6 ms·
Recommending BitLocker and OSX HD encryption I feel is a diservice to the public. I wouldn't put it past them to already have backdoors built in. Let alone the
by mr337 11y ago
Recommending BitLocker and OSX HD encryption I feel is a diservice to the public. I wouldn't put it past them to already have backdoors built in. Let alone they are both proprietary and not open to public audit. I guess we are suppoed to take their word [1]???
[1] http://mashable.com/2013/09/11/fbi-microsoft-bitlocker-backdoor/ http://mashable.com/2013/09/11/fbi-microsoft-bitlocker-backd...
- dijit 11y agoI really get a twisted feeling about people deposing Microsoft Bitlocker or OSX filevault due to potentially being backdoored- yet still running their operating systems, and any third party stuff you give full access to. I mean, I'm not trying to be all tin-foil, but trusting one source is much better than trusting two. (one for live OS security, another for offline data protection)
- mr337 11y agoWho said I was running OS X or MS products? :) I'm not following your 'trusting one source is much better than two'. Care to expand?
- fossuser 11y agoYou make the decision to trust some entity 'X' that has some probability of being compromised. If it isn't compromised you're good and if it is you're screwed, but as you add additional entities each introduces an additional individual probability of being 'bad'. There's an argument that it's better to trust one entity entirely in order to have a greater chance of being fully 'safe' rather than split your trust and having a higher chance of being partially compromised since partial compromise is often equivalent to being fully compromised. It's the same idea that leads the Tor network to use entry guard nodes: https://www.torproject.org/docs/faq.html.en#EntryGuards https://www.torproject.org/docs/faq.html.en#EntryGuards
- raesene9 11y agoWhat alternatives would you recommend? Also open to public audit doesn't mean anyone has actually looked at them/assured their security to any degree. the only product that I'm aware of in this category that has received that kind of scrutiny is truecrypt which has been abandonend by its original developers and doesn't have a license that is (AFAIK) conducive to someone else taking over the project.
- mr337 11y agoThat is the kicker, what to recommend. If at all possible I would recommend Linux or BSD. I am happy to see the article cover Ubuntu encryption. Also BSD has an embassy grade encryption, that has slipped from mind mind at the moment. I do realize that it isn't feasible to jump ship and move to another platform for everyone. The whole Truecrypt is a bummer since it was a good cross platform tool.
- brandon272 11y agoI'm a typical developer and I think I speak for the vast majority of people when I say that my concern is not with top level government agencies decrypting my hard drive. My concern is with me losing my computer or having it stolen by a petty thief, in which case I feel that the proprietary built-in encryption tools offered by Microsoft and Apple are perfectly suitable.
- mr337 11y agoI agree that for keeping the TSA Joe out of a laptop is is great. The issue comes with educating non technical people, which this article feels like it is aimed at, with a enryption methods that we can't gurantee are sound. While it may stop petty data theft we have seen how these backdoors trickle down and before you know it your local police department is abusing it left and right. An example of technology that has been package and sold is the Stingray for cell phones. Even though this is more of a nasty feature of cellphones that the Stringray exploits what is stopping a BitLocker or OSX exploit to be commoditized?
- brandon272 11y agoSecurity involves tradeoffs. If you are a non-technical person with typical security needs, the encryption functions that are built into operating systems offer a lot of security with almost no tradeoff other than clicking a button to enable it. Once you start layering on additional requirements for the type of encryption you are using (e.g. has to be open source, has to be audited, needs to offer no evidence of installed OS, etc.), you are creating a myriad of hoops to jump through that a non-technical person is more likely inclined to just not jump through at all. If you are someone with security requirements that need to guarantee that no one will ever be able to access your data, including the police or feds who might have access to secret backdoors, I would hope it's common sense that you should be doing a lot more research on encryption rather than relying on a random security article aimed at non-technical people.
- DanBC 11y ago> when I say that my concern is not with top level government agencies decrypting my hard drive. It's great that you have risk-assessed your needs. It's a shame that the title says "like you mean it", and not "for tamper resistance against most people, but probably not well funded government agencies".
- afreak 11y ago> But the FBI, concerned about its ability to fight crime — specifically, child pornography — apparently repeatedly asked Microsoft to put a backdoor in the software. A backdoor — or trapdoor — is a secret vulnerability that can be exploited to break or circumvent supposedly secure systems. >For its part, the FBI categorically denies asking for such access, telling Mashable that the Bureau doesn't ask for backdoors, and that it only serves companies lawful court orders when it needs to access users' data. (And, legally, it would still need a warrant even if a backdoor did exist.) There's a difference between "being asked to" and "actually doing it". If you think that Microsoft or Apple would backdoor their FDE to appease the FBI or any other federal agency is to assume that they have no interest in their customer base and would rather piss all over it. Besides, LUKS was "backdoored" by the FBI by simply having two agents behind someone's back and then having another agent grab the laptop as the individual turned around.
- hannibalhorn 11y agoThere has been some analysis of FileVault FDE, as well as an implementation of an open source library to read it. [1] The short answer is that they couldn't break it. While it'd be better if the whole thing was open source, at least the fact that I can understand the on-disk layout and algorithms used is comforting. [1] https://www.lightbluetouchpaper.org/2012/08/06/analysis-of-filevault-2-apples-full-disk-encryption/ https://www.lightbluetouchpaper.org/2012/08/06/analysis-of-f...