Live data from Hacker News

New Year's Resolution: Full Disk Encryption on Every Computer You Own

eff.org

61–70 of 187 posts

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#61
post #44

Earlier quoted context omitted.

I actually trust tarsnap more than setting up a host and having to maintain it: http://www.tarsnap.com/

Looks very interesting, as services go. For this kind of thing, I'm strangely less inclined to trust a slick-looking, well-designed and heavily-marketed backup "solution".. If I do fork out for a service, I would probably rather go with the kind of company that has as their tagline: "Online backups for the truly paranoid" , like them. Pricing's not a killer either.

The reason I trust (to the extend I trust anything on this planet) Tarsnap is that Colin Percival (the creator) is a cryptographer and the FreeBSD security officer. Leading to me have a higher confidence in him than most of the other "secure" backup services I have seen.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#62
post #43

Microsoft BitLocker in its most secure mode is the gold standard because it protects against more attack modes than other software. Unfortunately, Microsoft has only made it available with certain versions of Microsoft Windows. Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is... [1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

Do MS developers have a track record of bald-faced lies that I'm unaware of?

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#63
post #43

Microsoft BitLocker in its most secure mode is the gold standard because it protects against more attack modes than other software. Unfortunately, Microsoft has only made it available with certain versions of Microsoft Windows. Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is... [1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

Exactly. Trusting proprietary, closed source software (in other words, a third party) for encryption is missing the point of encryption so hard, it's not even funny.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#64
I'm not an expert on security, but I do know a bit about human nature. I'd suggest a 2-level encryption scheme. Perhaps FDE and a BIOS password as level 1, and then a futher encrypted area of your HD as level 2.

Why? Because this allows you to appear to be cooperating with any request to look at your computer. Simply type in the level 1 stuff and demonstrate the system booting up. I bet 9 times out of 10 whoever is checking you over will stop right there: it looks a lot like compliance. If they keep pushing for total access to your data simply say "no" Whereas if you say "no" to begin with, you're likely to attract more attention than if it appears you have nothing to hide. In many cases people are working jobs where they only have so much time to check things -- unless there appears to a be a person with a problem, in which case they can take all day with you. So help them out. Give them something to ask you for that you can produce. Then everybody can move along and it's not a problem for anybody.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#65
post #54

It's nice that computers are now powerful enough that full disk encryption is almost performance-neutral. But realistically, if they want your data then they can get it. Spear phishing works very well and if not, there's always indefinite detention. Technology is only a small part of the solution to warrantless border searches.

What encryption gives you is choice. If you don't use it, then you never have the choice of whether or not to give up data. The choice is taken for you. If you use encryption there are many attackers that you will be able to prevent being able to access the data.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#66
post #49

On OSX with Lion - there is no excuse http://osxdaily.com/2011/08/10/filevault-2-benchmarks-disk-e...

Have you noticed crashes and general instability on OS X Lion + Filevault 2? We've tried it on a Core2Duo Macbook Pro (early 2007) and MacBook (Mid 2010). We've seen lots of OS crashes (Macbook) and general performance issues when running XCode (Macbook Pro). We're also running virtualization software on the Macs (Parallels and VMWare) - I'm not sure if they're interacting with Filevault 2 (shouldn't be). Just wonder…

I use Lion's Filevault 2 on an early 2009 MBP and have not had any crashes or stability problems at all. FV2 on Lion is light years ahead of the broken Filevault 1 (Snow Leopard) implementation.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#67
post #43

Microsoft BitLocker in its most secure mode is the gold standard because it protects against more attack modes than other software. Unfortunately, Microsoft has only made it available with certain versions of Microsoft Windows. Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is... [1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...

Exactly. Trusting proprietary, closed source software (in other words, a third party) for encryption is missing the point of encryption so hard, it's not even funny.

To be fair, I trust TrueCrypt because it's "libre" and "open", but I've never looked at the source code myself. I trust that other people more knowledgable than me have taken a look at it, but if there is indeed a backdoor in it, then it will look on the surface like the most innocuous bug in the world.

Don't get me wrong: I understand and appreciate your point, but I honestly don't know how most of us using TrueCrypt (e.g. me) are any better off than those who use a proprietary solution. The only difference I can see is any backdoors in TrueCrypt or PGP must be better hidden.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#68
post #67

Earlier quoted context omitted.

Exactly. Trusting proprietary, closed source software (in other words, a third party) for encryption is missing the point of encryption so hard, it's not even funny.

To be fair, I trust TrueCrypt because it's "libre" and "open", but I've never looked at the source code myself. I trust that other people more knowledgable than me have taken a look at it, but if there is indeed a backdoor in it, then it will look on the surface like the most innocuous bug in the world. Don't get me wrong: I understand and appreciate your point, but I honestly don't know how most of us using TrueCryp…

While you are basically correct, the mere ability to check the source yourself and possibly be able to find (or even fix) said bugs-which-could-or-could-not-be-cleverly-hidden-backdoors puts it leagues ahead of any proprietary solution, where there is never any way to be sure there isn't just something like a void force_decrypt(string company_master_password)[1] in there.

And to be perfectly honest, I'd rather trust the FLOSS crowd who checked TrueCrypt and other more or less popular encryption tools probably hundreds, if not thousands of times than trust the development team of a company refusing to release the source of their software.

[1] Yes, I am kidding, but I hope you catch my drift.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#69
post #13

None of my current computers is powerful enough for that without it being a serious hassle. And I'm pretty sure it will drain my laptop battery much faster...

I have tested Windows 7 with both Bitlocker and Truecrypt, and Arch Linux with with LUKS, on my four year old Dell e520 (a 1.8ghz Core 2 Duo 6300 PC with 4GB of RAM). I didn't notice any real performance difference with FDE enabled, although I am sure a proper benchmark tool would have shown something.

Re: New Year's Resolution: Full Disk Encryption on Every Computer You Own

#70
post #56

On OSX with Lion - there is no excuse http://osxdaily.com/2011/08/10/filevault-2-benchmarks-disk-e...

Does it now play well with Time Machine?

I also let it encrypt the disks that Time Machine writes to. Works well.
Post reply on HN