When Full-Disk Encryption Goes Wrong
spaceisdisorienting.com
spaceisdisorienting.com
If you have a Mac, get an AirPort Time Capsule. This gives you automatic, hourly backups. The importance of automatic cannot be overstated. If you have multiple Macs, they can all backup the same Time Capsule.
You can save a little money using an external hard drive, but how often are you (or your family members) going to remember to plug it in and run Time Machine? Once a week?
FDE further complicates things, though, as if the volume master key is corrupted everything is lost. If my hard drive dies, there's a decent chance that a data recovery shop can recover at least some of the data.
If you're here, get a Tarsnap account. This gives you backups however you script them. They're versioned, deduplicated, and NSA-resistant.
And while I've got your attention, 1) are Arq backups encrypted and 2) can it back up via SSH to my own storage somewhere - like a cheap VPS with lots of disk space?
2) Yes. Although if you're after cheap space, Hetzner's storage boxes are the cheapest $/GB I've seen (https://www.hetzner.de/hosting/produktmatrix/storagebox-prod...), with Backblaze B2 close behind.
Compare that to Backblaze or CrashPlan, which do all your PCs for $5/month.
Or, if you are stingy and/or enjoy a bit of occasional sysadmin DIY, get a Linux box and configure it to look like a TC. There are plenty of tutorials out there, it's very easy.
Time Machine likely makes sense for laptops, though it's got low storage capacity at the price.
Not really. Those 4KB with the encryption key are EVERYTHING in full disk encryption. There's nothing equivalently important in unencrypted disks.
1) full disk encryption
2) police takes your laptop
3) after six months you are asked to decrypt the harddrive
4) you dont remember 100 character password after all that time
5) you go to jail until you remember
1. This is still murky law, still being explored... but I believe you can't be compelled to reveal something you know (your password) but could be compelled to reveal something you have (a key.)
2. Contempt of court I think is for 6 months at a time and has to be renewed, and regularly isn't renewed. If your hard drive contains crimes worse than 6mo of jail, contempt is a good way to go.
http://www.nytimes.com/2016/05/06/technology/former-officer-...
Important even if you're not using FDE, but by design FDE makes any data corruption significantly worse. Not an Apple specific problem, either. LUKS is actually specifically designed so that the master key is wrapped in a large all-or-nothing transform (anit-forensics) to make it exponentially harder to recover from a damaged header.
Every other FDE scheme I've ever seen does, accompanied by big scary "WRITE THIS DOWN. IF YOU LOSE IT, AND THEN YOUR DISK GETS CORRUPTED, YOUR DATA IS GONE FOREVER" warnings, and with good reason: yeah, if the master key sector is corrupted and you don't have a backup, you're screwed.
sudo fdesetup validaterecovery # check
sudo fdesetup changerecovery -personal # change
Obviously this doesn't reencrypt the disk, so you can guess how it works.This way, the user never can retrieve the master key and access rights can be modified all while keeping the master key and thus avoid re-encryption on the drive if a new user is added/an old one removed/one changes his/her password.
Downside: if the master key goes boom, so do the data, with no chance of any recovery.
This is true for LUKS on Linux as well. Destroy the LUKS header, you data is now forever gone.
Using a separate OS X boot volume I created a USB installer of El Capitan, booted that, went to Disk Utility, asked it to unlock the encrypted primary volume, using just the normal passphrase, and it worked. I then went back to the main menu to reinstall the OS; i.e. installing over the existing (newer) El Capitan installation. The installer took forever but it reinstalled the (older) OS version of El Capitan, created a new Recovery HD volume, and did not erase any of my data. And I could boot afterward.
So too bad this guy's blog doesn't accept comments or I'd tell him this directly and there's a pretty good chance his data can be recovered intact.
I lost a volume to BitLocker AES-XTS 256 earlier this year and luckily only lost a few days of work. I've since substantially improved my backups and even rotate a disk offsite weekly now.
I use Arch, which is not beginner friendly, but the wiki states this in a big, red banner. I'd expect an end-user friendly OS to do the same once the password is set for the first time, and over and over again until the backup has been made.
Does Apple actually enjoy leaving all the user's data to chance?
It's an external USB drive I have plugged into my monitor. When I plug my laptop into the monitor at work it silently does its duty. I never even think about it until I need to recover a file that I just rm'd!
Drives that claim to do encryption themselves have their own issues (like not actually using the user provided key for encryption and other crypto failures from developers & companies not familiar with how crypto is supposed to work).
One problem is that you have to trust the disk (manufacturer/firmware) to do this right. This is not so easy to verify yourself, and not all drives claiming FDE are equally secure. https://en.wikipedia.org/wiki/Hardware-based_full_disk_encry...
https://vxlabs.com/2012/12/22/ssds-with-usable-built-in-hard...
Many consumer drives are SEDs now. Check out the Samsung 840 EVO which is such a thing. It's always encrypting, it's just that out of the box it's always unlocked (i.e. it provides itself with the DEK at power on).
More details here: https://eprint.iacr.org/2012/374.pdf