Live data from Hacker News

New Year's Resolution: Full Disk Encryption on Every Computer You Own

eff.org

111–120 of 187 posts

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#111
post #76

The feds and other serious folks are pretty careful these days not to turn off anything until they've had forensics evaluate the situation. And not just because of FDE, memory analysis very frequently yields the best evidence due to it's timely and overlooked nature. Since most encryption systems retain their keys during lock and sleep, unless you usually leave your system powered off I wouldn't count on being afford…

If you're worried about a state-level adversary, then yes, you should always turn off your computer when not using it. They could still be spying on you and wait until you turn it on to kick down the door. There are people who have thought about these things, too. One suggestion is a dead man's trap, like a pad that you sit on, so if the door gets kicked down (or they snipe you from outside the window), as soon as you stand up (or fall off the stool) it scrambles RAM and shuts down the system. That's a super high level of paranoia, but still makes encryption useful.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#112
What about on my mobile? I am not aware (as I havent looked) of any encryption available to the data on my iPhone, or MyTouch 4G.

Further, I use Gmail - I have zero expectation of privacy from google.

I also store all my important docs for work and personal on DropBox.

What will I gain from encrypting my laptop? aside from it being stolen/lost - I dont see any added security/benefit from doing this.

I am not trying to be obtuse - but can one explain to me why I would want to do this, other than expressing my tech savvy?

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#113

I'm not an expert on security, but I do know a bit about human nature. I'd suggest a 2-level encryption scheme. Perhaps FDE and a BIOS password as level 1, and then a futher encrypted area of your HD as level 2. Why? Because this allows you to appear to be cooperating with any request to look at your computer. Simply type in the level 1 stuff and demonstrate the system booting up. I bet 9 times out of 10 whoever is c…

Truecrypt has a hidden OS option. It does sound like some work, however.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#115
post #43

Microsoft BitLocker in its most secure mode is the gold standard because it protects against more attack modes than other software. Unfortunately, Microsoft has only made it available with certain versions of Microsoft Windows. Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is... [1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

Exactly. Trusting proprietary, closed source software (in other words, a third party) for encryption is missing the point of encryption so hard, it's not even funny.

> Trusting proprietary, closed source software (in other words, a third party) for encryption is missing the point of encryption so hard, it's not even funny.

I don't have the experience, knowledge, and time (+ effort) to review every source-code line and every theorem used by an encryption application ... to make sure it's not doing something it shouldn't.

And (chances are) you don't either.

So it's not about closed-source or open-source, but rather it's about trust.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#116
One thing that worries me is how difficult it makes it if you get some data corruption. For example, I had a hardrive that had full disk encryption start to fail, and found pulling the data off much more difficult because I had to decrypt the whole lvm to get any access. I'm actually not confident how exactly corruption maps from cyphertext to plaintext in various modern crypto systems. I would guess that you would get out gibberish though.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#117

Earlier quoted context omitted.

Who thought that was happening with Dropbox? Did they ever make the claim that they would encrypt people's data?

https://www.dropbox.com/features claims "Secure Sockets Layer (SSL) and AES-256 bit encryption," and I truly do believe they encrypt. However, I also know that since their website allows me to access data and reset my password, their key management doesn't prevent Dropbox employees from viewing my stuff.

"they encrypt" can mean several different things. It's understandable that a naive ordinary internet user may get confused about the differences between "We use SSL" vs "We use client-side encryption and never see your passphrase" vs "we promise to encrypt your data before it's stored on third party servers". However, there's no excuse for any technically inclined person to confuse those things.

Dropbox had said that they encrypt data before storing it at Amazon, but their systems see all of your raw data because they do deduplication, and because they could reset your passphrase, and because client-side encryption of stored data would make web access very complicated if not impossible.

If all that weren't enough, the dropbox forums, long before the early 2011 PR problem, had threads about using truecrypt containers on dropbox shares to ensure security. It also had feature requests to add client-side encryption to the dropbox client. If some people didn't get the message that dropbox has access to raw data, after all of that evidence, they have only themselves to blame.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#118
Can anyone comment on the speed/performance of TrueCrypt, EncFS, and similar on older systems, e.g. a 5 - 7 year old laptop? I'm considering carrying a "sacrificial" machine in case it is, um, "indefinitely detained", but I'm uncertain what kind of a performance hit full disk (or partition -- though I'm inclined to encrypt the entire disk) encryption will incur. (I currently have Core Duo and P4 candidates for the job.)

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#119
post #93
post #81

Earlier quoted context omitted.

Filevault isn't supported by the major media editing apps. I travel a lot and rely on having a 'fake' account on my drive that I can login to if asked that has pretty much nothing on it.

you must be thinking of the original filevault that encrypted each user's home directory separately. filevault 2 in lion is true full-disk encryption, and the passphrase must be entered at boot. once it is decrypted, no application should even be able to detect (or rather, care about) the presence of encryption.

Oh, great to know thanks. I haven't moved to lion yet because of app support.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#120

Earlier quoted context omitted.

Drug trafficking and illegal immigration?

drug trafficking, illegal immigration don't serve as counterpoints; you're putting the cart before the horse The drugs trade is the flow of narcotics from source to sink. Stopping them at a national border is one approach; stopping them elsewhere in transit (as it leaves the source, on the open sea, at the destination by local police, etc) is another. And then you have one more: tackling the existence of a source and…

You got me wrong: I'm saying why they are - I'm not saying they should be.
Post reply on HN