Skip to content or view screen version

Many new encryption packages insecure

Crypt watch | 04.03.2008 11:30 | Repression | Technology

Passwords remain in memory - problems with TrueCrypt and FileVault.

This is vital for all to know:-

 http://facthai.wordpress.com/2008/02/27/most-encryption-insecure-afp/


and

 http://www.eff.org/press/archives/2008/02/21-0

Don't get caught out!

Crypt watch

Comments

Hide the following 4 comments

The true value of TrueCrypt

04.03.2008 17:06

This trick only affects machines left screen-locked or in sleep or hibernation mode, and it is a lab technique not an operational police technique.. If you can pull the power before getting arrested then it isn't applicable. If you leave your machine protected by a screen saver then you are already fucked anyway.

"We almost recommended TrueCrypt which works on several platforms. However, in light of this research, only Pretty Good Privacy (PGP) by Philip Zimmerman gets our nod, especially if you’re travelling"

PGP is the best encryption publically available but current draconian laws punish you for failing to reveal the key and the files are identifiable. A cheap and cheerful workaround is to encrypt a file using PGP and then dump that inside a TrueCrypt folder inside another TrueCrypt folder. The law can still force you to open the first folder, but they cannot identify a folder within a folder and so cannot force you to admit to even the existence of any other nestled files, let alone their key. So you are reasonably safe from both criminals and police alike.

Danny


PGP by zimmerman is bollocks

04.03.2008 21:30

"However, in light of this research, only Pretty Good Privacy (PGP) by Philip Zimmerman gets our nod, especially if you’re travelling""

what a bullshit. Zimmerman's PGP is closed source and nobody knows how exactly it works. nobody who has a glimpse of understanding what security means recommends that.

that you "have to give the key to you data" is a MYTH. NOBODY, i repeat NOBODY has to help to generate eveidence against him/herself. the law often quoted targets witnesses and clarifies that giving the key to evidence is enforced, the same as they HAVE to give evidence as witnesses.

some


Erm...

05.03.2008 23:44

The source code for the PGP algorithm is available online though? There are plenty of open source versions of it if you need it... and Mr Z did release the original source code.

Western Animal Rights Network
mail e-mail: info@animalliberation.co.uk
- Homepage: http://www.animalliberation.co.uk


every time a bell rings, an angel gets his wings

06.03.2008 18:47

"NOBODY, i repeat NOBODY has to help to generate eveidence against him/herself"

Yeah, read this and weep . The fact is there is no fifth addmentment to the UK consitution that allows us to stay silent - we don't even have a written constitution so everything they do is 'legal'. It's not democracy, it is not justice, but it is reality. First they came for the animal rights activists..

IMCista [Enter stage left ]:"Now everyone use TOR all the time..."

 http://www.theregister.co.uk/2007/11/14/ripa_encryption_key_notice/
Animal rights activist hit with RIPA key decrypt demand
"The woman, who claims to have not used encryption, relates her experiences in an anonymous posting on Indymedia."

Danny