Re: TrueCrypt mount without TrueCrypt ?
Steffen Schulz <[email protected]> Sun, 21 Mar 2010 00:27:04 +1100
| Newsgroups | gmane.org.user-groups.slug.chat |
|---|---|
| Message-ID | <[email protected]> |
On 100320 at 23:00, Daniel Pittman wrote: > Steffen Schulz <[email protected]> writes: > > Why do you assume its about the PC? > > Which, I think, implies that this is about not just "the PC", but "an > arbitrary PC, outside my normal administrative control" — since the later > could presumably be prepared with the drive encryption software through other > channels, and without the requirement for self-extracting. True. However, a random PC of a friend or the company PC are valid targets for this kind of usage. The idea might simply be to have some level of privacy. Targeted attacks are something different. > On the other hand, perhaps there is some utility in the approach the OP is > taking which hasn't occurred to me: while I /think/ my logic is sound, and my > conclusion correct, someone could point out something that changes the > position. Unlikely :-) Even if TrueCrypt itself is not compromised in the way you described a possible attack, merely accessing the data on a compromised platform will expose it. Theoretically you could use Trusted Computing infrastructure to prevent a compromised machine from spoofing a secure user interface and prompting you to access your encrypted data. But we'll probably never get this far.. /steffen -- SLUG - Sydney Linux User Group Mailing List - http://slug.org.au/ Subscription info and FAQs: http://slug.org.au/faq/mailinglists.html