Welcome Guest ( Log In | Register )



 
Reply to this topicStart new topic
> Hiding Your Personal Files From Pros, More serious approach to privacy
xerxes
post May 21 2007, 11:05 AM
Post #1


Member [ Level 2 ]
Group Icon

Group: [HOSTED]
Posts: 71
Joined: 8-May 07
From: Poland
Member No.: 21,854
myCENTs:97.91



Inspired by this thread, I decided to launch this one to see how you folks approach the issue of securing your private files at work or at places where computer-professionals can access the machine you use. Following is my response to ethergeek's post in the aforementioned topic:


QUOTE(ethergeek @ May 14 2007, 06:46 PM) *
The best way to hide your private files is to not keep them on machines that aren't yours.

I agree with that completely. Such machine could always be taken away from you without prior notice, with the files you care about in it. Besides, if the machine isn't yours you can't really control and evaluate the security mechanisms employed in such system.


QUOTE(ethergeek @ May 14 2007, 06:46 PM) *
install TrueCrypt or FreeOTFE

The problem with such kind of mechanism is that if you will loose control over the operating system, you can't gain access to your encrypted files anymore. Besides anybody who gains access to your account, can access the encrypted files as well. Moreover, there are already known viruses that can access OS's kernel to stop A-V and firewall software. I don't think we have to wait long till such malicious programs take over kernel drivers to read your encrypted files, which are important by definition. ethergeek - could you tell us a bit more about you installation of TrueCrypt? Do you need a password, or a certificate to initiate the process? What happens if you need to reinstall the system (without any break-downs)?


QUOTE(ethergeek @ May 14 2007, 06:46 PM) *
keep your private files on a USB key in your pocket.

That seems to work well (especially that there are Linux distributions designed to fit on such keys, and with such you can encrypt the contents of the key as well), unless you are in an environment, where security is a concern and USB ports are disabled.
Go to the top of the page
 
+Quote Post
ethergeek
post May 21 2007, 05:17 PM
Post #2


Premium Member
Group Icon

Group: [HOSTED]
Posts: 393
Joined: 9-March 07
From: Tucson, AZ
Member No.: 20,794



If you were gonna quote my post and then comment on it in a new thread, ya should have sent me a PM; I'd have responded sooner biggrin.gif

QUOTE
ethergeek - could you tell us a bit more about you installation of TrueCrypt? Do you need a password, or a certificate to initiate the process? What happens if you need to reinstall the system (without any break-downs)?


TrueCrypt and FreeOTFE can use passwords, keyfiles, and any combination thereof. There is nothing that links it to your windows account (if there is I sure as hell don't use it). Both applications are compatible in some way with Linux also; the FreeOTFE can create and work with linux dmcypt and cryptoloop volumes, and TrueCrypt has a linux version that will mount volumes directly. FreeOTFE also has a version for PocketPC.

I secure mine with a hard passphrase for the most part, though one of them additionally requires a keyfile on a USB key I keep in my safe at home.
Go to the top of the page
 
+Quote Post
Alegis
post May 25 2007, 11:55 AM
Post #3


Premium Member
Group Icon

Group: Members
Posts: 300
Joined: 25-May 06
Member No.: 13,654



QUOTE(xerxes @ May 21 2007, 11:05 AM) *
The problem with such kind of mechanism is that if you will loose control over the operating system, you can't gain access to your encrypted files anymore.

That's the whole point of security. Someone who can't get in your OS can't access them - otherwise someone would be able to leech the files off your HD by using something like EnCase. It's only evident that if you invest in security you lose some ease of use.

You guys are paranoid!
Go to the top of the page
 
+Quote Post
wutske
post May 27 2007, 11:42 AM
Post #4


Way Out Of Control - You need a life :)
Group Icon

Group: [HOSTED]
Posts: 1,077
Joined: 2-August 05
From: Kapellen (Antwerp, Belgium)
Member No.: 7,585



I have the data on my laptop encrypted using TrueCrypt and a few keys on a USB stick. It's not realy 100% secure because the 'drives' are only unmounted when I reboot and if you have the USB stick and you know you need it you can easily access the my data. Still, it's better than nothing cool.gif
Go to the top of the page
 
+Quote Post
Grafitti
post May 27 2007, 07:07 PM
Post #5


Premium Idiot
Group Icon

Group: [HOSTED]
Posts: 661
Joined: 9-July 05
From: Switzerland, but currently in Pakistan
Member No.: 6,943



I like PGP's Full Disk Encryption. That's about as safe as civilian encryption gets, as far as I know.
Go to the top of the page
 
+Quote Post
xerxes
post Today, 12:50 AM
Post #6


Member [ Level 2 ]
Group Icon

Group: [HOSTED]
Posts: 71
Joined: 8-May 07
From: Poland
Member No.: 21,854
myCENTs:97.91



QUOTE(Alegis @ May 25 2007, 12:55 PM) *
That's the whole point of security. Someone who can't get in your OS can't access them - otherwise someone would be able to leech the files off your HD by using something like EnCase.
I disagree. I don't understand why encryption software cannot be efficient and user-friendly at the same time. I would choose a software which:
a) enables you to access the files transparently (of course after providing ID of some sort, whether it's a password or a digital certificate)
cool.gif does not have to be installed with admin privileges
c) grants you the possibility of moving the encrypted files to a different computer and decrypting them over there

QUOTE(Alegis @ May 25 2007, 12:55 PM) *
You guys are paranoid!
That's not paranoia. I'm sure most of us keep private stuff at our work, even though we are not suppose to. IT guys usually have full access to our computers, with root accounts obviously, so that's nothing strange that we want to cover our tracks.

QUOTE(Grafitti @ May 27 2007, 08:07 PM) *
I like PGP's Full Disk Encryption. That's about as safe as civilian encryption gets, as far as I know.
Could you tell us a bit more about it? Why do you think Full Disk Encryption is better than other available solutions (as in better than creating a password-protected archive)? Remember we're talking about non-private computers so you can't really install software on your own, at least not that which hooks into the OS.
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. How To Play *.rm Files With Media Player(14)
  2. iTunes' .m4p Music-files With Bad Quality?(6)
  3. Did I Mess Up My Computer?(6)
  4. Can't View PHP Files Using XAMMP(3)
  5. Find Out A Files Original File Type(6)
  6. Problem With Xammp And Deleting Temp Files(2)
  7. HP 160GB Personal Media Drive(2)
  8. If You Have Some Private Files(17)
  9. Please Help!(4)


 



- Lo-Fi Version Time is now: 23rd November 2008 - 06:33 PM