View by:

Encrypt your entire hard drive!

Wednesday, July 1st, 2009 – running time 26:50
What's your best defense against a boot CD that breaks Windows passwords in two keystrokes? Encrypting your entire hard disk. Shannon's got the details on truecrypt drive encryption while Darren brings up plausible deniability with hidden volumes.

Encrypting your entire hard drive

Truecrypt is an open-source, free program for everyone. Download the latest version of Truecrypt.

Open Truecrypt and choose ëCreate Volumeí. Choose ëEncrypt entire hard driveí. Then, you will choose whether you single-boot or multi-boot your machine.

On the encryption options, I just choose AES because it is the default setting, and itís a very strong encryption.

Next you will choose a password. This option is neat because it actually gives you a small notice saying that a password with less than 20 characters is easier to break than one with more than 20.

On the next page, you must randomize your data. You must move your mouse around in the box of algorithms to create a very randomized clump of data. The more randomized, the better encrypted.

Truecrypt will make your create a rescue disk. This is easy if you have a cd burner already installed in your tower. If not (if you have a netbook), you must create the rescuedisk.iso and burn it onto a flashdrive or something of the like. You are basically making Truecrypt think you have a cd burner and are burning the cd, when instead, you are just sticking the iso on a USB flashdrive.

For my netbook, I used WinCD Emu. WinCD Emu emulates the burning of a cd, so Truecrypt thinks youíve finished this task.

Truecrypt will ask you to wipe your drive, and I just choose none since I donít really need to. Next you must go through a pretest. Your computer will restart and a Truecrype login screen will appear before the windows login (this is why Konboot wouldnít work!). If everything goes well and the pretest completes with no problems, you can begin encrypting. Encryption takes a LONG time, so be patient! Once itís done, itíll prompt you, and youíre finished!

For a more in depth step by step, go here.

And as always, you can email me at snubs@hak5.org!

Plausible Deniability with Hidden Truecrypt Volumes

Plausible Deniability basically means being able to deny awareness of something. For a more rich explination check out Wikipedia's article on the subject, it's quite interesting.

In regards to Truecrypt, our subject of the week, Plausible Deniability referrs to the ability to hide encrypted volumes within encrypted volumes. Since it cannot be proven that a hidden volume exists within a truecrypt volume.

Hidden volumes can contain just about any data, including entire operating systems. It is important to note that the sectors of a hidden volume do not change over time. If an adversary had access to the outer volume contents over a period of time the existance of a hidden volume could be proven if files were never read or written to or from these sectors.

Questions? Comments? Write me directly, Darren@Hak5.org or send feedback to the entire Hak5 crew.

Highlights
social security ( 1:30, 1:30 ) open source ( 7:08, 16:34, 7:08, 16:34 ) hard drive ( 5:15, 7:22, 7:30, 12:37, 5:15, 7:22, 7:30, 12:37 ) squarespace ( 0:32, 4:29, 5:25, 5:28, 5:35, 5:41, 5:51, 5:54, 0:32, 4:29, 5:25, 5:28, 5:35, 5:41, 5:51, 5:54 ) social security ( 1:30, 1:30 ) open source ( 7:08, 16:34, 7:08, 16:34 ) hard drive ( 5:15, 7:22, 7:30, 12:37, 5:15, 7:22, 7:30, 12:37 ) squarespace ( 0:32, 4:29, 5:25, 5:28, 5:35, 5:41, 5:51, 5:54, 0:32, 4:29, 5:25, 5:28, 5:35, 5:41, 5:51, 5:54 )

Automatically Generated Transcript(may not be 100% accurate) ( more )

" War."

" This time on the show TrueCrypt inside and out I protect my netbook from Condit with full disk encryption and Darren just off hidden volumes in key files all that -- This episode of tax."

" This episode of Hak5 has brought to you by godaddy Squarespace. Game -- and viewers like you."

" Anybody want this week's episode of Hak5 I met last I'm Shannon Morse and there is doing with area's best witty geek. It's our episode today. And every time we got about drive encryption now what does drive encryption well you've all had nightmares about your laptop up in disappearing in the middle of the night yeah your car something like that. To that point where be bad if you were in high profile position like say Paul war. You know so it works for companies that use reason and I think you'll. A bank. That it's protected and does so real quick. Give you an example here. Ernst and young. Lost data. I'm not a pistol from. That's it it was a stolen right out of a car and there because I your security. Right out of the backseat. And you know it contains Social Security numbers your address your name your data or this is all of the key ingredients that. Identity thieves need to destroy your life and I thought they need it out and make your life a living hell that will take. Way more money -- you could possibly ever have tried next. So real quick let's give you an example of how easy it is to actually bypass the quote unquote security. All of -- windows machine which is deployed in you know. Is it eight."

" And -- it is it's super super easy I'm gonna show it off on parents laptop I'm using this thing called Condit which -- two episodes prior. So I just have to press and turn at the at boot screens. Once it gets to the crypt those logic menu just press and turn. And we got some cute little last year I just press enter again. -- So all I've done so far as present and -- just a couple of things and then once it gets to be windows login screen which looks. Completely normal all have to do is position you know I don't I don't know the password I'll just say daring us. A --"

" I -- this machine."

" Whatever you just height. That -- it -- after that I'm no expert I didn't get machines. Politics is qualities. That that you might ask you a little ice so file that's all you need. It --"

" And it. So so we've got the machine and this could have all been prevented if we would've installed encryption on on the -- it. But. We didn't so now -- light it's been destroyed. Hampshire he's got -- But he says that data on. The credit cards. Basically this. -- I can basically you know. Credit cards and you know information on there Korea on credit cards. It just does let you guys know. Were actually protect against this. -- in the corporate environment and to me yourself but first. We want to talk to you a buy out Hak5 meet up which stoked about this I actually it and it specific. There an Apple as well anyway there."

" Patrick that I -- to pursue it because we are having our very first ever Hak5 meet up and we're celebrating our our four years of podcasting at the upcoming sixth season. And we hope these guys can make it out August 15 app Busch Gardens Williamsburg. It's open to all ages we're gonna have. What beer and hacking and roller coasters and more beer it's all the details or over Hak5 meet up dot Squarespace dot com we really hope you guys come down a week with final information. -- in the tickets for Busch Gardens it's it's about sixty bucks. And and and the components afterwards which won't have any sort entrance he'd just -- so -- be -- to. And and we hope you guys come down got all the details hotels all the ones of these it. Planned trip I mean -- two months out so want to let you know or advanced that we you get the best ever Hak5 yep the first ever -- idea in. Williamsburg Virginia it's going to be -- we really hope you come out August 15. Okay well with all that said and hopefully Mac you mean while back now. -- note that in a moment Shannon's going to be showing you all sorts of cool ways that you can encrypt your hard drive and keep it -- from. Well Paul really and and until then I want to thank our wonderful sponsor. Squarespace. "

" This is one of the many reasons why Squarespace is the fastest and easiest way to those beautiful powerful website. Right now matting -- speech he formed to hack I'd need to Squarespace dot com I love the fact that there's actually no could required. Its two week free trial of Squarespace dot com to see why we're so crazy about them and be sure he's promo code Hak5 to save 10% off the life your service and support the show. And don't forget there's just a few days remaining Squarespace iPhone giveaway to be sure to use -- Squarespace you tweaks to be entered into the daily drawings until July 8. I know exactly just knowledge."

" Our guess here we are we're gonna actually show you how to protect -- data unfortunately it to Hillary's use I can't use it. Corporate environment. There's no centralized management console there's no work of free you know single recovery system that we can actually use for or personnel. But on corporate environment you do have options there are solutions from McAfee. Encryption plots are just unfortunate things from period edge and then there's also one from -- say which. You know they they use some windows experts thinking -- you want to stuff like that. Centralized recovery council's so makes -- sysadmins like almighty yet active work right things but what we're talking about today. Is."

" Open source. It's TrueCrypt. TrueCrypt is completely free it's open sourced anybody that needs to -- is incredibly fast down land which isn't really. You can do everything from encrypting your entire hard drive to get certain pieces of data. Pretty much anything that you want to you but today I'm going to be showing you guys how to encrypt your entire hard drive. Sweet. -- right which. So there's a couple of choices on the front first screen you can do encrypt system partition or drive where you can just gonna create volume highlight just -- volume that's one. That's wonderful. And I'm encrypting the system partition and or the entire system drive or -- the -- drive that just when the system partition right. And it's gonna say hey if this Chris tuition is not acceptable you can go back and she used to encrypt Lee's system partitions that. Blah -- you just press okay with that host protected area. Certain netbooks have a host protected area in the use this -- store everything from tools to date after -- All sorts of different things. Base and its its like your recovery partition things Apple's of the so ultimately these years use wrote your royally. So from what I've heard online. From the different tutorials that I've read about this is you shining encrypt your -- protected areas just to be on the safe side salt she's now on that. Single -- bit multi bit that's obvious. I'm a single player. Next line is encryption options this is on your standard encryption options ES serve and when great. It's so I'll just stick with a yes. And then you choose your password. This is pretty cool because if you choose a password that's under twenty characters it's gonna come up and say hey it's a lot easier to break a twenty character password than it is something over twenty characters. And I'll keep on saying that until you get something that's over twenty. So up in. Let's see. -- and -- Arafat to do capitalize -- and and numbers. This is kind of interesting and weird all at the same time so it says you're supposed to move your mouse around for a long time just to get a very very randomized amount of keys. And it's very magical. In my opinion. Basic -- is taking your cursor position in translating that he news that Jerry. -- and it's. It's Simon and around for like a minute and -- next. And you see I have my had a key in mind streaky. As Mexican. Now this part that can't screw me up when I was doing this on mine but. The -- my -- that is it doesn't have a CD-ROM drive. With encryption on -- old disk drive. It's going to tell you that you have to make a rescue disk. BS CB. You hacked. So I'm gonna go to browse and I'm just gonna create this thing called rescue disks -- now that. Gonna save that. And then press next. And then it says it's being created has been stored so that's as snacks again see it's gonna tell me you how to burn a -- yet you can't go line yet. You have to treat this rescued this just in case so basically the actual applications looking out for you yes it is it's protecting -- just in case yeah you need to rescue -- that so how we get by this -- netbook which obviously. Room. This is what I do I found this really cool program called -- CDE and you emulator you basically just install it. You you running and then you create CD emulation on your computers you can turn little clusters. And SD cards. And make those work as if they are CD's -- your eyes on there and you can skip this part in Italy you go ahead to get."

" Basically use something like daemon tools -- power i.s so just -- the eyes so have a scan it and say if we wanted to live dangerously that is. Just basically any -- it any ice -- utility."

" Makes it look like CD-ROM drive yes exactly exactly that's what it's doing exactly what you're going forests making it look like it's this guy. You basically tricking TrueCrypt sneaking around as part if you don't shoot yourself in the foot later on -- you're."

" Her very much welcome -- to me. Okay so after that you get to the next screen which is basically just I'm telling you to do a test run. So you choose to do a test run you press okay and restart your computer. And once it gets to the restart screen you're gonna see cop not comment TrueCrypt. -- up on your screen and it's gonna ask you for the password that you just created -- gonna type that in. Okay so it boots up back into the screen back in -- windows. And then once it gets back to. Your long and you log in just like you that usually do it with your usual password and everything and then. TrueCrypt automatically pops back up. And it says here you test -- is completely done. And then you can say okay you can encrypt now seat she's encrypt and then it takes -- two hours to encrypt your address. It and it Yasser netbook obviously the atom processor. And that the fastest in the not. -- took a long time to encrypt to be added to use area."

" It's heading and a hard drive speed. Spindle speed as well as process be used night the actor doing it. Along -- along or drive."

" Right and once it's completely -- says encryption is."

" And you -- ago so what are some of the happy dots. Running full disk encryption."

" One thing about this being a whole full encryption thing is that. You might notice. A one to 2%. Full system performance hit it if you're like -- into my -- down but if you're on land in -- modern models of PCs and that's. Probably not gonna notice the difference."

" Okay. And now where we go we do. So if you guys want to find out more information about this you can edit TrueCrypt dot org and don't mind your own copy. Check it out it's great great program. And I NASA has shown its -- C dot com. It nature. Of pictures shared it makes and."

" I all the guys have their failing. I want to let you guys know about. The contest that is still going on this is based on the previous episodes 519 where we built a white box CSX our server 14000 dollars and we thought. Yeah or would you guys do with two grand building beautiful little white box and we've seen some awesome. Just just crazy ideas come from you guys which. You know you build mini ITX rays and and and ESX boxes that like target the -- in the good stuff anyway. So if you are what is system builders are totally think some hardware level want to get in on this is episode 519 released it hacked by dot -- has formed. It that is where you can post. Your 2000 dollars specs and white roses components and we're watching those -- and we're like. -- stuff going on so anyway entry there because you will be eligible to win it. Cool Hak5 swagger from the -- shop including. The very last Hak5 shooter is awesome that's so. With all that's that I want to thank our sponsor godaddy."

" Keep your personal information away from spammers hackers in your crazy ex roommate private domain registration from godaddy.com protects your privacy by keeping your address phone number and more out of the public database. Check out revision3.com. Slash godaddy for all of our godaddy codes in offers."

" I will be back in just a bit with a little bit of plausible deny abilities answer."

" I want to let everybody knows that. Dean Klein is an -- service they are the largest online video rentals service and offer choice of over 6000 new and classic titles across all councils and elves which plants are you 15951. Game by members can rent 124 games at a time and keep them for as long. As they like you can also purchase a game if you fall in love with it sent to the box and the manual. Pornography. And on over to gain slide dot com slash Hak5 to get. Two week free trial membership in line dot com slash act."

" This my friends it's a situation you never want to be. What the password. File will never tell. It's loaded so. You really wanna -- No one -- heart bypass or go for it but. You can now -- picture of myself -- the encrypted mature. He's atlas. But now it's not mean that it is the coolest. Most amazing feature this and if -- this. Ripped right open source goodness with possible the ability. That means that means that get the folder full. You know financial stuff here. -- yeah and another folder full financial. And I probably within a volume and you don't there's -- all integrated out. Really cool -- goodness. Basically. Plausible -- ability that I can. I said it's something with something to worth 2.0. One up. Passwords. Opens what made it look like you know the air. Yours and and then the other one -- The actual C it and you never told the -- volume exists within the -- volume and that is. You as a tomorrow or something on -- it happens right. But it's -- particular data and I want to make sure that secure. -- you access it went out then. Noticed that. Tech is that who TrueCrypt it's like we would in it it is needed you to Korea you know."

" Entire are ideally are accurate encryption and we're gonna creative blame here. And I'm gonna create an encrypted file container and I'm gonna create a hidden volume right. And we're gonna do normal -- we're gonna create both the both the regular. Encrypted volume and the hidden one inside of it sending connects right hand. We are going to select we're gonna create your file and -- from Texas country as an old school and we're gonna call it it and volume. The -- created not TC TrueCrypt threat. And we're gonna -- next and just like we would. We're going to -- out -- a yes that's cool and we're gonna make it a hundred megabits. File here right. And we're gonna give it a password that's pretty lame. Okay I'm actually gonna make this a little bit cooler and check this box is that you keep files check this -- to use keep files right and I and at a -- here. And back contempt three I actually have keep files here -- preview it. -- union and assailant tire right that's a picture of up all our associate producer getting his head shaved like wow so. Anyway we're gonna use that -- a key -- what that means is that whenever we want to un encrypt. This partition. This volume if you will -- actually going to need that -- present which is cool because it's two factor authentication it's not just something I know what. Like a password something I happen. And its outlook on the USB drive that seat deposit box and then. Really cool stuff with you mini Coopers and explosions so let's good format this fatten its August. All right so now it's time to create. It's an outer pulling content so we're going to open the -- point so this procurement drive is encrypted well and it just created hundred megabyte big. And -- this file here -- dot JPEG picture of -- the monkey and it throw that in there great food and content in there this is to say that you had a gun pointed -- that wasn't just the Wii zapper. And I did -- password you see that there's actually some embarrassing documents Orson. Finance data what do you to scribble stuff there that you would potentially wonder what I also -- my totally right. Just like your birth certificates so what we're gonna do next is go next in this. Which are here and we are finally going to create it it volume within. So we're gonna give UA ES just like the other one we could do something crazy like certainty they say yes but you know it's get right and here's a bad. Determined that the maximal maximum possible hidden volume size is nine 91 megabytes right. Because it 1500 -- container have -- island sighted -- volunteers have been very important to understand. If we need this this. This hidden. -- inside 900. Or 9191. Megs. And then later on added something else to this outer volume it would over right our existing -- in bowling with. So you know it's just a little JPEG when I actually really really -- and make this like. -- Right so that go ahead make edits you make it we're gonna give his super secret password. And we're going to use its key file again and that file which just happens to be. You look pretty -- like. And we're gonna hit okay and it next. And again format that and boom there -- goes a little warning about hey don't operate this stuff than that right. So here we go we've gone ahead and created a outer volume that is the current and then it hidden volume with and that the only two megs that's super secret okay. So all you have to do you actually load this up and -- get tours are super secret cool stuff here is select the file. And remember we -- that -- three and we quality didn't believe it easy. And we're gonna go and mount that on C drive. And here's a cool thing right we can put either pass where it right now -- now that picture out there monkey is in. The original volume on the outer at the super secret one that we really want to do stuff. In the hidden ones let's go ahead and -- were okay and let's. You keep -- choose to keep violent remember this is a USB drive that we let inside of -- drywall. The first house we ever lived in. Sub basement. Something like that. And okay. And now is double click on the he's right here I have. Mine volume that can go ahead and put my super secret data and now -- It's police super secure and nobody would be messing with my picture view on a roller coaster at Busch Gardens Williamsburg dollars. It happens right."

" Excellent. I really wish this room. In an -- universe. In which. Gamers are pro and lead over its. Well I mean don't. Mean that the thing about it is you know people are counties that we don't keep paper records right now it is digital right so you know it. Obviously you're gonna have a store where your first ticket -- security -- her. Licenses passports and stuff like that that's all well and good but. Bank information in you know. Credit card information you know account information for your home equity whatever we're all stuff you know -- can keep them. Audio video diaries some and so on and region company either the seat of my docs or some -- created under you know want to -- and it indicates the point where. But that's."

" It's the act you know sells better than putting important windows system 32 access oh the killer not well I just -- And you know about this -- it read and just think that I have read on the Internet that's what's. From what I understand this report. That this could. And we would love to hear what you guys think of you know what no -- but they totally if your trip or on the Forbes. That -- happen. Anyway you can imagine it -- play you one uses. -- (%expletive) is freaked out by its fighters I think we should wrap this -- yet yet it's just part. Well it's got you know that. The encourage your feedback feedback org we can get in touch with us we'd like to hear what you think about yet especially. Program formats and we can stuff and --"

" Anything else. I have gotten everybody's. But we did have the yes sex white box. That we -- next week. And indeed ridiculous and email and reading every single one even if I'm not refined everything once trust me. I will get you eventually. Please don't blame you right you know there. He knows it and you read all of the things that we don't reply to our ports and even swapped -- looks."

" Every point it could --"

" Our guys for all of us here at Hak5 are replying to you. That's technolust."

" It's."

" Show's awesome -- do I heard you're thinking I was like yes."

" That's -- facts."

" That's the patent and I got on the -- balls that drive you. I guess so here we are eat meat of being killed. Talking you guys."

" I -- percent to hook up your."

" Old. But."

" And the cookie."

" I'm sick audit."

" You hear my thought digested that -- it kid I gobbled -- a look what. --"

" I'm good."

" War."

" This time on the show TrueCrypt inside and out I protect my netbook from Condit with full disk encryption and Darren just off hidden volumes in key files all that -- This episode of tax."

" This episode of Hak5 has brought to you by godaddy Squarespace. Game -- and viewers like you."

" Anybody want this week's episode of Hak5 I met last I'm Shannon Morse and there is doing with area's best witty geek. It's our episode today. And every time we got about drive encryption now what does drive encryption well you've all had nightmares about your laptop up in disappearing in the middle of the night yeah your car something like that. To that point where be bad if you were in high profile position like say Paul war. You know so it works for companies that use reason and I think you'll. A bank. That it's protected and does so real quick. Give you an example here. Ernst and young. Lost data. I'm not a pistol from. That's it it was a stolen right out of a car and there because I your security. Right out of the backseat. And you know it contains Social Security numbers your address your name your data or this is all of the key ingredients that. Identity thieves need to destroy your life and I thought they need it out and make your life a living hell that will take. Way more money -- you could possibly ever have tried next. So real quick let's give you an example of how easy it is to actually bypass the quote unquote security. All of -- windows machine which is deployed in you know. Is it eight."

" And -- it is it's super super easy I'm gonna show it off on parents laptop I'm using this thing called Condit which -- two episodes prior. So I just have to press and turn at the at boot screens. Once it gets to the crypt those logic menu just press and turn. And we got some cute little last year I just press enter again. -- So all I've done so far as present and -- just a couple of things and then once it gets to be windows login screen which looks. Completely normal all have to do is position you know I don't I don't know the password I'll just say daring us. A --"

" I -- this machine."

" Whatever you just height. That -- it -- after that I'm no expert I didn't get machines. Politics is qualities. That that you might ask you a little ice so file that's all you need. It --"

" And it. So so we've got the machine and this could have all been prevented if we would've installed encryption on on the -- it. But. We didn't so now -- light it's been destroyed. Hampshire he's got -- But he says that data on. The credit cards. Basically this. -- I can basically you know. Credit cards and you know information on there Korea on credit cards. It just does let you guys know. Were actually protect against this. -- in the corporate environment and to me yourself but first. We want to talk to you a buy out Hak5 meet up which stoked about this I actually it and it specific. There an Apple as well anyway there."

" Patrick that I -- to pursue it because we are having our very first ever Hak5 meet up and we're celebrating our our four years of podcasting at the upcoming sixth season. And we hope these guys can make it out August 15 app Busch Gardens Williamsburg. It's open to all ages we're gonna have. What beer and hacking and roller coasters and more beer it's all the details or over Hak5 meet up dot Squarespace dot com we really hope you guys come down a week with final information. -- in the tickets for Busch Gardens it's it's about sixty bucks. And and and the components afterwards which won't have any sort entrance he'd just -- so -- be -- to. And and we hope you guys come down got all the details hotels all the ones of these it. Planned trip I mean -- two months out so want to let you know or advanced that we you get the best ever Hak5 yep the first ever -- idea in. Williamsburg Virginia it's going to be -- we really hope you come out August 15. Okay well with all that said and hopefully Mac you mean while back now. -- note that in a moment Shannon's going to be showing you all sorts of cool ways that you can encrypt your hard drive and keep it -- from. Well Paul really and and until then I want to thank our wonderful sponsor. Squarespace. "

" This is one of the many reasons why Squarespace is the fastest and easiest way to those beautiful powerful website. Right now matting -- speech he formed to hack I'd need to Squarespace dot com I love the fact that there's actually no could required. Its two week free trial of Squarespace dot com to see why we're so crazy about them and be sure he's promo code Hak5 to save 10% off the life your service and support the show. And don't forget there's just a few days remaining Squarespace iPhone giveaway to be sure to use -- Squarespace you tweaks to be entered into the daily drawings until July 8. I know exactly just knowledge."

" Our guess here we are we're gonna actually show you how to protect -- data unfortunately it to Hillary's use I can't use it. Corporate environment. There's no centralized management console there's no work of free you know single recovery system that we can actually use for or personnel. But on corporate environment you do have options there are solutions from McAfee. Encryption plots are just unfortunate things from period edge and then there's also one from -- say which. You know they they use some windows experts thinking -- you want to stuff like that. Centralized recovery council's so makes -- sysadmins like almighty yet active work right things but what we're talking about today. Is."

" Open source. It's TrueCrypt. TrueCrypt is completely free it's open sourced anybody that needs to -- is incredibly fast down land which isn't really. You can do everything from encrypting your entire hard drive to get certain pieces of data. Pretty much anything that you want to you but today I'm going to be showing you guys how to encrypt your entire hard drive. Sweet. -- right which. So there's a couple of choices on the front first screen you can do encrypt system partition or drive where you can just gonna create volume highlight just -- volume that's one. That's wonderful. And I'm encrypting the system partition and or the entire system drive or -- the -- drive that just when the system partition right. And it's gonna say hey if this Chris tuition is not acceptable you can go back and she used to encrypt Lee's system partitions that. Blah -- you just press okay with that host protected area. Certain netbooks have a host protected area in the use this -- store everything from tools to date after -- All sorts of different things. Base and its its like your recovery partition things Apple's of the so ultimately these years use wrote your royally. So from what I've heard online. From the different tutorials that I've read about this is you shining encrypt your -- protected areas just to be on the safe side salt she's now on that. Single -- bit multi bit that's obvious. I'm a single player. Next line is encryption options this is on your standard encryption options ES serve and when great. It's so I'll just stick with a yes. And then you choose your password. This is pretty cool because if you choose a password that's under twenty characters it's gonna come up and say hey it's a lot easier to break a twenty character password than it is something over twenty characters. And I'll keep on saying that until you get something that's over twenty. So up in. Let's see. -- and -- Arafat to do capitalize -- and and numbers. This is kind of interesting and weird all at the same time so it says you're supposed to move your mouse around for a long time just to get a very very randomized amount of keys. And it's very magical. In my opinion. Basic -- is taking your cursor position in translating that he news that Jerry. -- and it's. It's Simon and around for like a minute and -- next. And you see I have my had a key in mind streaky. As Mexican. Now this part that can't screw me up when I was doing this on mine but. The -- my -- that is it doesn't have a CD-ROM drive. With encryption on -- old disk drive. It's going to tell you that you have to make a rescue disk. BS CB. You hacked. So I'm gonna go to browse and I'm just gonna create this thing called rescue disks -- now that. Gonna save that. And then press next. And then it says it's being created has been stored so that's as snacks again see it's gonna tell me you how to burn a -- yet you can't go line yet. You have to treat this rescued this just in case so basically the actual applications looking out for you yes it is it's protecting -- just in case yeah you need to rescue -- that so how we get by this -- netbook which obviously. Room. This is what I do I found this really cool program called -- CDE and you emulator you basically just install it. You you running and then you create CD emulation on your computers you can turn little clusters. And SD cards. And make those work as if they are CD's -- your eyes on there and you can skip this part in Italy you go ahead to get."

" Basically use something like daemon tools -- power i.s so just -- the eyes so have a scan it and say if we wanted to live dangerously that is. Just basically any -- it any ice -- utility."

" Makes it look like CD-ROM drive yes exactly exactly that's what it's doing exactly what you're going forests making it look like it's this guy. You basically tricking TrueCrypt sneaking around as part if you don't shoot yourself in the foot later on -- you're."

" Her very much welcome -- to me. Okay so after that you get to the next screen which is basically just I'm telling you to do a test run. So you choose to do a test run you press okay and restart your computer. And once it gets to the restart screen you're gonna see cop not comment TrueCrypt. -- up on your screen and it's gonna ask you for the password that you just created -- gonna type that in. Okay so it boots up back into the screen back in -- windows. And then once it gets back to. Your long and you log in just like you that usually do it with your usual password and everything and then. TrueCrypt automatically pops back up. And it says here you test -- is completely done. And then you can say okay you can encrypt now seat she's encrypt and then it takes -- two hours to encrypt your address. It and it Yasser netbook obviously the atom processor. And that the fastest in the not. -- took a long time to encrypt to be added to use area."

" It's heading and a hard drive speed. Spindle speed as well as process be used night the actor doing it. Along -- along or drive."

" Right and once it's completely -- says encryption is."

" And you -- ago so what are some of the happy dots. Running full disk encryption."

" One thing about this being a whole full encryption thing is that. You might notice. A one to 2%. Full system performance hit it if you're like -- into my -- down but if you're on land in -- modern models of PCs and that's. Probably not gonna notice the difference."

" Okay. And now where we go we do. So if you guys want to find out more information about this you can edit TrueCrypt dot org and don't mind your own copy. Check it out it's great great program. And I NASA has shown its -- C dot com. It nature. Of pictures shared it makes and."

" I all the guys have their failing. I want to let you guys know about. The contest that is still going on this is based on the previous episodes 519 where we built a white box CSX our server 14000 dollars and we thought. Yeah or would you guys do with two grand building beautiful little white box and we've seen some awesome. Just just crazy ideas come from you guys which. You know you build mini ITX rays and and and ESX boxes that like target the -- in the good stuff anyway. So if you are what is system builders are totally think some hardware level want to get in on this is episode 519 released it hacked by dot -- has formed. It that is where you can post. Your 2000 dollars specs and white roses components and we're watching those -- and we're like. -- stuff going on so anyway entry there because you will be eligible to win it. Cool Hak5 swagger from the -- shop including. The very last Hak5 shooter is awesome that's so. With all that's that I want to thank our sponsor godaddy."

" Keep your personal information away from spammers hackers in your crazy ex roommate private domain registration from godaddy.com protects your privacy by keeping your address phone number and more out of the public database. Check out revision3.com. Slash godaddy for all of our godaddy codes in offers."

" I will be back in just a bit with a little bit of plausible deny abilities answer."

" I want to let everybody knows that. Dean Klein is an -- service they are the largest online video rentals service and offer choice of over 6000 new and classic titles across all councils and elves which plants are you 15951. Game by members can rent 124 games at a time and keep them for as long. As they like you can also purchase a game if you fall in love with it sent to the box and the manual. Pornography. And on over to gain slide dot com slash Hak5 to get. Two week free trial membership in line dot com slash act."

" This my friends it's a situation you never want to be. What the password. File will never tell. It's loaded so. You really wanna -- No one -- heart bypass or go for it but. You can now -- picture of myself -- the encrypted mature. He's atlas. But now it's not mean that it is the coolest. Most amazing feature this and if -- this. Ripped right open source goodness with possible the ability. That means that means that get the folder full. You know financial stuff here. -- yeah and another folder full financial. And I probably within a volume and you don't there's -- all integrated out. Really cool -- goodness. Basically. Plausible -- ability that I can. I said it's something with something to worth 2.0. One up. Passwords. Opens what made it look like you know the air. Yours and and then the other one -- The actual C it and you never told the -- volume exists within the -- volume and that is. You as a tomorrow or something on -- it happens right. But it's -- particular data and I want to make sure that secure. -- you access it went out then. Noticed that. Tech is that who TrueCrypt it's like we would in it it is needed you to Korea you know."

" Entire are ideally are accurate encryption and we're gonna creative blame here. And I'm gonna create an encrypted file container and I'm gonna create a hidden volume right. And we're gonna do normal -- we're gonna create both the both the regular. Encrypted volume and the hidden one inside of it sending connects right hand. We are going to select we're gonna create your file and -- from Texas country as an old school and we're gonna call it it and volume. The -- created not TC TrueCrypt threat. And we're gonna -- next and just like we would. We're going to -- out -- a yes that's cool and we're gonna make it a hundred megabits. File here right. And we're gonna give it a password that's pretty lame. Okay I'm actually gonna make this a little bit cooler and check this box is that you keep files check this -- to use keep files right and I and at a -- here. And back contempt three I actually have keep files here -- preview it. -- union and assailant tire right that's a picture of up all our associate producer getting his head shaved like wow so. Anyway we're gonna use that -- a key -- what that means is that whenever we want to un encrypt. This partition. This volume if you will -- actually going to need that -- present which is cool because it's two factor authentication it's not just something I know what. Like a password something I happen. And its outlook on the USB drive that seat deposit box and then. Really cool stuff with you mini Coopers and explosions so let's good format this fatten its August. All right so now it's time to create. It's an outer pulling content so we're going to open the -- point so this procurement drive is encrypted well and it just created hundred megabyte big. And -- this file here -- dot JPEG picture of -- the monkey and it throw that in there great food and content in there this is to say that you had a gun pointed -- that wasn't just the Wii zapper. And I did -- password you see that there's actually some embarrassing documents Orson. Finance data what do you to scribble stuff there that you would potentially wonder what I also -- my totally right. Just like your birth certificates so what we're gonna do next is go next in this. Which are here and we are finally going to create it it volume within. So we're gonna give UA ES just like the other one we could do something crazy like certainty they say yes but you know it's get right and here's a bad. Determined that the maximal maximum possible hidden volume size is nine 91 megabytes right. Because it 1500 -- container have -- island sighted -- volunteers have been very important to understand. If we need this this. This hidden. -- inside 900. Or 9191. Megs. And then later on added something else to this outer volume it would over right our existing -- in bowling with. So you know it's just a little JPEG when I actually really really -- and make this like. -- Right so that go ahead make edits you make it we're gonna give his super secret password. And we're going to use its key file again and that file which just happens to be. You look pretty -- like. And we're gonna hit okay and it next. And again format that and boom there -- goes a little warning about hey don't operate this stuff than that right. So here we go we've gone ahead and created a outer volume that is the current and then it hidden volume with and that the only two megs that's super secret okay. So all you have to do you actually load this up and -- get tours are super secret cool stuff here is select the file. And remember we -- that -- three and we quality didn't believe it easy. And we're gonna go and mount that on C drive. And here's a cool thing right we can put either pass where it right now -- now that picture out there monkey is in. The original volume on the outer at the super secret one that we really want to do stuff. In the hidden ones let's go ahead and -- were okay and let's. You keep -- choose to keep violent remember this is a USB drive that we let inside of -- drywall. The first house we ever lived in. Sub basement. Something like that. And okay. And now is double click on the he's right here I have. Mine volume that can go ahead and put my super secret data and now -- It's police super secure and nobody would be messing with my picture view on a roller coaster at Busch Gardens Williamsburg dollars. It happens right."

" Excellent. I really wish this room. In an -- universe. In which. Gamers are pro and lead over its. Well I mean don't. Mean that the thing about it is you know people are counties that we don't keep paper records right now it is digital right so you know it. Obviously you're gonna have a store where your first ticket -- security -- her. Licenses passports and stuff like that that's all well and good but. Bank information in you know. Credit card information you know account information for your home equity whatever we're all stuff you know -- can keep them. Audio video diaries some and so on and region company either the seat of my docs or some -- created under you know want to -- and it indicates the point where. But that's."

" It's the act you know sells better than putting important windows system 32 access oh the killer not well I just -- And you know about this -- it read and just think that I have read on the Internet that's what's. From what I understand this report. That this could. And we would love to hear what you guys think of you know what no -- but they totally if your trip or on the Forbes. That -- happen. Anyway you can imagine it -- play you one uses. -- (%expletive) is freaked out by its fighters I think we should wrap this -- yet yet it's just part. Well it's got you know that. The encourage your feedback feedback org we can get in touch with us we'd like to hear what you think about yet especially. Program formats and we can stuff and --"

" Anything else. I have gotten everybody's. But we did have the yes sex white box. That we -- next week. And indeed ridiculous and email and reading every single one even if I'm not refined everything once trust me. I will get you eventually. Please don't blame you right you know there. He knows it and you read all of the things that we don't reply to our ports and even swapped -- looks."

" Every point it could --"

" Our guys for all of us here at Hak5 are replying to you. That's technolust."

" It's."

" Show's awesome -- do I heard you're thinking I was like yes."

" That's -- facts."

" That's the patent and I got on the -- balls that drive you. I guess so here we are eat meat of being killed. Talking you guys."

" I -- percent to hook up your."

" Old. But."

" And the cookie."

" I'm sick audit."

" You hear my thought digested that -- it kid I gobbled -- a look what. --"

" I'm good."

Please visit the sponsors of this episode. Interested in more Revision3 special offers?

Go Daddy

Transfer your domain to Go Daddy for as little as $6.99 and get a free 1-year extension plus guaranteed renewal pricing! GoDaddy.com makes transferring easy and offers loads of extras including: hosting, a 5-page site builder, complete email, total DNS control and more! What are you waiting for?

Enter the code Hak3 when you checkout to get any .COM domain name for $7.49

Squarespace

Squarespace is an extremely easy to use, fully hosted, completely managed environment for creating and maintaining a website, blog or portfolio. Its intuitive format and features let you be as simple or as sophisticated as you want in the way that you organize your content, no matter what it is your website calls for. Either way, you'll end up with a website that looks like you paid thousands of dollars to design it for you. For plans starting at $8 dollars a month, Squarespace is a deal you can't beat.

Check out using the code Hak5 to get 10% off the lifetime of your order.

Gamefly

Gamefly is the largest online video game rental service and offers you a choice from over 6,000 new and classic titles across all consoles and handhelds. With plans starting at $15.95/month, Gamefly members can rent 1 to 4 games at a time and keep them for as long as they'd like. There are no late fees, no due dates, and shipping is always free. Once you're done playing a game, send it back, and Gamefly will send you the next available game on your list. If you really like the game you're playing simply click 'Keep It' on the Gamefly website and the game is yours at a discounted price. Gamefly will even mail you the case and manuals free of charge.

As a Hak5 fan you can get a 2 week free trial at www.gamefly.com/hak5
mari1ee

Started discussion: July 1, 2009 @ 9:44am GMT

Episode 520: Encrypt your entire hard drive! [Discussion]

What's your best defense against a boot CD that breaks Windows passwords in two keystrokes? Encrypting your entire hard disk. Shannon's got the details on truecrypt drive encryption while Darren brings up plausible deniability with hidden volumes.

Watch or download the episode now!

AbsoluteMayheM
5 months ago
Great ep! I dont use drive encryption, but i just might start!

Its also a good idea for USB keys as well.

Speaking of security I do use an application called KeePass Password Safe and I have been using if for a very long time.

I have all my banking info in it, I have all my work administrative passwords and even stuff like my WoW accounts info and serial number info.

-MayheM
MasterQ
5 months ago
I love that you guys were drinking yuengling... i live close to the brewery where it is made (oldest brewery in the US)... tasty stuff. it's good to see u representing the east coast :)
speed
5 months ago
I posted this on the Hak5 forums as well, but I figure I may as well get, err.... corrected by two groups of users:

I see a couple of problems with the whole "plausible deniability" thing with TrueCrypt. First of all, you'd have to give even the fake folder a decent password (not some lame one as Darren did on the show) in order for it to be believable (right, the password to all your financial documents is "hunter2", sure....); second, in order for you to have a believable fake hidden file, the information has to look like you'd want to protect it (fake banking information or confidential documents), but more often than not, you'd have to include a date somewhere ("July 2, 2009: $300 ABM withdraw at 2:48am" or "January 15, 2000: subject appears restless") and if someone sees this and sees that the information is old, they might get suspicious. However, you can't update the fake files since TrueCrypt warns this can damage the inner volume. Third, at this point, if someone sees that you have an encrypted file on your computer, wants the information that badly and sees that you have TrueCrypt on your HDD, won't they just assume you have a hidden volume and any claims otherwise are fraudulent? I know if I was going to (hypothetically, of course) torture someone for the password to a TrueCrypt volume, I'd keep torturing them for a password until the volume type was listed as "Hidden".

And I'm now prepared for the barrage of replies telling me why I'm way off base on every single point.
MasterQ
5 months ago
In reply to speed:
I posted this on the Hak5 forums as well, but I figure I may as well get, err.... corrected by two groups of users:

I see a couple of problems with the whole "plausible deniability" thing with TrueCrypt. First of all, you'd have to give even the fake folder a decent password (not some lame one as Darren did on the show) in order for it to be believable (right, the password to all your financial documents is "hunter2", sure....); second, in order for you to have a believable fake hidden file, the information has to look like you'd want to protect it (fake banking information or confidential documents), but more often than not, you'd have to include a date somewhere ("July 2, 2009: $300 ABM withdraw at 2:48am" or "January 15, 2000: subject appears restless") and if someone sees this and sees that the information is old, they might get suspicious. However, you can't update the fake files since TrueCrypt warns this can damage the inner volume. Third, at this point, if someone sees that you have an encrypted file on your computer, wants the information that badly and sees that you have TrueCrypt on your HDD, won't they just assume you have a hidden volume and any claims otherwise are fraudulent? I know if I was going to (hypothetically, of course) torture someone for the password to a TrueCrypt volume, I'd keep torturing them for a password until the volume type was listed as "Hidden".

And I'm now prepared for the barrage of replies telling me why I'm way off base on every single point.


The trick is that it's called _plausible_ deniability, meaning they can't prove that there is another volume in there. There is no way for them to distinguish a hidden volume from the random data truecrypt puts in the empty part of the file.

Even truecrypt itself can't tell if there is a hidden volume present. It simply tries to decrypt the file with every algorithm with the password you give it until it gets one that works. If it can't, it tells you either the password isn't correct or the file is not a truecrypt volume.

Your files can be old and the person trying to get in can be as suspicious as they want. Without the password you won't be able to find the hidden volume. Also, there's no security measure you can take that will protect against a person giving someone the key, so theres nothing that will protect against the torturing scenario you mentioned.
speed
5 months ago
In reply to MasterQ:
The trick is that it's called _plausible_ deniability, meaning they can't prove that there is another volume in there. There is no way for them to distinguish a hidden volume from the random data truecrypt puts in the empty part of the file.

Even truecrypt itself can't tell if there is a hidden volume present. It simply tries to decrypt the file with every algorithm with the password you give it until it gets one that works. If it can't, it tells you either the password isn't correct or the file is not a truecrypt volume.

Your files can be old and the person trying to get in can be as suspicious as they want. Without the password you won't be able to find the hidden volume. Also, there's no security measure you can take that will protect against a person giving someone the key, so theres nothing that will protect against the torturing scenario you mentioned.


That's my point though. Can they prove that there's a hidden volume? No. However, if they know even a little bit about TrueCrypt, they aren't likely to believe that the first password you give is legit unless TrueCrypt says the decrypted volume is a hidden one. The whole point of plausible deniability is that if you are forced to relinquish the password, you give them the password for the outer volume. However, that benefit is gone if the person has heard of TrueCrypt.
computoman
5 months ago
It is amazing what you can do by just hiding things in plain sight. You just have to be inventive the way you store files encrypted.
bobo99
5 months ago
hey, guys, cool episode, but i think that some viewers would find it cool to talk about the strength of the various encryptions and hashes and how long it would take to crack (with various cracking techniques) them!
MasterQ
5 months ago
In reply to computoman:
It is amazing what you can do by just hiding things in plain sight. You just have to be inventive the way you store files encrypted.


Truecrypt is not hiding things in plain sight. Hiding things in plain sight would be like renaming a file to have a jpeg extension and putting it in your pictures folder.

In reply to bobo99:
hey, guys, cool episode, but i think that some viewers would find it cool to talk about the strength of the various encryptions and hashes and how long it would take to crack (with various cracking techniques) them!


The US government uses AES for top secret file encryption because it takes a VERY long time to crack if it has a good key (which truecrypt will warn you about if yours is too short). Encrypting using two or all three of the algorithms makes it virtually impossible to crack any time soon (like in this lifetime)
computoman
5 months ago
I never said that truecrypt was hiding things in plain sight. Renaming a file is an oversimplified way to hide a file in plain sight. There are also more sophisticated yet very simple ways to hide things in plain sight other than just embedding an encrypted file in to a picture or the like.
I see no sense in encrypting a whole drive when usually the size of the sensitive data is only a fraction of that. During WWII, American Indian dialects were used to transmit messages. No encryption was necessary per say, except for using non traditional keywords. Security by obscurity.
View all 10 comments