Ask Leo!

TrueCrypt - Free Open Source Industrial Strength Encryption

Home » Recommendations » Software

Summary: TrueCrypt provides a solution for encrypting sensitive data - everything from portable, mountable volumes to entire hard disks.

TrueCrypt comes up frequently in Ask Leo! answers. Many people are concerned about things like privacy, identity and data theft, particularly on computers or on portable devices where they might not always have total physical control of the media.

Someone might gain access to sensitive data stored on your computer.

Encrypting your data renders that access useless, even when your computer or your thumbdrive falls into the wrong hands.

And TrueCrypt makes it not only easy, but nearly un-crackable.

There are two approaches to using TrueCrypt:

  • Whole Drive Encryption - you can use TrueCrypt to encrypt your entire hard disk, including the partition you boot from. In order to boot the machine, you must first supply your pass phrase to enable decryption. Once booted, data is automatically and transparently encrypted and decrypted as it travels to and from the disk. Once your machine is turned off, the data is unrecoverable without knowing the pass phrase.

  • Container Encryption - with this approach you create a single file on your computer's hard drive that is encrypted. You then "mount" that file using TrueCrypt, supplying the correct pass-phrase to decrypt it after which the contents of that file appear as another drive on your system. Reading from and writing to that "drive" automatically and transparently decrypts and encrypts the data. Once the drive is unmounted, the data is once again unrecoverable without knowing the pass phrase.

"Data encryption is an important part of an overall security strategy. TrueCrypt can be a key part of that strategy."

It's both simple and elegant.

I tend to prefer container based encryption for its portability, and for the fact that you need only mount the encrypted drive when you need access. I keep a bunch of my personal information in a TrueCrypt container that I regularly copy between machines, onto a thumbdrive, and I even back it up to the internet. When I need the data thereon, I simply mount it, specify my pass phrase to unlock it, and use the files that are stored within it however I need. In my case, I keep spreadsheets, public and private keys, documents, and even my Roboform password database on it, all securely encrypted when not in use.

TrueCrypt is not tied to any one platform, your user account or anything else; just the pass phrase. In fact, you can copy your encrypted file to another machine entirely and mount it with TrueCrypt. Even using other operating systems such as Mac or Linux.

I do have to throw out a couple of important caveats:

  • Encryption does not make a bad pass phrase any more secure. If you choose an obvious pass phrase, an attack can certainly be mounted that could unlock your encrypted volume. This is why we talk about pass phrase instead of password. Use a multi-word phrase that you can remember to be the key to your encrypted data, and it'll be much, much more difficult to break.

  • An encrypted volume does you no good if the files you care about are also elsewhere on your machine.

  • That being said, make sure you have secure backups, updated regularly. Preferably keep them UNencrypted, but secure in some other way, in case you lose your encrypted volume or forget your pass phrase. If you've chosen a good passphrase, without it the data is not recoverable.

Data encryption is an important part of an overall security strategy. TrueCrypt can be a key part of that strategy.

I recommend it.

Related:

Article 12553 | Posted July 13, 2008

Recent Comments
2 Comments

Excellent article. Guide to follow.

Posted by: Shankar at September 12, 2008 9:49 PM

A nice article. I've been using TrueCrypt for a while now, here's where I heard about it the first time, and I have to say it works very well. They now also include a feature called Encrypt System Partition/Drive... which encrypts your system drive/partition so it can't be booted without the passphrase. They even have (like hidden volumes) hidden systems, of which the existence (if all guidelines are followed) will be impossible to prove. For more information, refer to their website.

Posted by: Mike at November 1, 2008 1:56 PM

Post a comment on "TrueCrypt - Free Open Source Industrial Strength Encryption":






(Email Address will not be published.)

Remember Me?

By popular demand...
my tip jar
Cuppa Joe
Buy Leo a Latte!

(you may use HTML tags for style)

New!

RSS feed Subscribe to the RSS Feed specifically for comments on this article.

Before commenting, please...

Please wait. Your comment is being processed ...


Ask Your Question:


ask-leo.com
Web

Stay Informed

Weekly Newsletter

Archives

By Category
By Date

Advertisers

Advertise on Ask Leo!

««   »»

Question? - Ask Leo!
Who is Leo?
Link to Leo!

Terms, Conditions & Privacy