![]() |
|
|||||||
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
#1
|
||||
|
||||
|
What's your best defense against a boot CD that breaks Windows passwords in two keystrokes? Encrypting your entire hard disk. Shannon's got the details on truecrypt drive encryption while Darren brings up plausible deniability with hidden volumes.
Watch or download the episode now! |
|
#2
|
||||
|
||||
|
Great ep! I dont use drive encryption, but i just might start!
Its also a good idea for USB keys as well. Speaking of security I do use an application called KeePass Password Safe and I have been using if for a very long time. I have all my banking info in it, I have all my work administrative passwords and even stuff like my WoW accounts info and serial number info. -MayheM
__________________
"The statistics on sanity are that one out of every four Americans are suffering from some form of mental illness. Think of your three best friends. If they're okay, then it's you." - Rita Mae Brown. |
|
#3
|
||||
|
||||
|
I love that you guys were drinking yuengling... i live close to the brewery where it is made (oldest brewery in the US)... tasty stuff. it's good to see u representing the east coast
![]()
__________________
Why do you have flies in your freakin house? I noticed this earlier. It's southern California and I have fruit. You put zombie and you put eerie in the title and I don't wanna do it. |
|
#4
|
|||
|
|||
|
I posted this on the Hak5 forums as well, but I figure I may as well get, err.... corrected by two groups of users:
I see a couple of problems with the whole "plausible deniability" thing with TrueCrypt. First of all, you'd have to give even the fake folder a decent password (not some lame one as Darren did on the show) in order for it to be believable (right, the password to all your financial documents is "hunter2", sure....); second, in order for you to have a believable fake hidden file, the information has to look like you'd want to protect it (fake banking information or confidential documents), but more often than not, you'd have to include a date somewhere ("July 2, 2009: $300 ABM withdraw at 2:48am" or "January 15, 2000: subject appears restless") and if someone sees this and sees that the information is old, they might get suspicious. However, you can't update the fake files since TrueCrypt warns this can damage the inner volume. Third, at this point, if someone sees that you have an encrypted file on your computer, wants the information that badly and sees that you have TrueCrypt on your HDD, won't they just assume you have a hidden volume and any claims otherwise are fraudulent? I know if I was going to (hypothetically, of course) torture someone for the password to a TrueCrypt volume, I'd keep torturing them for a password until the volume type was listed as "Hidden". And I'm now prepared for the barrage of replies telling me why I'm way off base on every single point. |
|
#5
|
||||
|
||||
|
Quote:
Even truecrypt itself can't tell if there is a hidden volume present. It simply tries to decrypt the file with every algorithm with the password you give it until it gets one that works. If it can't, it tells you either the password isn't correct or the file is not a truecrypt volume. Your files can be old and the person trying to get in can be as suspicious as they want. Without the password you won't be able to find the hidden volume. Also, there's no security measure you can take that will protect against a person giving someone the key, so theres nothing that will protect against the torturing scenario you mentioned.
__________________
Why do you have flies in your freakin house? I noticed this earlier. It's southern California and I have fruit. You put zombie and you put eerie in the title and I don't wanna do it. Last edited by MasterQ : 07-03-2009 at 10:03 PM. |
|
#6
|
|||
|
|||
|
Quote:
|
|
#7
|
|||
|
|||
|
It is amazing what you can do by just hiding things in plain sight. You just have to be inventive the way you store files encrypted.
|
|
#8
|
|||
|
|||
|
hey, guys, cool episode, but i think that some viewers would find it cool to talk about the strength of the various encryptions and hashes and how long it would take to crack (with various cracking techniques) them!
Last edited by bobo99 : 07-06-2009 at 02:56 AM. |
|
#9
|
||||
|
||||
|
Quote:
The US government uses AES for top secret file encryption because it takes a VERY long time to crack if it has a good key (which truecrypt will warn you about if yours is too short). Encrypting using two or all three of the algorithms makes it virtually impossible to crack any time soon (like in this lifetime)
__________________
Why do you have flies in your freakin house? I noticed this earlier. It's southern California and I have fruit. You put zombie and you put eerie in the title and I don't wanna do it. Last edited by MasterQ : 07-06-2009 at 01:46 PM. |
|
#10
|
|||
|
|||
|
I never said that truecrypt was hiding things in plain sight. Renaming a file is an oversimplified way to hide a file in plain sight. There are also more sophisticated yet very simple ways to hide things in plain sight other than just embedding an encrypted file in to a picture or the like.
I see no sense in encrypting a whole drive when usually the size of the sensitive data is only a fraction of that. During WWII, American Indian dialects were used to transmit messages. No encryption was necessary per say, except for using non traditional keywords. Security by obscurity. Last edited by computoman : 07-06-2009 at 02:52 PM. |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
|||||