Re: TrueCrypt mount without TrueCrypt ?

Daniel Pittman <[email protected]> Sat, 20 Mar 2010 21:26:27 +1100
Newsgroups gmane.org.user-groups.slug.chat
Message-ID <[email protected]>
"Minh Van Le" <[email protected]> writes:

> Can a TrueCrypt volume be mounted on a PC that does not have TrueCrypt
> installed ?  I want an encrypted USB flash drive that has its own "auto
> extractor (or mount)" mechanism.

I don't know the answer to your question, I fear.  I am interested, though, to
understand what threat you are going to defend yourself against with this
arrangement?


It seems to me that this, especially from a single vendor source, is an
invitation to lose your data almost immediately.

My attack model is pretty simple; I assume:

1. If someone bothers to encrypt the content then they must consider it of
   some value.

2. At least some of the people will actually be correct in their assessment of
   value, and won't just be crypto geeks encrypting everything for fun.

3. Software from a single, major vendor like TrueCrypt can be identified by
   the OS, and will be reasonably standard.

4. Emulating, violating, or otherwise intercepting authentication to that
   software should be reasonably possible; certainly, on Win32 and Linux this
   shouldn't be a hugely difficult task as they are generally not secure
   enough to prevent such attacks.

5. Intercepting access to the now-decrypted data should be reasonably
   possible, and there are a wide range of channels available that can be
   undetectably exploited to this end.


At that point I think that it is reasonable to conclude that an attacker who
can deliver hostile software to the system can capture the authentication
information, or access the files after authentication, without too much
trouble.

At that stage you only need an attack vector; I suggest that the widespread
"botnet" infections that have been proved to steal data including address
books, financial data, and "any data, to hold hostage", would be sufficient.


Which, in turn, leads me to wonder: how can you trust any system that didn't
have a pre-installed secure configuration with this data, but most especially
how can you assume it is safe to install the decryption tools on demand?

        Daniel
-- 
✣ Daniel Pittman            ✉ [email protected]            ☎ +61 401 155 707
               ♽ made with 100 percent post-consumer electrons
-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html