• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Free Open Source On-The-Fly Encryption Software

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
You know, with all the talk lately about the courts ordering people to decrypt their hard drives (here), now seems like a good time to look into something like this. It's free, open source and works on-the-fly.

In case an adversary forces you to reveal your password, TrueCrypt provides and supports two kinds of plausible deniability:

  • Hidden volumes (see the section Hidden Volume) and hidden operating systems (see the section Hidden Operating System).
  • Until decrypted, a TrueCrypt partition/device appears to consist of nothing more than random data (it does not contain any kind of "signature" ). Therefore, it should be impossible to prove that a partition or a device is a TrueCrypt volume or that it has been encrypted (provided that the security requirements and precautions listed in the chapter Security Requirements and Precautions are followed).
 
I think I just recommended this a few days ago in a different article... quite a few people on [H] recommend TrueCrypt whenever disk encryption comes up. There's a few caveats but, by and large, it's a fantastic way to secure your machine.

A nice note for the [H] amongst us: if you have one of the i7-series processors from Intel they have a separate AES instruction set (AES-NI) to further improve the speed of the encryption/decryption process. TrueCrypt takes advantage of this instruction set, which helps to alleviate the speed offset of using encryption.
 
I've been using TrueCrypt for years now. It's a great little program. Also, it runs in a PE environment in case the OS drive is encrypted but unable to boot...
 
Pfffff..... Whatev.... Here is how it ends:

Gibbs: McGee, I need to see what's on this hard drive....!!!
McGee: But it's encrypted....
Gibbs: Now, McGee.....!!!!!!!!!!!!
McGee: Yes boss!
......10sec later......
McGee: Almost there boss....
.......5 sec later......
McGee: Got it boss!

Game over!

/;)
 
Pfffff..... Whatev.... Here is how it ends:

Gibbs: McGee, I need to see what's on this hard drive....!!!
McGee: But it's encrypted....
Gibbs: Now, McGee.....!!!!!!!!!!!!
McGee: Yes boss!
......10sec later......
McGee: Almost there boss....
.......5 sec later......
McGee: Got it boss!

Game over!

/;)

QFT
 
Pfffff..... Whatev.... Here is how it ends:

Gibbs: McGee, I need to see what's on this hard drive....!!!
McGee: But it's encrypted....
Gibbs: Now, McGee.....!!!!!!!!!!!!
McGee: Yes boss!
......10sec later......
McGee: Almost there boss....
.......5 sec later......
McGee: Got it boss!

Game over!

/;)

Very true.

I played with TrueCrypt years ago, but I've never done a whole system. I wonder how it'd work on a central server where all my data is actually stored. I assume it needs a password every time it reboots (I'd have to deal, do my reboots weekly or something).
 
I use Truecrypt for a few folders on my server where I store private documents (Bank statements and such)... I do this as I also have internet facing aspects (behind a firewall) of my server, and would prefer not to trust things to chance.

I did it the easy way, every time it rebooted I had to manually mount the volume and enter the password.

From what I've read though, you can also program truecrypt to react to some sort of token, such as a USB key, or to look for a file on such. So as long as the USB key is in the folder the files will decrypt. Might be what you would want
 
Very true.

I played with TrueCrypt years ago, but I've never done a whole system. I wonder how it'd work on a central server where all my data is actually stored. I assume it needs a password every time it reboots (I'd have to deal, do my reboots weekly or something).

There's an option to mount and dismount automatically built into the program. Or, you can use command line parameters too. This is what we do for our backups. It launches the command to mount the drive, copies all the information over and then dismounts the drive.

As for encrypting the system drive, it builds the encryption software into the HDD's MBR. When you first turn on the computer it prompts for a password. Without the password, all the data and the HDD is scrambled and unreadable.
 
Pfffff..... Whatev.... Here is how it ends:

Gibbs: McGee, I need to see what's on this hard drive....!!!
McGee: But it's encrypted....
Gibbs: Now, McGee.....!!!!!!!!!!!!
McGee: Yes boss!
......10sec later......
McGee: Almost there boss....
.......5 sec later......
McGee: Got it boss!

Game over!

/;)

Are you saying that if they wanted it could be cracked? I thought this stuff would take years on high end hardware to crack
 
Are you saying that if they wanted it could be cracked? I thought this stuff would take years on high end hardware to crack

I think he's trying to explain that he has no balls or that his employer controls them. :)

The encryption would take decades to brute force hack, maybe a little less with a bad password and using a keyword list.
 
That's what I originally thought, which is a shame for people who want privacy and are shy and give up easily.
 
Very true.

I played with TrueCrypt years ago, but I've never done a whole system. I wonder how it'd work on a central server where all my data is actually stored. I assume it needs a password every time it reboots (I'd have to deal, do my reboots weekly or something).

you can use passwords, tokens, usb keys, tokens on usb keys or a network drive and almost any combination and add or remove them at any time. You can make the token anything. A mp3 you like on the web. A picture of your dog/cat/girlfriend/whatever.

It's pretty bulletproof.
 
I use Truecrypt on my laptop. After having one stolen it's something I definitely will do on all future laptops as well.. They still end up with your hardware but none of your data, they have to reformat and reinstall at least.
 
Just kinda as an aside, this judge ordered the decryption because they have a recording of her saying that evidence was in the encrypted volume. If they didn't have that, then the judge likely wouldn't have ordered it. The judge has ALSO ordered the prosecution to not mention that she did decrypt the drive, so they can't use that as evidence against her.

Truecrypt is great stuff, but being stupid can undermine any encryption. It's not a perfect get-out-of-jail-free card. If someone knows you're hiding something specific in an encrypted volume, you will be put in jail.
 
Just kinda as an aside, this judge ordered the decryption because they have a recording of her saying that evidence was in the encrypted volume. If they didn't have that, then the judge likely wouldn't have ordered it. The judge has ALSO ordered the prosecution to not mention that she did decrypt the drive, so they can't use that as evidence against her.

Truecrypt is great stuff, but being stupid can undermine any encryption. It's not a perfect get-out-of-jail-free card. If someone knows you're hiding something specific in an encrypted volume, you will be put in jail.

It's not what they know, it is what they can prove. If they end up not getting access they have no evidence. Anything saying we know the evidence is there is irrelevant. It's hearsay. If they can use that argument, they can create a black box say anything is in it and "force you to provide the password" to their evidence. Something you cannot do.

The whole point of the fifth amendment is to not allow someone ( who knows their rights ) to dig themselves a deeper hole. You have a right to remain silent and perform no actions whatsoever to help them with your persecution/prosecution.
 
you can use passwords, tokens, usb keys, tokens on usb keys or a network drive and almost any combination and add or remove them at any time. You can make the token anything. A mp3 you like on the web. A picture of your dog/cat/girlfriend/whatever.

It's pretty bulletproof.

Oh sweet! It canbe like Johnny Pneumonic!
 
I've been using TrueCrypt for years now, encrypting a hidden partition on my external drive. It's amazing and (free, too!) would definitely recommend it to anyone.
 
Pfffff..... Whatev.... Here is how it ends:

Gibbs: McGee, I need to see what's on this hard drive....!!!
McGee: But it's encrypted....
Gibbs: Now, McGee.....!!!!!!!!!!!!
McGee: Yes boss!
......10sec later......
McGee: Almost there boss....
.......5 sec later......
McGee: Got it boss!

Game over!

/;)

You forgot about the part where Gibbs is about ready to deliver his fronthand. :D
 
Agreed, truecrypt is on all my laptops. Use a yubikey in static mode along with your password for a sort of two factor + adding more entropy to your key (that standard 8 character mixed case password you have may be weak to a brute force attack, but a fully random 128 bit key won't be).

If they steal it, they get the hardware including the expensive ssd, but they'll never get the invaluable work data on the laptop itself. Keep regular backups and should the laptop get stolen you just get a new one and restore and reencrypt and you're good to go.
 
Encryption still isn't an option for computer's running SSDs though right?
Um, why would it not be available on a SSD?
Encryption works on just about everything, including SD cards and flash drives.
 
What is needed is a way to store your login token on an edible device.

That way when the police kick in your door you just quickly swallow it and let your stomach acid erase the evidence.

Plus it will be impossible to force you to decrypt the drive because you don't know the contents of the 1024 bit key...
 
Or some other sort of easily erasable/destroyable token.

Passwords are bad because you actually know what they hence you can be forced/tortured/bribed/etc to reveal it.
 
Yubikey static key, toss it in the trash and your data is forever lost.
 
I see that Yubikey seems quite interesting...

Just push the button and it generates a new random password that cannot decrypt the old stuff...

I still think the edible one is more effective... no evidence for the police to find in you rubbish.
 
another here who has been using tc for who knows how long now. Great bit of software that we all should use.
 
I've been using TrueCrypt for years now.

One TC drive stores bank account and other financial information. The second TC drive stores my tax documents of the last 4 or so years, plus tax documents of my customers.

I might consider getting a small 8 GB or 16 GB SSD and encrypt the entire thing with TC in the near future.
 
Also, only reason I switched to Truecrypt was because when I moved from XP to Vista, the security key for some damn reason did not work in Vista so it corrupted all the files in the encypted folder.
 
Or some other sort of easily erasable/destroyable token.

Passwords are bad because you actually know what they hence you can be forced/tortured/bribed/etc to reveal it.



I guess you could pop the token in your microwave & that should take care of it? Or throw it in fire but the one I like the most is to keep the token in some kind of ceramic enclosure with thermate & set that mofo off with a wireless ignition switch when they are busting down your door! Instant melt down...instant melt down. The whole setup on battery backup lol..:D
 
There are lots of self destructing USB keys out there now. Some will autodelete and "break" themselves if they aren't accessed within a certain time frame or are ever connected to a unrecognized PC. Others erase themselves after failed attempts or if they aren't access by proprietary software, or they show a "fake" drive unless that partition is unlocked with software.
 
How does apparent random data on a drive not look like encryption?

It's not like a new drive, a freshly reformatted drive, or deleted files leave random data behind.
 
Back
Top