Re: TrueCrypt mount without TrueCrypt ?

Daniel Pittman <[email protected]> Sat, 20 Mar 2010 22:51:05 +1100
Newsgroups gmane.org.user-groups.slug.chat
Message-ID <[email protected]>
Steffen Schulz <[email protected]> writes:
> On 100320 at 21:45, Daniel Pittman wrote:
>> "Minh Van Le" <[email protected]> writes:
>> 
>> > Can a TrueCrypt volume be mounted on a PC that does not have TrueCrypt
>> > installed ?  I want an encrypted USB flash drive that has its own "auto
>> > extractor (or mount)" mechanism.
>
> Quick Google search yields: http://www.truecrypt.org/docs/?s=truecrypt-portable
>
>
>> Which, in turn, leads me to wonder: how can you trust any system that didn't
>> have a pre-installed secure configuration with this data, but most especially
>> how can you assume it is safe to install the decryption tools on demand?
>
> Why do you assume its about the PC?

Because the question seems to be about having a tool that can be plugged in to
an arbitrary PC, without previous preparation, to provide an "auto extractor
(or mount)" mechanism.

Which, I think, implies that this is about not just "the PC", but "an
arbitrary PC, outside my normal administrative control" — since the later
could presumably be prepared with the drive encryption software through other
channels, and without the requirement for self-extracting.

> Maybe its just about protecting privacy in case of physical theft or loss of
> the USB stick?

*nod*  It could be; my assumption is an assumption.  OTOH, I think it is
reasonably supported.


> (If it indeed is about the PC, buy a USB stick with read-only switch and
> install a bootable r/o Linux on it. It can run from RAM while you switch the
> stick to r/w mode and access your data. Still doesn't protect you from
> hardware gimmicks for sniffing keyboard input, or CCTV.)

*nod*  If I was designing a security system to allow me to access secure data
on an untrusted OS, that would be my preferred approach.

On the other hand, perhaps there is some utility in the approach the OP is
taking which hasn't occurred to me: while I /think/ my logic is sound, and my
conclusion correct, someone could point out something that changes the
position.

(On the gripping hand, I suspect the most likely answer is that the OP
 considers my confluence of factors to be unimportant in the threat model they
 are trying to defend their data against, and consequently don't care. :)

        Daniel
-- 
✣ Daniel Pittman            ✉ [email protected]            ☎ +61 401 155 707
               ♽ made with 100 percent post-consumer electrons
-- 
SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/
Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html