<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Using Just Full Disk Encryption is Not Enough</title>
	<atom:link href="http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Wed, 01 Sep 2010 22:00:29 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: albert</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-264</link>
		<dc:creator>albert</dc:creator>
		<pubDate>Mon, 12 Jul 2010 09:01:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-264</guid>
		<description>other very good esential software are: superantispyware / spyware doctor / trojan remover and kaspersky virus removal tool.
for prevent malicius code in autorun from pendrives, mp3, mp4, phones, ipod, etc. I use mx one, usb doctor or sokx pro.
ofcourse also is a good choice disable autorun in you desktop pc, netbook, notebook, etc.</description>
		<content:encoded><![CDATA[<p>other very good esential software are: superantispyware / spyware doctor / trojan remover and kaspersky virus removal tool.<br />
for prevent malicius code in autorun from pendrives, mp3, mp4, phones, ipod, etc. I use mx one, usb doctor or sokx pro.<br />
ofcourse also is a good choice disable autorun in you desktop pc, netbook, notebook, etc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Max (Admin)</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-249</link>
		<dc:creator>Max (Admin)</dc:creator>
		<pubDate>Sat, 12 Jun 2010 01:09:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-249</guid>
		<description>&lt;blockquote&gt;What do you mean “bomb threat”? No need for that type of language at all, I mean what the **** are you even mentioning that for???? We’re not even talking about hiding illegal activity, don’t you think that language is a bit rash and disrespectful to people who have been killed by bombs?&lt;/blockquote&gt;

Not really, nope, and are you on medication yet for being far too sensitive?</description>
		<content:encoded><![CDATA[<blockquote><p>What do you mean “bomb threat”? No need for that type of language at all, I mean what the **** are you even mentioning that for???? We’re not even talking about hiding illegal activity, don’t you think that language is a bit rash and disrespectful to people who have been killed by bombs?</p></blockquote>
<p>Not really, nope, and are you on medication yet for being far too sensitive?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Padraig</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-248</link>
		<dc:creator>Padraig</dc:creator>
		<pubDate>Fri, 11 Jun 2010 13:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-248</guid>
		<description>What do you mean &quot;bomb threat&quot;? No need for that type of language at all, I mean what the **** are you even mentioning that for???? We&#039;re not even talking about hiding illegal activity, don&#039;t you think that language is a bit rash and disrespectful to people who have been killed by bombs?</description>
		<content:encoded><![CDATA[<p>What do you mean &#8220;bomb threat&#8221;? No need for that type of language at all, I mean what the **** are you even mentioning that for???? We&#8217;re not even talking about hiding illegal activity, don&#8217;t you think that language is a bit rash and disrespectful to people who have been killed by bombs?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: storm</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-215</link>
		<dc:creator>storm</dc:creator>
		<pubDate>Fri, 09 Apr 2010 18:28:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-215</guid>
		<description>Dear illegal visitor,

can you tell me how did you assign a batch file to your laptop key? I&#039;m looking for workarounds but no info at all.</description>
		<content:encoded><![CDATA[<p>Dear illegal visitor,</p>
<p>can you tell me how did you assign a batch file to your laptop key? I&#8217;m looking for workarounds but no info at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: illegal visitor</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-214</link>
		<dc:creator>illegal visitor</dc:creator>
		<pubDate>Wed, 07 Apr 2010 12:08:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-214</guid>
		<description>Hi there,

Good article! I am playing around with TC as well and know the risks we still face. I am wondering about the ram copy issue. I do own a laptop with 1 GB of RAM, suppose I am working on it and they seize my laptop. Would it be adequate to let the machine reboot so the ram is cleared and overwritten? Not sure how much chance there is that my encryption key resides in the memory after a reboot. It would halt however on the truecrypt pw screen so there might not be a lot of memory overwritten.

I wrote a little batchfile btw to make things more difficult :) I did bind it to an unused laptop key. When I press that key my screen is instantly locked, after a 2 second delay my TC volumes are forcefully dismounted and the laptop will proceed to reboot.

Batchfile content:

@ECHO OFF
BREAK=OFF 

rundll32.exe user32.dll, LockWorkStation

&quot;C:\TC\Sleep.exe&quot; 2

&quot;C:\Program Files\TrueCrypt\TrueCrypt.exe&quot; /q /d /f

&quot;C:\TC\Sleep.exe&quot; 2

shutdown -f -r

EXIT</description>
		<content:encoded><![CDATA[<p>Hi there,</p>
<p>Good article! I am playing around with TC as well and know the risks we still face. I am wondering about the ram copy issue. I do own a laptop with 1 GB of RAM, suppose I am working on it and they seize my laptop. Would it be adequate to let the machine reboot so the ram is cleared and overwritten? Not sure how much chance there is that my encryption key resides in the memory after a reboot. It would halt however on the truecrypt pw screen so there might not be a lot of memory overwritten.</p>
<p>I wrote a little batchfile btw to make things more difficult <img src='http://www.anti-forensics.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  I did bind it to an unused laptop key. When I press that key my screen is instantly locked, after a 2 second delay my TC volumes are forcefully dismounted and the laptop will proceed to reboot.</p>
<p>Batchfile content:</p>
<p>@ECHO OFF<br />
BREAK=OFF </p>
<p>rundll32.exe user32.dll, LockWorkStation</p>
<p>&#8220;C:\TC\Sleep.exe&#8221; 2</p>
<p>&#8220;C:\Program Files\TrueCrypt\TrueCrypt.exe&#8221; /q /d /f</p>
<p>&#8220;C:\TC\Sleep.exe&#8221; 2</p>
<p>shutdown -f -r</p>
<p>EXIT</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Timy</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-197</link>
		<dc:creator>Timy</dc:creator>
		<pubDate>Sat, 27 Feb 2010 18:37:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-197</guid>
		<description>I&#039;ve always wondered too, if you use sleep mode, what is stopping them from disconnecting your LAN and plugging it into their own laptop/rogue AP?

I know assigning a static IP would somewhat defer this..however, it could be a true problem.

Also, what if the had a USB-&gt;Ethernet dongle?
After which plugging it in, the OS automatically installs/uses it, and gets a new DHCP lease through it, allowing for our new friends to poke around wherever assuming they can get past your firewall..

So many possibilities!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve always wondered too, if you use sleep mode, what is stopping them from disconnecting your LAN and plugging it into their own laptop/rogue AP?</p>
<p>I know assigning a static IP would somewhat defer this..however, it could be a true problem.</p>
<p>Also, what if the had a USB-&gt;Ethernet dongle?<br />
After which plugging it in, the OS automatically installs/uses it, and gets a new DHCP lease through it, allowing for our new friends to poke around wherever assuming they can get past your firewall..</p>
<p>So many possibilities!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dubanks</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-168</link>
		<dc:creator>dubanks</dc:creator>
		<pubDate>Tue, 29 Dec 2009 05:28:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-168</guid>
		<description>Hello
Nice article.
Say I have a 8G flash drive, If I encrypt entire drive then it comes up as unformatted drive in windows. So someone might just format the whole darn thing.
What I would like to do is to be able to disguise this 8G drive as 4G drive and the remaining 4G should remain invisible to unsuspecting user. Using TC I should be able to detect the hidden partition. For noraml windows it should appear like a 4G drive.
Is it possible? TIA</description>
		<content:encoded><![CDATA[<p>Hello<br />
Nice article.<br />
Say I have a 8G flash drive, If I encrypt entire drive then it comes up as unformatted drive in windows. So someone might just format the whole darn thing.<br />
What I would like to do is to be able to disguise this 8G drive as 4G drive and the remaining 4G should remain invisible to unsuspecting user. Using TC I should be able to detect the hidden partition. For noraml windows it should appear like a 4G drive.<br />
Is it possible? TIA</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-122</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Fri, 08 May 2009 08:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-122</guid>
		<description>Nice post - really like the keyfile tip in the comments as well.  Double layers of security like this are vital (or if your keyfile is on a biometric USB drive, triple layers!)

&lt;a href=&quot;http://www.peopleperhour.com/quotes/freelance/Programming&quot; rel=&quot;nofollow&quot;&gt;Freelance programmer&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Nice post &#8211; really like the keyfile tip in the comments as well.  Double layers of security like this are vital (or if your keyfile is on a biometric USB drive, triple layers!)</p>
<p><a href="http://www.peopleperhour.com/quotes/freelance/Programming">Freelance programmer</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JOJO</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-79</link>
		<dc:creator>JOJO</dc:creator>
		<pubDate>Tue, 21 Apr 2009 20:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-79</guid>
		<description>How can I WHOLE-DISK encrypt a hard-drive with a dual-boot situation ? (IE: Linux/Windows) Anyway?</description>
		<content:encoded><![CDATA[<p>How can I WHOLE-DISK encrypt a hard-drive with a dual-boot situation ? (IE: Linux/Windows) Anyway?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-56</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 28 Mar 2009 14:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-56</guid>
		<description>You can completely circumvent the impact of keyloggers by using they XP on-screen keyboard to type your password.

This can be found at Start/Programs/Accessories/Accessibility.

If you find it too time consuming to do it this way you can just type a portion of it this way. Just make sure it&#039;s always the same portion so they can never record that missing fragment with the logger.</description>
		<content:encoded><![CDATA[<p>You can completely circumvent the impact of keyloggers by using they XP on-screen keyboard to type your password.</p>
<p>This can be found at Start/Programs/Accessories/Accessibility.</p>
<p>If you find it too time consuming to do it this way you can just type a portion of it this way. Just make sure it&#8217;s always the same portion so they can never record that missing fragment with the logger.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
