5 ms·
Being robbed sucks but when it comes to digital possessions there's no reason it needs to suck this much. > I didn’t really trust file encryption because I tho
by sehrope 13y ago
Being robbed sucks but when it comes to digital possessions there's no reason it needs to suck this much.
> I didn’t really trust file encryption because I thought I might lose files because of it and therefore I never enabled Mac OSX’s built-in FileVault hard drive encryption. I should have though. It’d save me from worrying about who’s going through all my files now.
This is a no brainer. I have yet to notice any real performance hit for enabling full disk encryption. Just enable it, make sure to have a long/strong password, and make sure your computer actually locks when you close the lid.
You should never be worried about losing files on a single computer. If they're important then they should be backed up to multiple computers/drives/services. If you're worried about accidentally wiping your laptop when you setup FDE then just make a backup before hand.
> My backup drive was literally NEXT to my MacBook. By sheer luck, I had just backed up my internal drive the day before and they didn’t take it.
Offsite backups are a must. It can be your own "offsite" (ie. a server at friends/parents/office) but it needs to be somewhere other than the primary site.
> I didn’t have a cloud backup because I don’t trust a third party with my data.
There's nothing wrong with not trusting third parties but that's exactly what encryption is for. Encrypt your data locally and then you can store it remotely without worrying about it being accessible to a third party. DIY scripting with GPG/S3 works well for a lot of situations. Or you can just use Tarsnap[1].
Honestly it makes a lot of sense to do the same with USB drives as well. My Linux machine is my primary computer (OS X laptop when roaming...) so the majority of my backup USB drive usage is done there. I have them setup with LUKS/dm-crypt[2] for full disk encryption. It's really easy to setup, plug-n-play on modern systems, and it almost falls into the "no reason not too" category. I just wish OS X supported it too.
[1]: http://www.tarsnap.com/ http://www.tarsnap.com/
[2]: http://en.wikipedia.org/wiki/Linux_Unified_Key_Setup http://en.wikipedia.org/wiki/Linux_Unified_Key_Setup
- sliverstorm 13y agoOffsite backups are a must Depending on your threat model, they don't even have to be outside the house. If petty burglary is what you are defending against, a disk in a quiet corner of your basement is probably plenty. I bring up threat models a lot, because I'm still fascinated with the model of data security as an adversarial relationship in which you can characterize your enemy, and thus qualify "good enough".
- sehrope 13y ago> Depending on your threat model, they don't even have to be outside the house. If petty burglary is what you are defending against, a disk in a quiet corner of your basement is probably plenty. Being outside of the house protects it equally well against fires/floods/earthquakes/pets too. Protection against burglary is an added bonus.
- sliverstorm 13y agoOh yes, being somewhere other than your house has very clear upsides, but an appropriate location is not always forthcoming. For example, I would consider it pretty poor form to plug in a personal networked backup box at my desk at work. That kind of move can also pose a risk to my sustained employment!
- AnimalMuppet 13y agoI keep a USB stick in my cube. This requires manually rotating it out every so often, but it doesn't get me fired.
- sehrope 13y ago> Oh yes, being somewhere other than your house has very clear upsides, but an appropriate location is not always forthcoming. It's not too hard to find one. Unless you're completely anti-social you probably have at least one tech-savvy friend that can understand the need for this kind of setup. Even better if you have more than one friend (hopefully not too be an "if") then you can have a "round robin" approach with a group of friends. An open source (so the crypto can actually be vetted) version of BTSync[1] would be great for this. > For example, I would consider it pretty poor form to plug in a personal networked backup box at my desk at work. That kind of move can also pose a risk to my sustained employment! Haha. Yes plugging in random networked boxes at the office might arouse some (just!) concern. When I wrote that piece I was thinking specifically of my company as I'm the boss :D [1]: http://www.bittorrent.com/sync http://www.bittorrent.com/sync
- 13y ago
- Bluerise 13y agoCyphertite[1] works very will for encrypted backups. It splits your data in chunks, encrypts them on the fly while sending them to the cloud. It doesn't use much space, apart from a little metadata, and you don't have to worry about the NSA, as the encryption keys are only on your local machine. [1] https://www.cyphertite.com https://www.cyphertite.com
- cortesoft 13y agoI agree with the offsite backups, but I find it to be impractical for a lot of my data. I have over 8TB of data at my house, and getting that backed up offsite is not trivial.
- jevinskie 13y agoHow little "offsite" can one get away with? Could you put a waterproof (flooding), fireproof, buried (tornadoes) safe with a NAS (SSDs for earthquake protection?) in the barn in your yard? It would be easy to run Ethernet to that and have fully synced backups without ISP/cloud service charges. What natural disasters/events will take out both your home and the hardened safe in your barn? edit: An EMP may fit the bill. :-O
- dredmorbius 13y agoOne problem with "fireproof" is that a safe that will protect paper records against combustion (by shielding them from the most intense heat and preventing oxygen from entering) will almost certainly get hot enough to melt plastics and render magnetic storage damaged if not unreadable. One of the characteristics of fireproof safes is also their ability to withstand a multi-story drop. The reason being that when the floor burns out from under it, that's what happens. This still doesn't do much to ensure data records are retained. So long as it's a barn in the yard, reasonably directional WiFi might well suffice. As for what natural disasters could take out your house and your barn: if you live in wildfire country, that's a distinct possible risk. As a random Google Image search example: http://www.mesonet.ttu.edu/cases/PitchforkFire_050811/20110508.html http://www.mesonet.ttu.edu/cases/PitchforkFire_050811/201105... Note the plot of 20cm depth soil temperature rise (and how long the temps stay elevated): http://www.mesonet.ttu.edu/cases/PitchforkFire_050811/meteo_PITC_050911.png http://www.mesonet.ttu.edu/cases/PitchforkFire_050811/meteo_...
- blueskin_ 13y agoNot always. Fireproof safes are rated for paper, tape or drives, as well as a time limit. A safe rated for drives will guaranteed a maximum of 55 degrees (C) inside it for the rated time, enough for drives to survive without problem when powered down. See: http://www.theregister.co.uk/2013/12/02/setting_the_iosafe_214_on_fire/ http://www.theregister.co.uk/2013/12/02/setting_the_iosafe_2...
- elwell 13y agoI don't know if this post is intended to be a response or a summary of the blog post, but it's a summary.
- jevinskie 13y ago> This is a no brainer. I have yet to notice any real performance hit for enabling full disk encryption. Just enable it, make sure to have a long/strong password, and make sure your computer actually locks when you close the lid. I have confirmed, using dtrace, that OS X uses Intel's AES-NI instructions to accelerate encrypted disks. I found no performance decrease for batch file copies. I did not test small files nor seeking. I should run more benchmarks now that I have an SSD. Perhaps the CPU is now the bottleneck.
- ivionday 13y agoGod bless every engineer who has made this a reality.
- jmspring 13y agoMy sense of pity really was cut short by not encrypting things. Regardless of the mention/data that disk encryption is a minor hit, reality is, for most it would be a non issue...our day to day computing issues aren't going to stress Filevault. Just turn it on...that or keep sensitive stuff in an encrypted disk image. There is a lot in this story that sucks but a lot that is "should have known better" as well.
- seszett 13y agoA good way to keep your files secure without using encryption is running anything else than OSX or Windows, too. I have had two laptops stolen, from my home - once entering by the (closed) door, once by a (closed) window. With them being under FreeBSD and Arch Linux, I'm quite confident that my data stayed safe (I ihad scans of about all my papers in there). It's kind of security through obscurity, but I think it works pretty well, any disk that's not FAT32, NTFS or HFS+ formatted is quite secure against theft. Regarding backups, my laptops usually rsync their /home every day to my remote server (and most data on them is in git repositories anyway).
- mike-cardwell 13y agoIf you don't want to pay the TarSnap premium, just set up Duplicity directly with Amazon S3, or some other external box if you have one available: https://grepular.com/Secure_Free_Incremental_and_Instant_Backups_for_Linux https://grepular.com/Secure_Free_Incremental_and_Instant_Bac...