Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy technology
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 20th, 2011, 03:03 PM
EncryptedBytes EncryptedBytes is offline
Frequent Poster
 
Join Date: Feb 2011
Location: Odenton, Maryland
Posts: 416
Default Truecrypt question/verification

I've been using this freeware for years and love it. Recently though I received a new laptop which came with two SATA drives built into it. The user has free reign with them, though I have my windows partition with one and house my VMware OS's on the other. Windows mounts the other one on load up for additional space. I am looking for confirmation on my thought process here to encrypt both and not lose my mind, here is what I have in mind:

Perform a full disk encryption on Drive1 housing my windows, then perform another full disk encryption on the other though once I boot into Windows allow truecrypt to run upon start up and auto-mount the second drive? This way both drives can be used and I lose no functionality. Is this the correct solution to this dilemma?
  #2  
Old November 21st, 2011, 12:03 PM
Hank88's Avatar
Hank88 Hank88 is offline
Infrequent Poster
 
Join Date: Dec 2010
Location: B.C., Canada
Posts: 16
Default Re: Truecrypt question/verification

Wouldn't your question be better answered over at the TrueCrypt Forums?

http://forums.truecrypt.org/

Ken:
  #3  
Old November 22nd, 2011, 02:35 AM
LockBox LockBox is offline
Very Frequent Poster
 
Join Date: Nov 2004
Posts: 2,081
Default Re: Truecrypt question/verification

Quote:
Originally Posted by EncryptedBytes
I've been using this freeware for years and love it. Recently though I received a new laptop which came with two SATA drives built into it. The user has free reign with them, though I have my windows partition with one and house my VMware OS's on the other. Windows mounts the other one on load up for additional space. I am looking for confirmation on my thought process here to encrypt both and not lose my mind, here is what I have in mind:

Perform a full disk encryption on Drive1 housing my windows, then perform another full disk encryption on the other though once I boot into Windows allow truecrypt to run upon start up and auto-mount the second drive? This way both drives can be used and I lose no functionality. Is this the correct solution to this dilemma?

It's exactly what I do. You simply use the "System Favorites" function.
http://www.truecrypt.org/docs/?s=system-favorites
  #4  
Old November 22nd, 2011, 01:04 PM
dantz dantz is offline
Frequent Poster
 
Join Date: Jan 2007
Posts: 579
Default Re: Truecrypt question/verification

I'm writing this from a reliability/data recovery/disaster recovery point of view.

Encrypting the entire system disk plus fully-encrypting the entire internal data disk may seem like the simplest solution, but the reality is that in the first case it can make disaster recovery much more difficult, and in the second case it will result in a disk that can be spontaneously overwritten by normal Windows activities. It's almost always better to encrypt each partition separately rather than encrypting entire disks.

I normally recommend first encrypting the system partition and then separately encrypting any other partitions that might contain sensitive user data. You can set them as system favorites if you want them to mount during bootup, otherwise leave them unmounted until they are actually needed. Don't bother encrypting the manufacturer's recovery partitions or the Windows 7 boot partition, as those partitions don't store any user data.

Exceptions to the above: On the system drive, if you have altered your partition layouts AFTER storing sensitive data in them, but BEFORE encrypting them, then it's possible that some data remnants might now exist in unallocated space (e.g. partition gaps etc.). This is uncommon, but possible. In this case you can either encrypt the entire system disk in its current condition, or you can wipe the entire disk, set up new partitions, reinstall Windows and then encrypt the individual partitions.

The same logic applies to disks that are used only to store user data. If you've been altering your partition layouts such that sensitive data remnants might now exist within the unallocated space then it's probably best to first wipe the entire disk, then set up new partitions and encrypt them. You could also merely encrypt the entire device, as this would include all unallocated space, but I recommend against this option when used in conjunction with internal hard disks because Windows has an unpleasant habit of spontaneously 'fixing' the apparently blank and uninitialized (from Windows' point of view) disk. Basically, Windows overwrites your encryption header with boot sector information, although worse outcomes are also possible. These sorts of things are especially likely to happen during a Windows upgrade or reinstallation, but it can also happen at other times such as during an unexpected Windows glitch. Other software, especially partitioning software, can also spontaneously make these sorts of changes to your fully-encrypted device without warning. If the disk is external then you can merely disconnect it during the riskier moments, but an internal disk is always vulnerable to these sorts of occurrences.

Note: To improve your chances of recovering your data if things should go wrong, I recommend burning an extra copy of the TC rescue disk as well as copying the rescue disk iso file. You should also manually back up the headers of all encrypted partitions. Store all header backup files and the iso file externally. And back up your data as well, of course. The added layer of encryption will immensely complicate most data-recovery operations, so keeping separate backups of important data is crucial. The backups can also be encrypted, of course. As long as they're not connected to the system they won't necessarily share its fate.
 

Wilders Security Forums > Privacy Related Topics > privacy technology « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:47 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums