Safe: Free Easy File System Encryption
getsafe.org
getsafe.org
Second: The 'Learn more' presentation actually says nothing, nevermind that the start page is equally uninformative. Not a single word about techniques used or what makes this service supposedly 'safe' or why I should trust it with my data.
I am highly suspicious of anything claiming to be "safe" or "secure", expecially when it is this dodgy around details. I'd not advise anyone to actually use this for anything sensitive.
EDIT: Just noticed the tiny light-grey 'About' link at the bottom, which gives a little more info. Still, I absolutely dislike the site design.
i designed the splash page to be very sparse because i wanted to minimize distractions and make it simple to just get started using the app. i figure most people don't like reading as much as they like looking at pictures.
for those who like to read (and have a discerning eye) the "about" link has all the gory details you're looking for.
it was a trade-off and there definitely could be a better result but this is what developed in the end. the splash page may change as more feedback rolls in.
1) No animations. Just get rid of them all.
2) Put a link on the 'Learn More' page that takes you back to the homepage. The 'Learn More' page only contains a link to the download page, no way to click back to homepage.
3) 6 click throughs to read 6 sentences on the About page is annoying. I don't need a single sentence stretched out across an HD screen (feels like I have to take a few steps back to read the massive text without panning my entire head left and right). Have all 6 of those on one long page instead.
4) I didn't even notice the tiny links on the front page at the far bottom left (probably because of how gigantic everything else is). Make those links more prominent and maybe also have those links as part of the footer of every page. The http://www.getsafe.org/about is especially useful and contains most of what I wanted to see.
https://defuse.ca/audits/encfs.htm https://defuse.ca/audits/ecryptfs.htm
Truecrypt is a different beast (acts as the basis blob or blockdev for a file system) and has done significantly better on more rigorous audits: https://opencryptoaudit.org/reports/
If the above (grand-parent) is the worst tptacek says about encfs, I would argue that you are in decent shape.
This "auditability" seems to me a strength worth nurturing.
[0] Where "by-and-by" refers to the usual superhuman app-sec standards in which "10 hours" translate into actual, meaningful work.
* CBC - Cipher block chaining: https://en.wikipedia.org/wiki/Cipher_block_chaining#Cipher-b...
* CFB - Cipher feedback: https://en.wikipedia.org/wiki/Block_cipher_modes_of_operatio...
As evinced by the structural similarity of the diagrams in the pages above, the two are very similar; hence tptacek's characterisation of their combination in encfs as "weird", I presume.
* XTS - "XEX-based tweaked-codebook mode with ciphertext stealing": https://en.wikipedia.org/wiki/XEX-TCB-CTS#XEX-based_tweaked-...
I have to more or less hope this is the encryption mode referenced above. NIST recommends an AES cipher to employ with it.
Resolving all acronyms here seems futile (albeit entertaining), thus I will simply rest.
(This is my last unsolicited reply in this thread, I promise.)
Which is begging the question, naturally.
edit: To wit, whether an alternative exists that would satisfy the encfs use case.
Actual issues when I gave it a try: 1) Unmounting the safe is possible but there's no easy way to remount the Safe 2) All the filenames are obfuscated (good and bad). Abilities to search for files, view thumbnails etc., usual filesystem functionalities are affected.
I think it's quite early but it is an intriguing project. Like others, I would love to learn more about the folks behind it as well as the product details.
I wrote a little bit about data security, especially cloud data security a while back: http://vuongnguyen.com/personal-business-cloud-security.html if anyone is interested in my humble opinion.
-V.
In this case, wouldn't you lose plausible deniability? If I remember there's a feature in TrueCrypt which allows you to have two passwords, a fake password that you could use if questioned that decrypts a portion of the volume, and the real password that decrypts the entire thing. I maybe conflating two separate things, though.
Safe is mainly for making it difficult for casual snoopers to view your data. For instance, if your computer or external hard drive gets stolen.
Safe and TrueCrypt form an ecosystem of encryption tools. Safe is a bit more user-friendly but it's for casual use. For special circumstances TrueCrypt is a better tool. Compare butter knife to swiss army knife.
Edit: I found this after installing the app: http://www.getsafe.org/about it has a bit more detail.
I used this many years ago to build a Mac app with the exact same functionality, and probably much safer encryption: http://excesapp.com/
-encryption [AES-128|AES-256]
As of 10.7, the default algorithm is the AES cipher running in CBC mode
on 512-byte blocks with a 128-bit key.
--Not sure why I'm being downvoted for sharing this. Go figure, HN can be mean sometimes.
The website at getsafe.org has very, very little info for a crypto app. I understand the need to keep the pitch simple for casual users. But the website needs a link to much more detailed info for those of us who know some things about security.
Other options for FUSE-ish things on Windows are CBFS and Dokan.
If you don't care about cross-platform or open-source then encrypted sparse bundles are great!