Encryption - The security holy grail
With groups like Anonymous actively looking to embarrass your company, laptops thefts occurring every second, and the recent poor US District Court ruling on fifth amendment password protection rights, it is time you actually encrypt your data properly.
Your Windows login password is not encrypting your computer (surprise!). Full-disk encryption (used by very few people) is a good step, but by itself it still will not completely protect your data from prying eyes, overzealous governments, or your own mistake of leaving your company's crown jewels at the local coffee shop.
Instead—as with many successful security designs—you can set up a layered approach to protecting your data with encryption. It's fairly easy, quick, and free.
To create a more complete protection scheme, I am going to walk you through three steps to build this layered security approach:
Step one: Install full-disk encryption
The key to proper encryption is not just the encryption itself, but also protecting the right data. This is why full-disk encryption (FDE) is a popular starting place for many users. You can purchase hard drives with built-in FDE or use software tools like Windows Bitlocker. In either case, your computer can be locked down as soon as it shuts off. If your laptop is stolen, or sold on eBay years later without a proper disk wipe, or even if it finds its way in the government's hands, it will be useless without a password.
If you have Windows 7 Ultimate or Enterprise, a tool called Bitlocker comes preinstalled and can turn your drive into an FDE. For all other systems, I recommend TrueCrypt, available for free at http://www.truecrypt.org/. After downloading and installing, select the Create Volume command and Encrypt the system partition or the entire system drive.
Now follow the instructions and create a strong password. I recommend using a sentence as your password, i.e: This is my password, it rocks!. You won't forget it and it won't crack easily. After your FDE is set up, you will need your password to boot-up the computer. Without the correct password, the drive is left encrypted and worthless even if viewed by forensic tools. Now your computer will be automatically locked down if it is lost or stolen.
However, you aren't finished.
Step two: Create a hidden volume
FDE drives still leave your data and personal information vulnerable in at least two scenarios: 1) You are forced to turn over your password (as in Judge Blackburn's District Court ruling), or 2) Someone has hacked into your live machine and remotely recording your keystrokes/data while you work.
To address these issues, we are also going to put our personal/business files in an encrypted directory—but not using just any encryption scheme. Encryption with hidden volumes is the key to really protecting your information and rights.
Here's a useful analogy for understanding hidden volumes:
Imagine a magic door. If you unlock the door with one key, it opens to a closet full of junk and old boxes. However, if you use a different key, and the door opens to the inside of a bank vault. If you look at the walls surrounding what's behind the door, they look the same size regardless of whether you are opening the closet or the vault . Anyone opening the tiny closet or looking at the structure of the door won't be able to see the giant bank hidden within.
With a correctly implemented hidden volume on your encrypted hard drive, you don't have to worry when someone cracks (or coerces you into giving up) the password. When they use it to open the door, they will only see the closet.
I prefer to use the word "password" for the closet. It's easy to remember and sadly common, and any password-cracking tool will guess it in milliseconds with a simple dictionary attack. Once the closet is open, non-sensitive business files and perhaps a few love letters or copied movies—something that might cause minimum embarrassment—will be revealed. Even to a skilled thief with good forensic tools, the real data, the bank vault, cannot be seen. They have no indication or proof it even exists. For all that person knows, they got your password and opened your encrypted files. In a courtroom setting this is known as "plausible deniability". (Yes, you complied with the court order to give up your password.)
To get started, once again we turn to TrueCrypt to set up a hidden volume file. Open TrueCrypt, select create a volume, create encrypted file container, normal hidden volume. Make sure you create a very large outer layer as this will eventually contain both your closet and bank vault. For a normal "My Documents" folder, I create a 20GB file. Don't forget an easy password for the outer layer—this easy password will be the one that opens the closet.
After it formats, create the hidden volume inside this wrapper with 19 GB and a strong password, leaving 1 GB for your closet. After this hidden volume formats, open the outer layer by mounting and using the simple password. Import some non-sensitive files, photos and random documents. Test your work when you reboot: Use the easy password, and you should see only these non-sensitive files.
Going forward put all your important files in the hidden volume. Unless you leave your FDE and new encrypted My Documents folder open 24/7, your data will remain protected.
Step three: Set up tracking for your computer
One of the downfalls of FDE drives is not being able to hunt down someone who has stolen your computer. Your data is protected, but your actual computer is gone. To be able track someone who steals a locked down computer, install a hidden volume operating system. This is a lot more advanced than the steps above, but if you follow the TrueCrypt instructions you can create two operating systems that open with two different passwords, just like the closet/bank scenario. This alone can be useful for protecting your data for advanced needs or baiting a thief. Create a strong password for your normal operating system and "password" for a second, dummy version of the operating system. Now, on the dummy system install Prey Project's open-source laptop tracking tool. This tool uses Wi-Fi and IP addresses to find your stolen laptop for free.
Now if you computer is stolen A) the thief swaps out the drive and you never see it again, all while your data is protected or B) the thief guesses the password (who wouldn't try the most-commonly used password, "password"), logging into a clean OS with Prey installed allowing you track him down, all while your actual data is still fully protected in the other encrypted OS installation.
The three steps in this layered security approach really are very straightforward. If you have any troubles, more information can be easily found on TrueCrypt's website or Youtube. Just remember if you don't encrypt—and encrypt properly—then your data is not really protected.
CSO (US)
Related articles:
Send us your comments
Comments
security News and Features
embedded_ad
Growth, Agility and New Business Capabilities
Cisco enables the world of many clouds – private, public, and hybrid. We offer a portfolio of cloud services and solutions that uniquely bring together the intelligence of the network, the power of the data center, and the flexibility of applications. The result is a compelling, assured, and consistent user experience with every service delivered from the clouds, anywhere, any time, on any device.
Hong Kong government CIO to form cloud expert group
Datacenters in Hong Kong can never become greener as the local government is lukewarm to the use of renewable energy, said Greenpeace during an interview with Computerworld Hong Kong on Monday...









Wedding Dresses 2011
Bridesmaid Dresses
modest bridesmaid dresses
Bridesmaid Dresses Under 100
.
The initial thing you choose to do is launch early.Not often covered want to help you procrastinate organising a wedding because should you do, you are usually setting all by yourself up meant for failure.Be sure you have the essentials, a store, banquet community hall, dress and additionally tuxedo, food stuff, and several other items arranged well earlier are very important they can be available on your own wedding time.The the next thing you choose to do is to keep organized and possibly the best ways to begin this is using the guidelines.A list will assist you organize your thinking and give them on daily news so are unable to forget them all.Establish offerings to have finished and one after the other complete most of tasks over the list so that you will know you're prepared as soon as your wedding time of day finally goes around (Mon, 2012-02-06 04:24)
Pandora
Pandora Jewelry
cheap Pandora Jewelry
buy Pandora Jewelry
(Sun, 2012-02-05 13:44)
Tiffany Bracelets Store
Tiffany Bracelets Online
cheap Tiffany Bracelets
Tiffany Bracelets On Sale
.This works well after a vacation when any basket provides a holiday design.
Secret #5
Check Auction web sites, sometimes people has received a great gift that that they can't use and want to sell it to shop for something they could use.If you do not get "I need to have that.Auction fever", then some terrific deals are available.Please beware with all the wording regarding Ebay and try to cope with a respected seller.
I trust I've specified you some ideas for finding prime quality discount womens perfume.
For all the time discount perfumes
Buy the best quality perfume your finances will make it easy for.True cologne is around 30 fragrance oil, followed by eau de toilette on 8 and additionally body sprays have got just 1 savings
FREE SHIPPING for any order throughout $59 (Sat, 2012-02-04 13:06)
Audemars Piguet Replica watches
Replica Audemars Piguet Watches for Sale
discount Audemars Piguet watches
Audemars Piguet watches
.
The earliest clocks with movements driven by the power coming from a falling bodyweight had regulations hands nor dial, as well as marked your hours by simply striking a fabulous bell.Ultimately, a face to exhibit the a long time was incorporated, and later on the days were segregated into minutes and a further hands affixed to indicate them.These types of clocks were heavy iron-framed affairs, usually used high in the tower within which the weight had a fantastic distance to travel before it needed rewinding.
Regulation to prevent the unwanted weight crashing down from top to bottom of the actual tower was achieved by a device generally known as a Foliot debt.In this specific, the closing wheel in the train was initially set with a horizontal spindle (Fri, 2012-02-03 23:07)