4 ms·
The question is, do people usually keep large areas of random data on their hard disks?
by jpablo 13y ago
The question is, do people usually keep large areas of random data on their hard disks?
- ef47d35620c1 13y agoWhen talking about normal people, the answer to that question is, "No". TCHunt was written in 2007 (7 years ago) and demonstrates that random data that is modulo 512 and larger than X bytes is very unique when looking at files that typically reside on the filesystems of end use computers. Forensic IT examiners use that to find disguised TC volumes.
- cpplinuxdude 13y agoNope. Grain on an image sequence? Yes.
- tlrobinson 13y agoIt would be nice if the default filesystem on an unsuspicious and relatively popular operating system (Linux?) normally overwrote erased data with random data, and worked to maintain a large contiguous area at one "end" of the drive. You would need to be careful not to fill up your drive to the point that it overwrote part of your hidden volume, of course. I think this would allow for true deniability.
- Zenst 13y agoYou might find this a worthhile read about such an approach to filesystems at the filesystem level https://www.usenix.org/legacy/events/sec2001/full_papers/bauer/bauer.pdf https://www.usenix.org/legacy/events/sec2001/full_papers/bau... Though shred and other tools to delete via random overright do exist, but as you imply a low level approach would be much more secure. Another consideration is the type of storage, then there are backups which will still have deleted data. Let alone SSD's which are a whole different breed and can transparantly make a block as dead and realocate some of the reserved data storage without you knowing and with that leave the existing data permently inplace for forensics. With that having an excrypted file system would certainly help cover such issues, though encryption within encryption could be the extra layer of plausable denability you require.
- U2EF1 13y agoWorse, overwriting SSD's with random data would halve their lifespan, and some SSD's don't even allow you to control where exactly you are writing to. Better to just never write unencrypted data to the drive at all.
- rlanday 13y agoDoesn’t FAT do that? Although maybe a Linux user choosing to use FAT for some other reason isn’t that plausible in itself…
- MertsA 13y agoDon't be so quick to judge, I've got a small FAT partition on my boot drive right now for the EFI system partition. That partition also doesn't frequently have data written to it, you could in theory hide a small encrypted volume in the free space and so long as Grub wasn't updated nothing would touch that free space.
- porlw 13y agoI don't think FAT even bothers to zero the data when it's allocated, so you might be able to see what was previously stored in a block by reading it straight after allocation. OTOH this might be driver dependent.
- Nacraile 13y agoOverwrite entire disk with random data. Create new filesystem. Place encrypted volume in unallocated space. "The disk was just securely wiped prior to the current OS install"
- baddox 13y agoEven the most plausible deniability fails when the information-holder is sufficiently incentivized to tell the truth, whether that is by threats of punishment, torture, etc.
- jamesaguilar 13y agoAlso, if the police have a record of you downloading CP (or whatever), find your hard drive with a huge random segment, and find TrueCrypt software on your machine, they're probably going to put two and two together.
- baddox 13y agoI think the point of plausible deniability applies to the notion that random data on your computer is circumstantial evidence that isn't particularly useful in getting a conviction.
- ams6110 13y agoCircumstantial evidence is used all the time to get convictions. It's not proof, but if there's enough of it it becomes very persuasive.
- DanBC 13y agoThey might not get a conviction for images of child sexual abuse, but they'll put you through the grinder to get you to reveal any encrypted data. The US has some protections and case law for this. The UK has RIPA and peoe have gone to prison for not revealing encrypted content. Some cases have maximum terms of 2 years but some have maximum of 5 years. This needs to be factored into the risk assesssments of people using encrypted volumes.
- seniorsassycat 13y agoWhat random bits on my drive? Oh those, those are left over from testing to see if truecrypt volumes are distinguishable from random data.
- Zenst 13y agoCertainly some types of data sets can appear very random and radio telescope do produce much data that could certainly qualify as random. Also with trust issues in entropy for random number generation the viable options for large random chuncks of data start to become more appealing in use for certain tasks.
- Renaud 13y agoI almost always use truecrypt to erase my disks completely when I'm re-purposing them or before throwing them away or giving them to someone else. You never know where they are going to end-up years later. I just bang randomly on my keyboard when Truecrypt asks for a password and then let it overwrite the drive. It's pretty fast too and works the same way on all platforms.