Re: Are computer forensics people as stupid as they seem?



ass@xxxxxxxxxxxxxx wrote:

I've actually devised a system by which you can use OTFE without
anyone knowing it's actually being used. Meaning you have a fully
functional operating system and all the space on the drive is occupied
by benign unencrypted data. Yet the drive still harbors an encrypted
operating system and encrypted partitions that cannot be detected by
any forensic techniques. It's fairly trivial to set up. Gold star to
anyone who can tell me how to do this. I call it OTFE+.

You didn't do it. :)

It's a physical impossibility to store data of any type on a drive
outside the specifications of that drive. IOW, bits and bytes written
to a drive within the cyl/head/sectors/etc geometry of the drive
itself.

That being fact, any place you write your "hidden" encrypted data to
must be protected from being overwritten. The "unused" portions of the
drive (cluster slack?) must be locked, which means an easily detected
locking mechanism and/or "stale file syndrome". Or, your data is in
constant peril of being completely lost when a single bit of your
"hidden" content gets overwritten by normal, unencrypted operations
like booting the machine and generating a boot log. ;).

We've "been there discussed that" in this group several times now. The
consensus is that "stenographic" drive or volume encryption is mostly
snake oil in principal.

.



Relevant Pages

  • Re: Are computer forensics people as stupid as they seem?
    ... functional operating system and all the space on the drive is occupied ... by benign unencrypted data. ... install DCPP, encrypt, make a hidden OS, encrypt, create a DCPP ...
    (alt.privacy)
  • Re: Are computer forensics people as stupid as they seem?
    ... A far more effective way is encryption, ... Full OTFE, on the other hand, while it does have its own "something ... functional operating system and all the space on the drive is occupied ... people using this technique and not posting how they do it, ...
    (alt.privacy)
  • Re: help !!encrypted files?
    ... >>NTFS is not easy to get around. ... > computer Operating System. ... It provides encryption good enough for top government level ... > home user needs that is above me. ...
    (microsoft.public.windowsxp.general)
  • Re: protecting a folder
    ... You don't mention the operating system but there is no native way to ... password protect folders. ... allow only authorized user accounts to access the folder within the ... Encryption has it's own hazards and many encryption programs use a ...
    (microsoft.public.security)
  • Re: Controversial paper - Good response article on ZDNet
    ... Designing in security is good. ... If say 95% of the world uses a given operating system there ... such an encryption method? ...
    (sci.crypt)