4 ms·
As a casual user, I would like to know how I am endangering users by encouraging them to use TrueCrypt? And what should I be encouraging them to use instead?
by 4oh9do 12y ago
As a casual user, I would like to know how I am endangering users by encouraging them to use TrueCrypt? And what should I be encouraging them to use instead?
- quesera 12y agoIf your disk is mounted when your computer is stolen or confiscated, your data is accessible. If your adversaries want your data, FDE will help them and not you. If you have secrets that would put you in danger if revealed, you would now be danger. The alternative is file-level encryption. The only accessible files at any given time are the ones you're using, so if you are relieved of your laptop on short notice, not all beans will be spilt. File-level encryption is a pain in the neck to work with. FDE is much more convenient, and a pretty good answer if your threat model doesn't include "drive by laptop snatching" as a major concern. This is most people.
- late2part 12y agoi.e. not Ross Ulbricht
- hackuser 12y ago> If your adversaries want your data, FDE will help them and not you. Sorry to nitpick, but it may confuse a casual user: FDE will not help your adversaries, it just won't help you. That is, in those circumnstances (i.e., when your disk is mounted) FDE won't have any effect.
- quesera 12y agoAgreed. The comparison which wasn't clear in that sentence was to file-level encryption. At the point of seizure, your chosen data protection method is either helping your adversaries by offering all files unimpeded, or helping you by not doing so. It's equivalent to having no data protection at all, if you adversaries are competent.
- 4oh9do 12y agoAh, I see. Am I correct then that the cautionary note was just in general about the pitfalls of FDE if a mounted drive is compromised while mounted? I think I misinterpreted it to mean that there was a specific problem with TrueCrypt which leads its use to endangering users. In my own use case and in that of people I've recommended TrueCrypt to, having the hard drive apprehended while shut down, specifically during customs checks, is a far greater risk than having the computer compromised while the encrypted drive is already mounted. Given that particular threat model, is it OK for me to continue to use and recommend using TC?
- quesera 12y agoIf you cannot be surprised while the drive is mounted, and cannot be compelled to mount it (maybe just by booting the machine) then there is no known specific additional risk to running FDE. Note that "surprised" might include a networked attack, in addition to being tackled in a coffee shop. File-level encryption protects your data until you reach the court order level of compulsion, and possibly further. At least in civilized countries. So, given those caveats, I'd say your answer is "yes", but...the best plan is to do both. FDE as a matter of policy, and file-level on any files of specific value.
- 4oh9do 12y agoThanks again. Can you please clarify what is meant by networked attack in this context? Someone gaining access to the mounted drive over a network, or something else?
- quesera 12y agoSure. If your FDE disk is mounted and your machine is susceptible to any kind of remote exploit (OpenSSL, Adobe flash, weak ssh password, etc) then the attacker has full reign over your disk when they arrive. File-level encryption constrains them to just the files you have open at the time, although of course any breach might be persistent, so they could theoretically wait around until supersecret.txt gets opened and grab it then.