Re: TrueCrypt mount without TrueCrypt ?
Daniel Pittman <[email protected]> Sat, 20 Mar 2010 21:26:27 +1100
| Newsgroups | gmane.org.user-groups.slug.chat |
|---|---|
| Message-ID | <[email protected]> |
"Minh Van Le" <[email protected]> writes: > Can a TrueCrypt volume be mounted on a PC that does not have TrueCrypt > installed ? I want an encrypted USB flash drive that has its own "auto > extractor (or mount)" mechanism. I don't know the answer to your question, I fear. I am interested, though, to understand what threat you are going to defend yourself against with this arrangement? It seems to me that this, especially from a single vendor source, is an invitation to lose your data almost immediately. My attack model is pretty simple; I assume: 1. If someone bothers to encrypt the content then they must consider it of some value. 2. At least some of the people will actually be correct in their assessment of value, and won't just be crypto geeks encrypting everything for fun. 3. Software from a single, major vendor like TrueCrypt can be identified by the OS, and will be reasonably standard. 4. Emulating, violating, or otherwise intercepting authentication to that software should be reasonably possible; certainly, on Win32 and Linux this shouldn't be a hugely difficult task as they are generally not secure enough to prevent such attacks. 5. Intercepting access to the now-decrypted data should be reasonably possible, and there are a wide range of channels available that can be undetectably exploited to this end. At that point I think that it is reasonable to conclude that an attacker who can deliver hostile software to the system can capture the authentication information, or access the files after authentication, without too much trouble. At that stage you only need an attack vector; I suggest that the widespread "botnet" infections that have been proved to steal data including address books, financial data, and "any data, to hold hostage", would be sufficient. Which, in turn, leads me to wonder: how can you trust any system that didn't have a pre-installed secure configuration with this data, but most especially how can you assume it is safe to install the decryption tools on demand? Daniel -- ✣ Daniel Pittman ✉ [email protected] ☎ +61 401 155 707 ♽ made with 100 percent post-consumer electrons -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html