Source: http://news.cnet.com/8301-13578_3-10446503-38.html

The answer is, of course, to store your data online and encrypt it.

Which is what we thought was happening with Dropbox and why people were up in arms about discovering that it wasn't the case.

There remains the space for a cloud sync service that encrypts client side and provides good enough clients for every major platform.

Spider Oak comes close, but it's just too damn ugly an interface and isn't the "Install and forget" option that Dropbox is.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#79
post #35

Earlier quoted context omitted.

I'm adding FDE too :) I use Knox for Vaults (on Mac), what do you use out of curiosity?

Knox is a better UI for the bultin in folder encryption on OSX?

see http://help.agilebits.com/Knox/why_knox.html

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#80
post #78
post #60

Earlier quoted context omitted.

The answer is, of course, to store your data online and encrypt it.

Which is what we thought was happening with Dropbox and why people were up in arms about discovering that it wasn't the case. There remains the space for a cloud sync service that encrypts client side and provides good enough clients for every major platform. Spider Oak comes close, but it's just too damn ugly an interface and isn't the "Install and forget" option that Dropbox is.

Who thought that was happening with Dropbox? Did they ever make the claim that they would encrypt people's data?
Post reply on HN