20 ms·
Encrypting Windows Hard Drives
- skrowl 11y agoSince the death of TrueCrypt, I've been using VeraCrypt (https://veracrypt.codeplex.com/ https://veracrypt.codeplex.com/). It's cross-platform FOSS instead of the "Hey, buy now!" BestCrypt that this article is pushing.
- sliverstorm 11y agoBestCrypt sounds like it's cross-platform, at least.
- egb 11y agoVeraCrypt https://veracrypt.codeplex.com/wikipage?title=Downloads https://veracrypt.codeplex.com/wikipage?title=Downloads seems to have Linux and OSX as well as Windows - or is there something else going on?
- bgroins 11y ago"BIOS mode only, UEFI/GPT not supported" It's getting increasingly difficult to buy a Windows computer that's not UEFI/GPT, so no OS level encryption.
- Llevel 11y agoTheir store looks like they only have volume encryption on Windows, and container encryption for Mac, Linux and Windows, unless I'm mistaken. https://www.jetico.com/online-shop/shop/index/all-products https://www.jetico.com/online-shop/shop/index/all-products
- sliverstorm 11y agoA-ha, I missed that distinction.
- kijin 11y agoVeraCrypt looks good, but incompatibility with TrueCrypt volumes makes me uncomfortable with switching. I've also looked at CipherShed and DiskCryptor, but the fragmentation gives me no assurance that I'll be able to access my encrypted volumes several years from now. So I'm still stuck with TrueCrypt 7.1a. After all, it's the only disk encryption software for Windows that has been independently audited. None of the purported replacements and proprietary alternatives can lay claim to that distinction, no matter how much Bruce Schneier might personally trust the developers.
- ikeboy 11y agoVeracrypt now has a truecrypt mode, which can read truecrypt volumes. I believe it can also convert them to Veracrypt ones by changing the algo then unchecking truecrypt mode.
- userulluipeste 11y agoI've found about DiskCryptor trough ReactOS driver signing page: https://reactos.org/wiki/Driver_Signing https://reactos.org/wiki/Driver_Signing They say that they review the code the result of which they offer signature for. Is or isn't that enough for "independently audited" label?
- kijin 11y agoReview != security audit.
- darkhorn 11y agoThere are some motherboards that can store the encription key so that you don't need to type the pasword again when booting. BitLocker supports it. What a great technology. It saves your life!
- wfunction 11y agoSounds like it completely defeats the point of encryption.
- jhallenworld 11y agoYou could store the key (or password to the key) in the TPM in order to prevent BIOS, bootloader or option ROM tampering. An issue is that too many things could affect the TPM PCR values (for example, plug in a USB stick even though you don't boot from it- I think this is a mistake in the spec), so users get used to typing in the backup password and may not notice that a root-kit was installed.
- MichaelGG 11y agoIn my experience of using Bitlocker for years, it's very rare that I have to enter the backup password. Even when I changed the default PCRs used.
- theandrewbailey 11y agoIt works great until $MALICIOUS_ENTITY unexpectedly takes your laptop, turns it on, and gathers unencrypted data.
- yebyen 11y agoI think the point of this feature (TPM? at least as I've seen it implemented on laptops) is that you can have a signed bootloader and encrypted drive such that, you don't need a passphrase to boot the OS (the TPM has it, or equivalent), your TPM verifies you are booting a trusted OS (that means it will actually authenticate users in the usual way and check their authorization before granting them access to data) ... and nobody who just picks up your laptop can either read your files without your password, or remove the drive and gain access to your files without the TPM. Whether that chain all works as I imagine or not, I can't say and I haven't investigated to be able to say. I don't know if all it takes to gain access to the TPM in reality is (physical access to the machine), a USB stick with EFI booting, and any signed OS that will verify you are a root user authorized by that USB stick, which anyone who has $99 can get on their own, or just download Ubuntu or RedHat on your own can get. That would be a pretty big let-down if that was really all you needed, though.
- higherpurpose 11y agoI don't think Microsoft is ever going to risk putting a Backdoor™ in Windows after NSA_key or at the very least after the Snowden document leaks + OPM hack (which both prove the US government's incompetence in storing classified information securely, which means the company's backdoor could be exposed at any time). But that doesn't mean Microsoft isn't going to make it easy for the NSA to bypass its security. We've seen several reports of that from the Snowden documents, and it affects OneDrive, Outlook, Skype and probably even Bitlocker. All Microsoft needs to do is not fix a vulnerability it finds out about (not a third party that reports the vulnerability to the company, as they would have no choice but to fix that). And it doesn't even need to do that indefinitely. It could fix it when a new vulnerability appears, and it can rotate them every 6 months or so. Then it can either directly give that vulnerability to the NSA through all the "cyber sharing programs" where Microsoft has been a "volunteer" for years (way before Apple), or it can let NSA "discover" it on its own, which can be as easily done as Microsoft's security researchers talking about a new vulnerability internally through channels that don't have strong end-to-end security.
- MichaelGG 11y agoIf they rotate vulnerabilities in Bitlocker, that could be discovered via reverse engineering. And a big vulnerability (like incorrectly calculating the IV for a sector) would require rewriting the disk. I'd also wonder what vulnerabilities would exist in such software. The encryption part is well described, and one would expect it'd be done right (and if it's wrong, that requires rewriting the disk to fix). Other than that, what are we talking about? Bugs in the TPM/BIOS PCR checking? Accidentally writing the keys somewhere? I'm probably being very unimaginative here. Edit: Let me say I'm assuming you have a password in addition to the TPM. Obviously if you can boot the machine up and have Bitlocker decrypt, and you have access to the machine, you can somehow extract the key if you have the resources.
- Someone1234 11y ago> Windows after NSA_key _NSAKEY wasn't a backdoor. People need to let that go. Not a single line of code was ever discovered that indicated the NSA was utilising it as a backdoor into cryptography, so the entire basis for the conspiracy theory is that the variable which holds the "backup key" happened to have been named that (and that includes the NT4.0/2000 source code leaks). https://en.wikipedia.org/wiki/NSAKEY https://en.wikipedia.org/wiki/NSAKEY Also Microsoft shares the Windows code with many institutions[0]. Yet none of them, nobody at Microsoft, and not even the Snowden leak indicated a backdoor in Windows. Microsoft MIGHT have made it easier for the US Government to tap Skype calls (and I believe that they did based on available evidence). Aside from that for all the mudslinging almost none of it ever sticks. [0] https://www.microsoft.com/en-us/sharedsource/ https://www.microsoft.com/en-us/sharedsource/
- MichaelGG 11y agoSince he knows Niels Ferguson and understands cryptography, why doesn't Bruce get some proper analysis or statement regarding the damage of removing the diffuser? Seems like that's one obviously big elephant in the room here.
- bradford 11y agoBruce's article linked to this article (https://firstlook.org/theintercept/2015/06/04/microsoft-disk-encryption/ https://firstlook.org/theintercept/2015/06/04/microsoft-disk...), which does have a statement about the elephant diffuser, including why MS removed it and its overall impact to bitlocker. I think it's best summarized as: "Removing the Elephant diffuser doesn’t entirely break BitLocker. If someone steals your laptop, they still won’t be able to unlock your disk and access your files. But they might be able to modify your encrypted disk and give it back to you in order to hack you the next time you boot up"
- tptacek 11y agoThat is true of practically every full disk encryption package, because of the nature of encrypting disk sectors rather than files: with no format flexibility or straightforward place to store metadata, and no awareness of message boundaries, it is difficult to meaningfully authenticate data. Vanilla CBC makes it easier to mount attacks, and XTS makes it harder, and the diffuser may have even made it incrementally harder. But no notion of difficulty here deserves the uppercased "Hard" we're looking for with cryptography: at best, you concede attackers "only" the ability to randomize targeted ranges of stored bytes, which --- especially for the mountains of C code we call "operating systems" --- is a devastating vulnerability. If you are seriously worried about Highly Capable Attackers, and you lose custody of your laptop, you should consider writing it off.
- tptacek 11y agoWhat analysis are you looking for? The purpose of the "diffuser" is well-understood, as are the security implications of losing it. This comes up on HN about once every other month, on threads you've been a part of. What part of the explanation you've gotten here seemed inconclusive?
- jron 11y agoI think this is worth repeating: "I asked Microsoft if the company would be able to comply with unlocking a BitLocker disk, given a legitimate legal request to do so. The spokesperson told me they could not answer that question." - https://firstlook.org/theintercept/2015/06/04/microsoft-disk-encryption/ https://firstlook.org/theintercept/2015/06/04/microsoft-disk...
- nickpsecurity 11y agoIt doesn't mean anything because it's a standard move to reduce legal risk. No comment is almost always the safest answer. This applies to individuals too: https://www.youtube.com/watch?v=6wXkI4t7nuc https://www.youtube.com/watch?v=6wXkI4t7nuc
- LMAlVvQjSGj 11y agoIt's a pathetic stance.
- belorn 11y agoIt is a move to reduce trust in a market where trust is the single most important aspect. Schneier's article is all about whom he trust, why he trust them, and conclusion he makes based on that trust. If you bought a security product and the developer of it describes its strength as "No comment", would you trust it? Personally I am sticking with the abandoned TrueCrypt until a successful fork has been created or luks + dmcrypt has been ported to windows.
- nickpsecurity 11y agoIf you were right, then the most trustworthy companies would have the most market share while offering us good EULA's. Looking at top software names, it's clear trust and success in the market place have almost nothing to do with each other. It's actually opposite with the dirtiest companies on top in most places. Negative media definitely hurts the bottom line but majority of time isn't an issue. They have PR people for that. There have always been companies that share source with customers, use stronger security tech, warranty their code, and so on. They were minority players pre-Snowden with many having left that market because so few cared. (myself included) Post-Snowden, they're still minority players with the market mostly going for whoever promises the most on their web sites & in media. Trust and security have always come 2nd (5th?) to all kinds of other criteria for buyers in the IT market. If you doubt, look at number of Facebook or Gmail users vs number using more private alternatives. People & companies sell themselves out in droves.
- revanx_ 11y agoThere may not be any deliberate backdoor in BitLocker however I think it's safe to assume that NSA has access to the source code, probably found some angle to exploit.
- tptacek 11y agoWhat's the disk encryption offering you think NSA doesn't have source code to?
- Dylan16807 11y agoPlus encryption routines aren't that big; for a major organization there's no real need for source code at all.
- nickpsecurity 11y agoThat's a good point. Any product of significance that runs in software on untrusted users computers can be compromised by determined attackers, NSA or not. Even hardware-protected secrets have been bypassed. Hence, the security argument must rest on something that works regardless of whether enemies know the mechanism.
- erhardm 11y agoI think that's the Kerckhoffs' principle[0]. Regarding to state actors who have the resources to attack any system, I think it's important to make it as hard as possible, even if it's "known" they will find a way. Why? Because it will drive the costs very high with years of R&D having as result that they'll only use new attack techniques on high-level targets and that means risk of revealing attacks goes up(assuming high-level targets are more sophisticated and spill the beans - as in Kaspersky case[1]). [0] - https://en.wikipedia.org/wiki/Kerckhoffs%27_principle https://en.wikipedia.org/wiki/Kerckhoffs%27_principle [1] - https://securelist.com/blog/research/70504/the-mystery-of-duqu-2-0-a-sophisticated-cyberespionage-actor-returns/ https://securelist.com/blog/research/70504/the-mystery-of-du...
- 11y ago
- unsignedint 11y agoOne problem I have with BitLocker is that it's only supported on Ultimate/Enterprise (on 7) and Professional and up (on 8) I guess one could argue about not having those editions in a business setting, but the vast majority of pre-installed Windows in a market is Home Premium, and I can't think of enough justifications (especially in small businesses) for higher editions, and besides, many people, in home setting would want to have this extra protection for their computers. (After all, they do banking, tax, etc.) -- It seems like non-pro 8.1 does BitLocker for system drives, but then it also comes with a bit of "only if's" (InstantGo, SSD, non-removable RAMs, TPM, etc.) As someone else mentioned here, it seems like choices are starting to become narrow as fairly limited solutions can support UEFI/GPT, too...
- Someone1234 11y agoWindows 8.1 and above now have a type of "poor man's bitlocker" simply called drive encryption. It works on non-pro/non-enterprise systems. It requires a TPM, uEFI, and Microsoft Account. But once you meet the requirements it gives you a "basic" level of encryption which for a petty criminal is hard to break. Most Surface Pros 3 will have this enabled already. http://www.howtogeek.com/173592/windows-8.1-will-start-encrypting-hard-drives-by-default-everything-you-need-to-know/ http://www.howtogeek.com/173592/windows-8.1-will-start-encry... Legit Bitlocker is superior in many ways (in particular not having to store a backup key in a Microsoft Account, and having more choices about how to decrypt). But for consumers it is a very welcome addition.
- wlesieutre 11y ago> It requires a TPM, uEFI, and Microsoft Account. But once you meet the requirements it gives you a "basic" level of encryption which for a petty criminal is hard to break. Most Surface Pros 3 will have this enabled already. Are you sure this is accurate? I'm using a Surface Pro (comes with Windows Professional), and when I go to the BitLocker settings (in Control Panel) it's shown as enabled. I haven't changed from whatever the default settings are.
- yareally 11y ago
- adrianscott 11y agoCertainly there is 0% chance that the author is asking us to read between the lines here... #FaceValue
- tptacek 11y agoIt's a little disturbing to see Schneier recommending a disk encryption package that offers to encrypt drives using CAST, GOST, and Blowfish.
- sarciszewski 11y agoIs this a warrant canary? /s What do you recommend for Windows users?
- tptacek 11y agoBitlocker, and then authenticated encrypted archives (for instance, PGP'd ZIP files) for anything sensitive, including your mail spool.
- sliverstorm 11y agoExcept everybody's trying to run him out of town on a rail for even suggesting Microsoft (!!!!!) Bitlocker
- nickpsecurity 11y agoHe's currently recommending, for Windows users, either Bitlocker (256-bit AES) or BestCrypt (256-bit AES, RC6, Serpent, or Twofish). Not whatever link in the article you found those in. Unless I overlooked them in Bitlocker or BestCrypt's spec pages... About those, though, CAST-128 isn't trustworthy (chosen-plaintext attack), GOST is probably there for Russian market, and Blowfish is fine given all the beatings it survived (good sign of security). I still use Blowfish and even IDEA in my polymorphic ciphers that semi-randomize a combination of strong ciphers along with counters.
- tptacek 11y agoBlowfish and IDEA are not fine. They're block ciphers with 8-byte blocks. They are both materially less secure than AES. Recommending them is borderline malpractice.
- Kenji 11y agoIf it ever turns out that Microsoft is willing to include a backdoor in a major feature of Windows, then we have much bigger problems than the choice of disk encryption software anyway. That might be so, but proper encryption is still valuable. Say you have a disk full of sensitive information. Say your computer was turned off as the adversary gets hold of it. If you have a proper encryption program, no OS backdoor will be able to decrypt it retrospectively (that is, when it's activated after the bust). Broken encryption makes you vulnerable even when you're offline or the PC is turned off.
- marcosdumay 11y agoWay to miss the point. If you run Windows, Microsoft has complete control of your computer. Unless you never turn it on, MS can log all the keys you press, all the data on the disk, all the network traffic, or really anything else they want at will. If you trust them not to do the above, why wouldn't you trust them to encrypt your disk too? (Unless you don't trust their competence. But then, you are trusting them to secure your computer while it's on, but not when it's off?)
- RaleyField 11y ago> Microsoft has complete control of your computer. So does any Linux distro if you don't compile from sources yourself. Who knows, maybe Debian openssh fiasco was an inside job. > why wouldn't you trust them to encrypt your disk too? I trust them that they wouldn't be actively spying on their customers, because that's a good way to kill your company. I don't trust them they tried their utmost to secure our computers (we'd be running Singularity/Midori/Verve otherwise), because they are likely being coerced to comply with various orders and regulations.
- hackuser 11y ago> I trust them that they wouldn't be actively spying on their customers, because that's a good way to kill your company. Many, many companies actively spy on their customers, including some of the most successful companies in the world.
- venomsnake 11y agoDo we have good container encryption that mounts them as drives on windows? I never understood the point of whole disk encryption stuff.
- themeek 11y agoBitlocker (well, "Device Encryption") does upload your harddisk keys to OneDrive by default, and OneDrive is onboarded to PRISM for government request. So in the case that you end up provisioning a computer or device with Bitlocker, the key may very well end up in a database for query. Outside of this it's not really so speculative to think that Bitlocker has backdoors for gov't access. It's unlikely that Microsoft Bitlocker survived the combined forces of state-of-the-art cryptanalysis, legal compulsion, and company infiltration (exposed by Snowden). A backdoor for disk encryption need not directly attack the cryptography. It could be something as simple as a means to generate a bunch of predictable blocks on the harddrive - that's enough to break XTS. That is, even if there's no software backdoors or backdoors build into the TPM (Lenovo, for example, has 'key escrow' capabilities to extract Bitlocker keys out of TPMs) or crypto backdoors in HW PRNGs (e.g. Intel RDRAND), etc there are software bugs in other places that could reveal the contents of the hard disk. So it's merely not a threat model you're ever going to find a solution for. In the very worst case, presuming there were some mystical level of harddisk encryption that was't trivial to backdoor or break by a sophisticated adversary - intelligence folks can use TEMPEST attacks, break into your computer when you turn it on, and/or get rubber hose access. An encrypted disk will not stop Mossad. There is no disk encryption that will unilaterally prevent USG from accessing your files (you can only make it more expensive). But as the USG is fond of repeating - you don't need your disk encryption to protect you from the government unless you have something to hide. You only need it to prevent attacks from criminals and for device theft.
- tptacek 11y agoCan you explain more carefully the XTS attack you're contemplating here? The Device Encryption recovery key feature was discussed at length here: https://news.ycombinator.com/item?id=8546524 https://news.ycombinator.com/item?id=8546524 Certainly, people who are concerned about security should disable/avoid it.
- themeek 11y agoSure. XTS reuses the sector-block for an IV, and so on a per-block level encryption is deterministic. The flaw here would be a scenario where there are deliberate repeated modifications to blocks of the harddrive (somewhere like within hibernation/wake code). Something carefully designed could, in theory, lead to the compromise at a block level that would allow tweaking of some contents on the disk (say, contents of the registry, or of some boot switches, etc) that would in turn enable the machine to be booted and the disk to be decrypted. It's also true that the TPM protector for bitlocker uses a pin with max ~20 bits of entropy to shield the bitlocker key from exfiltration. The TPM is supposed to lock out repeated requests to extract they key but given the heavy involvement of the NSA in designing the TPM spec and its similarity to the Clipper Chip in function (so too with Apple's "Secure Enclave"), and its difficulty to audit (as if mom and pop consumers really need protection from adversaries who are going to reverse TPM chips to get computer data), one can't help but to acknowledge that a backdoor could easily exist there. All of this is hypothetical of course. I don't claim to know that this sort of attack is there or that it is placed deliberately. I'm merely trying to make the point that a backdoor need not be in the harddisk encryption code itself.
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- ikeboy 11y ago>when Microsoft released Windows 8 Um, no.
- spacehome 11y ago> BitLocker is Microsoft's native file encryption program. Yes, it's from a big company. But it was designed by my colleague and friend Niels Ferguson, whom I trust. Nullius in verba