<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Using Just Full Disk Encryption is Not Enough</title>
	<atom:link href="http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/feed" rel="self" type="application/rss+xml" />
	<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption</link>
	<description>Rendering computer investigations irrelevant</description>
	<lastBuildDate>Fri, 05 Mar 2010 05:55:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
	<item>
		<title>By: Timy</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-197</link>
		<dc:creator>Timy</dc:creator>
		<pubDate>Sat, 27 Feb 2010 18:37:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-197</guid>
		<description>I&#039;ve always wondered too, if you use sleep mode, what is stopping them from disconnecting your LAN and plugging it into their own laptop/rogue AP?

I know assigning a static IP would somewhat defer this..however, it could be a true problem.

Also, what if the had a USB-&gt;Ethernet dongle?
After which plugging it in, the OS automatically installs/uses it, and gets a new DHCP lease through it, allowing for our new friends to poke around wherever assuming they can get past your firewall..

So many possibilities!</description>
		<content:encoded><![CDATA[<p>I&#8217;ve always wondered too, if you use sleep mode, what is stopping them from disconnecting your LAN and plugging it into their own laptop/rogue AP?</p>
<p>I know assigning a static IP would somewhat defer this..however, it could be a true problem.</p>
<p>Also, what if the had a USB-&gt;Ethernet dongle?<br />
After which plugging it in, the OS automatically installs/uses it, and gets a new DHCP lease through it, allowing for our new friends to poke around wherever assuming they can get past your firewall..</p>
<p>So many possibilities!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dubanks</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-168</link>
		<dc:creator>dubanks</dc:creator>
		<pubDate>Tue, 29 Dec 2009 05:28:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-168</guid>
		<description>Hello
Nice article.
Say I have a 8G flash drive, If I encrypt entire drive then it comes up as unformatted drive in windows. So someone might just format the whole darn thing.
What I would like to do is to be able to disguise this 8G drive as 4G drive and the remaining 4G should remain invisible to unsuspecting user. Using TC I should be able to detect the hidden partition. For noraml windows it should appear like a 4G drive.
Is it possible? TIA</description>
		<content:encoded><![CDATA[<p>Hello<br />
Nice article.<br />
Say I have a 8G flash drive, If I encrypt entire drive then it comes up as unformatted drive in windows. So someone might just format the whole darn thing.<br />
What I would like to do is to be able to disguise this 8G drive as 4G drive and the remaining 4G should remain invisible to unsuspecting user. Using TC I should be able to detect the hidden partition. For noraml windows it should appear like a 4G drive.<br />
Is it possible? TIA</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-122</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Fri, 08 May 2009 08:29:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-122</guid>
		<description>Nice post - really like the keyfile tip in the comments as well.  Double layers of security like this are vital (or if your keyfile is on a biometric USB drive, triple layers!)

&lt;a href=&quot;http://www.peopleperhour.com/quotes/freelance/Programming&quot; rel=&quot;nofollow&quot;&gt;Freelance programmer&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>Nice post &#8211; really like the keyfile tip in the comments as well.  Double layers of security like this are vital (or if your keyfile is on a biometric USB drive, triple layers!)</p>
<p><a href="http://www.peopleperhour.com/quotes/freelance/Programming">Freelance programmer</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JOJO</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-79</link>
		<dc:creator>JOJO</dc:creator>
		<pubDate>Tue, 21 Apr 2009 20:43:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-79</guid>
		<description>How can I WHOLE-DISK encrypt a hard-drive with a dual-boot situation ? (IE: Linux/Windows) Anyway?</description>
		<content:encoded><![CDATA[<p>How can I WHOLE-DISK encrypt a hard-drive with a dual-boot situation ? (IE: Linux/Windows) Anyway?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-56</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Sat, 28 Mar 2009 14:16:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-56</guid>
		<description>You can completely circumvent the impact of keyloggers by using they XP on-screen keyboard to type your password.

This can be found at Start/Programs/Accessories/Accessibility.

If you find it too time consuming to do it this way you can just type a portion of it this way. Just make sure it&#039;s always the same portion so they can never record that missing fragment with the logger.</description>
		<content:encoded><![CDATA[<p>You can completely circumvent the impact of keyloggers by using they XP on-screen keyboard to type your password.</p>
<p>This can be found at Start/Programs/Accessories/Accessibility.</p>
<p>If you find it too time consuming to do it this way you can just type a portion of it this way. Just make sure it&#8217;s always the same portion so they can never record that missing fragment with the logger.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-32</link>
		<dc:creator>Yar</dc:creator>
		<pubDate>Tue, 17 Mar 2009 21:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-32</guid>
		<description>All great tips. Especially about updating software and disabling services you don&#039;t need.

I do not use TrueCrypt volumes with a keyfile as I know I&#039;m just going lose it ;) but very good tip.</description>
		<content:encoded><![CDATA[<p>All great tips. Especially about updating software and disabling services you don&#8217;t need.</p>
<p>I do not use TrueCrypt volumes with a keyfile as I know I&#8217;m just going lose it <img src='http://www.anti-forensics.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  but very good tip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Doe</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-27</link>
		<dc:creator>John Doe</dc:creator>
		<pubDate>Tue, 17 Mar 2009 19:19:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-27</guid>
		<description>Don&#039;t forget to be logged in as user and not as admin. This creates another security layer since it might affect some rootkits and viruses from installing correctly.

For Truecrypt it might be a smart move to use a keyfile besides a strong password. Then an attacker needs to get hold of both your password and keyfile.

Watch out for Mantech&#039;s MDD, it can make a complete memory dump. Might reveal keys, passwords of Truecrypt (did not have time to test this). Will discover Windows hashes for sure. See a nice article on:
http://taosecurity.blogspot.com/2009/03/using-forensic-tools-offensively.html Offensively</description>
		<content:encoded><![CDATA[<p>Don&#8217;t forget to be logged in as user and not as admin. This creates another security layer since it might affect some rootkits and viruses from installing correctly.</p>
<p>For Truecrypt it might be a smart move to use a keyfile besides a strong password. Then an attacker needs to get hold of both your password and keyfile.</p>
<p>Watch out for Mantech&#8217;s MDD, it can make a complete memory dump. Might reveal keys, passwords of Truecrypt (did not have time to test this). Will discover Windows hashes for sure. See a nice article on:<br />
<a href="http://taosecurity.blogspot.com/2009/03/using-forensic-tools-offensively.html">http://taosecurity.blogspot.com/2009/03/using-forensic-tools-offensively.html</a> Offensively</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: m0rebel</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-24</link>
		<dc:creator>m0rebel</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:59:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-24</guid>
		<description>Great post! I also want to add, update your system and all your software! So many Windows users seem to not prioritize updates, but that&#039;s the #1 way people end up hacking your computer. There&#039;s always a new Windows file sharing bug, or web browser bug, or Flash player bug, or PDF reader bug, and the only way to be much safer is to promptly install updates.

And speaking of Windows file sharing: only have it enabled if you have a really good reason for it, and make sure that only authorized people are allowed to view your shares. It doesn&#039;t matter if your disk is encrypted if you&#039;re sharing your documents with others over the network.</description>
		<content:encoded><![CDATA[<p>Great post! I also want to add, update your system and all your software! So many Windows users seem to not prioritize updates, but that&#8217;s the #1 way people end up hacking your computer. There&#8217;s always a new Windows file sharing bug, or web browser bug, or Flash player bug, or PDF reader bug, and the only way to be much safer is to promptly install updates.</p>
<p>And speaking of Windows file sharing: only have it enabled if you have a really good reason for it, and make sure that only authorized people are allowed to view your shares. It doesn&#8217;t matter if your disk is encrypted if you&#8217;re sharing your documents with others over the network.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yar</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-20</link>
		<dc:creator>Yar</dc:creator>
		<pubDate>Fri, 13 Mar 2009 16:20:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-20</guid>
		<description>hiddenillusion, great article at diablohorn. I did leave out having a secure passphrase. I myself use at least a 15 character passphrase on all encrypted volumes and disks.

The best you can do is to make a long passphrase, substitute letters in it for numbers and symbols. Then at the end, beginning or maybe between words add symbol combinations that are easy to remember. This will make for a very difficult password to brute.</description>
		<content:encoded><![CDATA[<p>hiddenillusion, great article at diablohorn. I did leave out having a secure passphrase. I myself use at least a 15 character passphrase on all encrypted volumes and disks.</p>
<p>The best you can do is to make a long passphrase, substitute letters in it for numbers and symbols. Then at the end, beginning or maybe between words add symbol combinations that are easy to remember. This will make for a very difficult password to brute.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: hiddenillusion</title>
		<link>http://www.anti-forensics.com/youre-still-not-safe-using-just-full-disk-encryption/comment-page-1#comment-19</link>
		<dc:creator>hiddenillusion</dc:creator>
		<pubDate>Fri, 13 Mar 2009 15:49:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.anti-forensics.com/?p=240#comment-19</guid>
		<description>interesting article, I see you post a lot about Truecrypt, might want to check this out to go along with your articles.

http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/</description>
		<content:encoded><![CDATA[<p>interesting article, I see you post a lot about Truecrypt, might want to check this out to go along with your articles.</p>
<p><a href="http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/">http://diablohorn.wordpress.com/2009/01/01/truecrypt-variety-of-bruteforcing-options/</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
