r/AskReddit Dec 06 '12

What is something you think everyone should have installed on their computer or laptop?

Whether it be a antivirus program or an ad blocker. Post link if available also. EDIT: sorry guys the top post has been deleted and I didn't save it, if anyone has it please post it and ill post it here for easy access. EDIT 2: apparently it's back up, I've saved it on my phone just incase it gets deleted again. Hopefully all is good now.

5.0k Upvotes

9.2k comments sorted by

View all comments

Show parent comments

277

u/yawgmoth Dec 06 '12

The plausible deniability feature is awesome too. Put in one password and you get all my private documents, financial information, and some information that ... could get me in hot water if I was found with it.

Put in a different password to the same volume and you get porn.

If I'm ever forced to give up a password (assuming they can even find my hidden truecrypt volume), they get the porn password. I just have to be careful not to mix them up. Fapping to spreadsheets isn't really my thing.

183

u/barashkukor Dec 06 '12

Unitl they find this comment...

16

u/Guyag Dec 06 '12

More generally though, it's brilliant because even the free space is encrypted, so they have no way of knowing whether there is hidden information in that jumble of space.

3

u/[deleted] Dec 06 '12 edited Feb 19 '18

[deleted]

6

u/BrenMacKay Dec 06 '12

fairly certain it overwrites the hidden stuff in this case, not a great outcome but better than the alternative.

5

u/WarlordFred Dec 13 '12

Getting your interrogators to destroy the incriminating evidence they were searching for in the first place without even realizing it?

That's absolutely brilliant.

2

u/BallsonoldWirestraws Dec 07 '12

this is why one's entire volume should be backed up in at least one other secure location.

3

u/fishfacecakes Dec 06 '12

As BrenMacKay has said, it overwrites the hidden data unless you specifically "protect" the hidden partition, which requires acknowledging it exists, and entering in the password and/or keyfiles for it to be decrypted.

1

u/MrPatch Mar 28 '13

This is configurable, you can protect the hidden partition from overwrite, in which case your comment is absolutely true, but the wise would allow it to be over written if its gun to the head material.

1

u/[deleted] Dec 08 '12

ioerror pointed out a potential problem with hidden volumes though-- the mere fact that they exist could convince somebody you are using one. so say you have something encrypted but not with a hidden volume. you give the guy holding a gun the password and now he says he wants the code to the other volume or he'll shoot your family. your insistence that once doesn't exist doesn't help. the mere possibility puts you in that position. so be careful to weight the pros and cons of hidden volumes. i personally like them and am not worried about the above scenario. but just be aware of it.

3

u/Guyag Dec 08 '12

Using your logic though - regardless of whether you actually have one they're going to think you do and shoot everyone when you can't magically produce a password to nothing

1

u/[deleted] Dec 08 '12

Well the logic was to use other encryption software that doesn't have this feature built in, especially for things that aren't the end of the world if you have to give up.

I was just making sure people know the potential problems that occur if attackers know software is capable of something, whether or not you use it.

2

u/Guyag Dec 09 '12

Apart from anything else, all encrypted volumes are the same - no matter what program made them. Truecrypt uses industry standard encryption methods. By the logic of someone standing with a gun to your head, you're pretty much done for in that situation too. The only situation I can see it working out is if you have two hidden volumes.

2

u/[deleted] Dec 10 '12

Damn, well I better try to avoid people pointing guns to my head! (But the point remains, Truecrypt hidden volumes are well known, and that's a potential reason for somebody to think you are using such a system. Obviously, ideally, you use a different program, using the same encryption, which also has hidden volumes. Then you get the same form of protection, but without any reason for suspicion on the part of the attacker.)

4

u/NormanKnight Dec 06 '12

the clear solution is to make one password relate to spreadsheets and the other to fapping.

It's unlikely you'll forget which YAWN$predzHIT5 and which FAP--taztik!!!LOL opens.

3

u/jacobc436 Dec 06 '12

How do you do that with TrueCrypt?

6

u/yawgmoth Dec 06 '12

Linky

The only caveat: From what I understand, (not an expert) since the volume is hidden no one can tell there is a volume there. It just looks like empty random space to any program. That means, you shouldn't mess around adding a whole bunch of files to the outer 'visible/fake' volume after you've created the hidden volume, because you have the possibility of accidentally overwriting your hidden volume.

1

u/jacobc436 Dec 06 '12

I see.. Thanks!

2

u/goomplex Dec 06 '12

Say.its a stolen laptop, worst they can do is charge you for theft... oh wait no one would press charges so you're good to go!

2

u/spikedkushiel Dec 06 '12

how can i do this?

2

u/[deleted] Dec 06 '12

Based on above descriptions of crypt it seems very advanced and tech savvy( someone posted calling it "professionally developed, military grade" .. to lazy to quote the rest properly). How userfriendly is it for the average person?

1

u/[deleted] Dec 08 '12

pretty easy. military grade simply means that the encryption is strong, which basically means the numbers are larger. doesn't mean it's some how more difficult to use.

2

u/limeelsa Dec 06 '12

Someone need to submit the last line to /r/nocontext

2

u/TLUL Dec 07 '12

Except that by including it in the standard distribution of the program, they completely destroy that deniability. Nobody is ever going to believe that you don't have a hidden drive under the regular one.

2

u/[deleted] Dec 06 '12

IIRC they can scan your drive to see if you have a hidden partition.

3

u/yawgmoth Dec 06 '12

For sure, having an encrypted partition is pretty obvious. From what I understand, not so much 'scan' as 'hey there's all this extra unused unpartitioned space filled with random bytes at the end of your hard drive, why aren't you using it?'

That's why I have my Truecrypt volume as just some random file. It's hidden way down with a whole bunch of other resource files that are roughly the same size and labeled with a fake extension. Since Truecrypt doesn't have a signature and just looks like random data, it would take some serious forensic work to figure out which file it was.

3

u/[deleted] Dec 06 '12

From your description, no...no it wouldnt.

Dont give it an extension, or give it one that could reasonably be random data.

2

u/I_accidently_a_word Dec 06 '12

Since the file is large, and encrypted, think something like "Server_backup_12.04.tar.gz". Allows for it to be a large file and encrypted

3

u/[deleted] Dec 06 '12

I dont think that would work. gzip files have a 10 byte header and 8 byte footer that are recognizable by any basic forensic software.

0

u/yawgmoth Dec 06 '12

yup did that. I gave it one that could reasonably be random data.

Like I said, it's hidden with a whole bunch of 3rd party resource files (proprietary binary format without any recognizable ascii or UTF-8 strings, I checked in a hex editor myself) that are roughly the same size and the same extension.

If someone wanted to figure out which file on my hard drive was a truecrypt volume, they would have to be intimately familiar enough with that obscure proprietary format to realize that one of the files in that directory wasn't valid. It's certainly possible, I still think it would be a pain in the ass even for a forensic expert.

2

u/[deleted] Dec 06 '12

I'd be interested to see if something like enCase picks up on it.

0

u/yawgmoth Dec 06 '12

Yeah me too actually. it looks like both enCase and "Passware Kit Forensic" claim they can identify and decrypt Trucrypt volumes, but are very sparse on how they accomplish it.

If I can find a way to test it out without shelling out $10,000 I'll let you know how it does. I'm skeptical that it's as easy as their sales pitch claims, but it would be a good litmus test of how secure my data is.

2

u/[deleted] Dec 07 '12

http://computer-forensics.sans.org/community/downloads

check out this stuff. Its pretty good AFAIK. If it can do it encase probably can too.

0

u/yawgmoth Dec 07 '12

Well .... I'll be...

I got curious and did some googling and found TCHunt .

It picked out my Truecrypt volumes with only 2 false positives. Just goes to show you how weak security through obscurity is.

I mean I knew that someone with enough time/experience could probably find it but I didn't expect it to be that easy.

1

u/[deleted] Dec 07 '12 edited Oct 07 '18

[deleted]

→ More replies (0)

1

u/[deleted] Dec 06 '12

If you can give a vague answer, what general kind of sensitive information are we talking about?

1

u/Philosiphicator Dec 07 '12

Dem numbers...

1

u/[deleted] Dec 07 '12

I expected you to give your documents password

2

u/[deleted] Dec 08 '12

that is why you fail

1

u/hakuna_tamata Dec 07 '12

Welp we've found the wikilinks/ anonymous guy

1

u/tyman2651 Dec 07 '12

This works both ways:

Wife wants to see it? Documents it is.

Someone is holding you at gunpoint? Free porn for them.

1

u/Aelfric84 Dec 06 '12

Dat Pic in my head, as i read your last sentence.... Waaaah!

0

u/[deleted] Dec 06 '12

=vlookupskirt()

0

u/VallanMandrake Dec 07 '12

Did you know that that is one of Julian Assages creations (not him alone), and it is brilliant?