>>> - Encypting your Entire Hard Drive with Truecrypt (Mac and Windows)
Do people recommend this method, or is Apple's built-in full disk encryption sufficient?
>>> - Encypting your Entire Hard Drive with Truecrypt (Mac and Windows)
Do people recommend this method, or is Apple's built-in full disk encryption sufficient?
Obviously you need to make sure you have a good backup scheme in place, and escrow the decryption key somewhere (ideally, printed).
There are some functionality advantages to Truecrypt (deniable volumes, etc.), but Filevault is pretty good. I'd feel equally comfortable with either one. (I'd prefer OPEL, the drive encryption on-controller, for performance reasons, but Mac OS X doesn't support that.)
Once you do that, you have a lot of other things to worry about before "which widely accepted disk crypto package should I use for FDE" becomes the biggest question.
When available, OSX makes use of the hardware AES-NI capabilities of the CPU though.
Any experiences to share? Anything positive/negative /etc? Would appreciate comments, esp on compatibility with non-Mac devices.
Thanks!
"Many eyes make bugs shallow".
And of course someone has read the source, someone wrote it. But the number of eyes on the code would be more than closed source.
There may be other ways...
'Unlocking FileVault': http://www.youtube.com/watch?v=doGzuOYCNJE
I knocked Apple a bit for security issues 2006-2009, but they've made a serious effort to fix things starting sometime in 2010 or 2011. I mean, iOS and the iPhone platform is probably one of the most secure mobile OSes now (RIM edges it out, but RIM sucks). OS X has added other security features as well, starting with 10.6.
You mean, like every device with PCI slot or FireWire port? It's hardly just Apple that provides DMA.
Rooting Windows doesn't take too long either, and to get data (the real reason to root a device) it's not like it's necessary. Just pull the HD and plug it into another machine - you already have physical access. Physical access == game over, unless you have good encryption, and the kind of machine or OS makes no difference.
The FileVault issues are a good point, though I don't know what changes have occurred since full-disk encryption came out with 10.7. VileFault's attack vector readme lists DMA (true on any DMA device, though easier on some) and reading unencrypted data to look for passwords - only DMA seems viable with full disk encryption.
pmset -a destroyfvkeyonstandby 1 hibernatemode 25
That command will disable light suspend mode. When the lid is closed, the laptop will hibernate, writing its memory to disk (encrypted) and power off, clearing the encryption key from memory.