New Year's Resolution: Full Disk Encryption on Every Computer You Own
eff.org
eff.org
What freaks me out most these days is how easily people fall into the belief that "oh well traveling is not a right so you have to give up rights when you fly or drive anywhere".
No, if you are a citizen of the United States and unless you are actually crossing a border, you should have the unqualified protection against unreasonable searches, especially without warrants.
I also don't accept the "well it's worse in other countries, be happy you are not there" argument. This country is not even 250 years old. The laws we made are pretty fundamental and not old at all. It's not some kind of game where they should be allowed to dance around the edges to break them.
The drugs trade is the flow of narcotics from source to sink. Stopping them at a national border is one approach; stopping them elsewhere in transit (as it leaves the source, on the open sea, at the destination by local police, etc) is another. And then you have one more: tackling the existence of a source and a sink. In other words, you look at supply (i.e. creation/generation of stock) and demand. I believe that this is perhaps the best approach, and it is definitely one to which borders are irrelevant. So I don't really accept that as a counterpoint to what I was saying. In some ways, the fact you thought it was illustrates my point: our focus on borders is simplistic and maybe distracting us from finding more effective approaches that might be inspired by a thorough analysis of the system dynamics.
People trafficking is to some extent the same thing: source, sink, and a flow over many miles from one to the other (maybe across a border, maybe not).
As for illegal immigration, you have a flow that exists because of inequality (i.e. it's a flow down a gradient) - a difference in living standards, job opportunities, safety, etc. This inequality makes the recipient country a sink and the donor country a source. But of course, once again we shouldn't be talking about countries. Some regions are more attractive than others, and people have always moved between them, generally to the gain of one region and the detriment of another. Population flows can be cross-border, or not, despite the similarity in causes. Once again; should borders really be the focal point at which destabilising migrations are addressed by modern, globalised societies?
However governments rarely divest themselves of power once acquired, and so although many, many more folk are internationalist these years, there exists this relict of national control.
/stills rant about how in the United States, the Social Security was promised never to be used as a universal identifier.
Passports were referenced plenty in Around The World in 80 Days, written in 1873. ( http://aroundtheworld.phileas-fogg.net/80days.html )
Although if you mean the systematic use of passports, rather than their invention, yes - Wikipedia Says:
*During World War I, European governments introduced border passport requirements for security reasons (to keep out spies) and to control the emigration of citizens with useful skills, retaining potential manpower. These controls remained in place after the war, and became standard procedure, though not without controversy. British tourists of the 1920s complained, especially about attached photographs and physical descriptions, which they considered led to a "nasty dehumanisation"
While the modern-EU person can do this without any trouble, anyone from outside the EU (or the US), this is just a pipedream without serious legal money to throw at the visa manufacturing industry.
Nationalism is still heavily with us, and even more so than in earlier times.
I agree. Practically speaking, the government can only search what you're physically carrying over the border. That means if you boot from something like a live CD and store all your data in the cloud, you're safe from search. To search a US-based cloud provider, the government needs warrants and for those they need probable cause, which means you are relatively protected against unreasonable searches.
I encrypt my laptop because I don't want to rely on the cloud, but this is hardly the path of least resistance. If you want to be secure in your papers, don't have any papers.
There remains the space for a cloud sync service that encrypts client side and provides good enough clients for every major platform.
Spider Oak comes close, but it's just too damn ugly an interface and isn't the "Install and forget" option that Dropbox is.
However, I also know that since their website allows me to access data and reset my password, their key management doesn't prevent Dropbox employees from viewing my stuff.
Dropbox had said that they encrypt data before storing it at Amazon, but their systems see all of your raw data because they do deduplication, and because they could reset your passphrase, and because client-side encryption of stored data would make web access very complicated if not impossible.
If all that weren't enough, the dropbox forums, long before the early 2011 PR problem, had threads about using truecrypt containers on dropbox shares to ensure security. It also had feature requests to add client-side encryption to the dropbox client. If some people didn't get the message that dropbox has access to raw data, after all of that evidence, they have only themselves to blame.
If I understand correctly, it's not as secure/confidential as Spider Oak: the encryption key for file A is Hash(A) and your own key is only used to gain access to Hash(A) in order to decrypt the files. This lets them deduplicate more efficiently on their end, but it also means they can determine if two users have the same file. It also has some other repercussions (there is a HN story about it). It's still a lot better than DropBox, though.
http://www.philzimmermann.com/EN/news/PGP_10thAnniversary.ht...
Disk encryption means not having to apologize profusely to everyone when/if your laptop is stolen. That's the real low hanging fruit.
Of course, the only sensitive data I have is authentication credentials (easily revoked), commercially sensitive stuff, and personal privacy (which has much higher value to me in keeping secret than to anyone else in publishing), so I feel pretty safe.
So the outcome was that a warrant was given to search his house, 6 armed officers entered, took two laptops and left (to my knowledge, they still haven't been returned). He wasn't charged with a crime or wasn't a suspect in a crime, he merely had a link posted in a wordpress-hosted blog that he runs by the person that distributed the zip file containing the emails.
It's pretty bad that you can lose hardware and have it inspected by unknown persons for unknown reasons simply because you had an anonymous poster put something on your blog.
This story, to me, really brought it home that the biggest threat to computer privacy probably isn't theft but rather falling foul of a political position.
http://tallbloke.wordpress.com/2011/12/14/tallbloke-towers-r...
Why? Because this allows you to appear to be cooperating with any request to look at your computer. Simply type in the level 1 stuff and demonstrate the system booting up. I bet 9 times out of 10 whoever is checking you over will stop right there: it looks a lot like compliance. If they keep pushing for total access to your data simply say "no" Whereas if you say "no" to begin with, you're likely to attract more attention than if it appears you have nothing to hide. In many cases people are working jobs where they only have so much time to check things -- unless there appears to a be a person with a problem, in which case they can take all day with you. So help them out. Give them something to ask you for that you can produce. Then everybody can move along and it's not a problem for anybody.
(BTW, if you're worried about a state-level adversary, that means you should always turn off your computer when not using it, and wait a few minutes before physically leaving it to prevent a cold boot attack)
The point of a hidden OS is plausible deniability. When used correctly, there shouldn't be any evidence that another OS exists. For instance: what if there wasn't a hidden OS, and you do keep random data in your unused HD space? They'd be jailing you for refusing to give something that doesn't exist.
That doesn't sound like a desirable outcome.
Basically, laws that don't make absolute logical sense are fine, they'll just decide who to prosecute. Totally fine, nothing to see here.
Something mentioned at the beginning of the paper "I've Got Nothing to Hide" and Other Misunderstandings of Privacy, is Friedrich Dürrenmatt's Traps, from 1956. It involves a seemingly innocent man put on trial by a group of retired lawyers for a mock trial game, the man inquires what his crime shall be. "An altogether minor matter," the prosecutor replied … "A crime can always be found."
So you're better off making a hidden OS partition and not using it, just so you can access it.
That said I still use it on both of mine and definitely suggest it, it's a very small performance penalty for what will be a godsend if your laptop turns up lost or stolen.
https://code.google.com/p/cryptsetup/ It's an excellent precaution against the much more mundane and common threats like loss or theft though
The latter option probably won't earn you any favors with the judge or the jury.
Though MS says that BitLocker doesn't have back doors [1], I wonder how true this actually is...
[1] http://blogs.msdn.com/b/si_team/archive/2006/03/02/542590.as...
Don't get me wrong: I understand and appreciate your point, but I honestly don't know how most of us using TrueCrypt (e.g. me) are any better off than those who use a proprietary solution. The only difference I can see is any backdoors in TrueCrypt or PGP must be better hidden.
And to be perfectly honest, I'd rather trust the FLOSS crowd who checked TrueCrypt and other more or less popular encryption tools probably hundreds, if not thousands of times than trust the development team of a company refusing to release the source of their software.
[1] Yes, I am kidding, but I hope you catch my drift.
http://www.h-online.com/newsticker/news/item/Debian-package-...
This bug was injected for two years: the damage has been done, with literally over a million of weak keys that pollute the internet. That said, I acknowledge, that the ssl system has (perhaps even more) serious weaknesses beyond the keys themselves. It should have been caught days after commit, and never should have made it into debian stable (and debian has a very slow, thorough release cycle). But telnetd comes to mind, etc. Perhaps only OpenBSD shows consistent true efforts in open source auditing.
They could just type any information in they wanted to, upload a picture, hit print, and the process would mail them a drivers license like everyone else.
I don't have the experience, knowledge, and time (+ effort) to review every source-code line and every theorem used by an encryption application ... to make sure it's not doing something it shouldn't.
And (chances are) you don't either.
So it's not about closed-source or open-source, but rather it's about trust.
And that's my point. How can I trust someone who's unwilling to show me the source of their software and denies me my basic freedoms?
What I am not saying is that Free Software should be blindly trusted - that would be stupid and reckless. What I am saying is that for security[1], proprietary software cannot and must not be trusted, under any circumstances. You cannot even verify what the program you are using does? It's not secure, full stop.
And again, it's a massive difference between hiding a backdoor in a binary blob as opposed to essentially trying to hide it in plain sight. It's possible, but highly unlikely to go unnoticed for a prolonged amount of time. And if it is found, it will probably be fixed pretty much instantly as per Linus' Law.
Finally, corporations and businesses are bound to law for the most part. If they are required (or ordered) to include a backdoor for the FBI or NSA, they will most likely have to oblige. Not so much for Free Software. You essentially cannot force such a backdoor since even if the original maintainers include it, the project will just be forked, and law enforcement - to put it bluntly - can't do shit against it.
[1] And arguably everywhere else, too, but I'd prefer to stay on topic.
http://osxdaily.com/2011/08/10/filevault-2-benchmarks-disk-e...
We've tried it on a Core2Duo Macbook Pro (early 2007) and MacBook (Mid 2010). We've seen lots of OS crashes (Macbook) and general performance issues when running XCode (Macbook Pro).
We're also running virtualization software on the Macs (Parallels and VMWare) - I'm not sure if they're interacting with Filevault 2 (shouldn't be).
Just wonder if anyone else has noticed this.
filevault 2 in lion is true full-disk encryption, and the passphrase must be entered at boot. once it is decrypted, no application should even be able to detect (or rather, care about) the presence of encryption.
https://discussions.apple.com/message/16987224
Though I'd love to hear any reports to the contrary!
> Our calculations confirm that a relatively short series of truly randomly chosen English dictionary words is secure; many people find these somewhat more memorable. Above we used "In the jungle! The mighty Jungle, the lion sleeps tonight!" The important thing is to choose enough words and to choose them in a random un-guessable way, such as by changing the spacing, punctuation, spelling, or capitalization.
The problem with this example is that the 10 words are not chosen independently. Type "in the j" into a google search box and the whole phrase will appear in the drop-down box. So the entropy for the choice of that phrase is about lg2(37^8) or about 42 bits.
So an approximation of the total entropy is:
Choice of source phrase = lg2(37^8) ~= 41.7 bits
Choose one of the 10 suggestions from the drop-down box = lg2(10) ~= 3.3 bits
Permutation of words = lg2(10! / 2! / 3!) ~= 18.2 bits
Spacing (assume each word may independently be precedeed by a space with probability 0.5) =10 bits
Punctuation (each word may be independently followed by '!') = 10 bits
Capitalization: independently choose one of {lowercase, camelcase, uppercase) for each word = lg2(3^10) ~= 15.8 bits
Total so far: 98 bits.
Now consider the third option: a mixture of 16 independently-chosen letters, numbers and symbols. Assume most ASCII characters are available (lets eliminate single quote, backslash and $ which cause problems for some web apps) and we have
lg2(92^16) ~= 104.4 bits, which wins.
Humans are great at remembering phrases, quotes, etc. Think about how widespread referential humor is, where the joke is just a reference to/quote from another work. That's something the brain is great at. Random or semi-random jumbles of letters? Not so much.
• not all SSDs even have hardware compression
• modern workloads have less highly compressible data than in the past: large-media formats include their own compression, and bulk data processing often does its own application-level compress/decompress on store/load
I'd be interested to see any benchmarks that quantify the speed/lifetime hit that whole-disk encryption might cause for SSDs, but my hunch is that the effect would be slight in normal scenarios.
1. http://www.anandtech.com/show/4485/back-to-the-mac-os-x-107-...
sure it's slower but how often do most people really push their disk past 20 MB/s?
Encryption is great but won't save you if they ask for your password (honestly, I'd prefer to give them the password and circumvent using online storage.)
With that in mind - what advice would all you security buffs have on the best way to back up your hard drive to an online disk? Specifically using a basic hosting account as opposed to SAAS or cloud service?
If I do fork out for a service, I would probably rather go with the kind of company that has as their tagline: "Online backups for the truly paranoid", like them.
Pricing's not a killer either.
More than anything else, cpercival earned my trust simply by being honest. There are precious few companies I could say this about.
Does this impose a significant processor load and does that translate to greater power consumption?
http://www.tomshardware.com/reviews/bitlocker-truecrypt-encr...
batteries derate rapidly as the current draw goes up. They are not linear. For my own edification it would be nice to know what kind of energy hit encryption takes on both storage mediums.
For whatever it may be worth, I couldn't find idle power consumption for my notebook's CPU, but it is possible to come up with a worst-case estimate by taking the battery capacity and dividing by the runtime. Apple specifies "up to" 7 hours. While that is of course hard to achieve, I think it's fair to use that figure when looking at idle power use. The battery is 50Wh, so we can figure that the computer as a whole is using at most about 7W when idle. The i7-2677M CPU is specced to use up to 17W all by its lonesome when running flat out, so that's a substantial increase, especially when you take into account the fact that the base 7W idle-ish consumption is for everything in the computer, not just the CPU.
Power stations are built to supply x amount of energy for y time. They aren't like a car engine where switching off the air-con makes a noticeable difference.
This kind of meme gets going because of the campaign to switch appliances off at the wall, thinking it is going to make some type of differences. Every analysis I have ever seen is that (1) the difference is so small it makes no difference and (2) whatever minute drop in demand is found will quickly be used up in industrial users expanding consumption into the lower demand period. Just running one arc-furnace or aluminium smelter for 1 hour longer is going to negate most domestic level fine shavings like switching the TV off at the wall.
Mostly this stuff is promoted to make people feel like they personally are involved and making a difference.
Further, I use Gmail - I have zero expectation of privacy from google.
I also store all my important docs for work and personal on DropBox.
What will I gain from encrypting my laptop? aside from it being stolen/lost - I dont see any added security/benefit from doing this.
I am not trying to be obtuse - but can one explain to me why I would want to do this, other than expressing my tech savvy?
Don't use gmail and don't use dropbox for unencrypted files ;)
But seriously, the risk of your laptop being stolen or lost is a huge incentive for encrypting it. I feel much better knowing that the worst that could happen with my laptop is that i loose it (stolen/lost/dropped). I wouldn't wan't to be uncertain whether anyone had access to my personal files if it got lost and the data I have on it is more valuable than the hardware (and I'm still a student...).
For anyone that is tech savvy I see no reason not to do FDE.
Okay, two exceptions. Loosing TRIM support on SSD-drives and travelling to/from countries that feel they have the right to inspect the content of my laptop and that might frown upon the fact that it is encrypted.
At 10 per second, I feel ok with an 8-10 character numeric passphrase, or a 7-8 character lowercase-only passcode.
I just wish the iPhone had some intelligence about adaptive locking -- lock faster when it's outside my home/car, don't go from unlocked to locked very fast, if at all, if docked in secure places inches from a 9mm. Or pairing with an RF device attached to me, like the Blackberry CAC reader.
On another note, I plan to slowly switch to Ubuntu and I wonder how secure the home folder encryption is?
One other thing to watch out for with SSDs is the "native" AES encryption. From what I've read in many cases it's only there to provide a fast wipe facility and doesn't actually provide protection for data on a lost laptop. Some SSDs (eg Intel 320) provide password protection for the encryption keys via the ATA password, but a bit of reading didn't make me feel too comfortable with how they've implemented it.
If you're confident you're encrypting all your data, then you're still way above average. The nice thing about FDE is that I can "set it and forget it." I don't have to think about which files belong on which partition anymore. It's all safe.
But here's the thing: If you use Linux with dm-crypt, you can set it to pass TRIM commands to the disk. It seems pretty safe, it's only that it will leak information about which blocks are actually used.
LE: Here's how to do it: https://wiki.archlinux.org/index.php/System_Encryption_with_...
2xWestern Digital blue label RAID 0 : 0,65Mb/s (for refrence)
Crucial M4 without FDE : 19,07 Mb/s
Crucial M4 with FDE : 5,59 Mb/s
however the benchmark shows that a SSD is still substantially faster than a classical RAID 0 array
FDE on any type of media causes no slow down if the CPU can encrypt/decrypt at least as fast as the disk can transfer data. It's not correct to say that FDE always causes slow downs.
Technology is only a small part of the solution to warrantless border searches.
My core duo 1.6 GHz laptop gets about 60 MB/s of AES encryption/decryption speeds on battery (which I think reduces the clock to 1 GHz).
I consider the impact negligible.
However if you have an SSD in your system and do full-disk-encryption you will loose potential TRIM-support which can have a significant performance penalty depending on drive.
I wonder whether the dual cores help significantly. (As I'm more inclined to make the P4 the sacrifice.) However, if your observation is that the perceived impact is "negligible", this encourages me that it will be acceptable, if more significant, on the P4.
I hadn't noticed the benchmark utility you describe. I'll have a look for/at it. Thanks!
What would be the best strategy for me to use? Should I just encrypt the home volume using something cross-platform like TrueCrypt, or is it practical (an maintainable) to do full-disk encryption in such an environment?
My home partition has very sensitive data and I've been putting off creating a TrueCrypt container for this data.
Out of personal interest: Did you get Linux to mount the HFS+ partition with R/W access with journaling enabled? I am also curious if you make any progress with encrypting the entire partition.
But I don't run any anti-virus, this is even one of the good reasons why I stopped using windows aeons ago. I tried LUKS with AES a few years ago, and though the performance was good it comes with a really significant hit.
It is possible for "swap" RAM to be encrypted on Linux and it could generate a random per boot key, also being a form of obfuscation. https://lkml.org/lkml/2011/12/28/69
https://help.ubuntu.com/community/EncryptedFilesystems
If you want hibernate to work you can use uswsusp for example: https://we.riseup.net/debian/encrypted-swap
Sleep always works, but as mentioned above, your key will be in memory...
Since the keys/other private info might leak there, you are not doing it right, unless you have sysctl swappness level set to 0.
Not only that, /tmp and other temporary directories might also be another leaky place...
I'm assuming that a corrupted encrypted file is totally unusable here, and now that I think more about it I'm not sure - encryption with chained blocks would mean errors have a larger affect than just at the error site, wouldn't it?
https://grepular.com/Secure_Free_Incremental_and_Instant_Bac...
My laptop HD was encrypted, it got corrupted, and I lost the entire drive. If even a few bytes are corrupted, you are SOL.
Luckily, I had an offsite backup (unencrypted) I'm just warning people about the dangers of not keeping an unecrypted backup.
Don't call that luck. You should be proud of yourself.
I use FDE on my laptop. My backups are also encrypted. I use duplicity which basically tars up the files and then encrypts using GnuPG. It only tars up the changes between each run, so I have incremental backups, and version history of every single file on my system. All encrypted - https://grepular.com/Secure_Free_Incremental_and_Instant_Bac...