best full disk encryption for storage drive

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Guest
Please note that I do not have expirience with this. Few things which I know I just read from searching about it.

As I understand, some disk encryptions are vulnerable because, for example, it can be still accessed by cold boot attack. Thats just one method which I read about while searching. Who knows how much more of them is there.

So, is there any encription that protects against all of that possible attacks? From ANYONE, not just mid-ranged hacker or my girlfriend trying to break to desktop 😀 , but even expert with forensic knoweledge and equipment.

That would require strong encryption method, and absence of vulnerabilities like that one mentioned above, and similar.

If there is not ideal solution, that just suggest me the best one out there (which would make attacker's life as harder as possible).

Also, is there one with, or is there a way to implement it, feature like some lockdown, to erase all or make disk unusable permanetly, after some failed password attempts. To protect against brute force attack.

tnx!
 
AFAIK, there isn't. Just steps you could take to improve your security, but even then they're not guaranteed by any means to guarantee protection from intrusion or hacking. You could use bitlocker if you're using a version of windows that supports it, along with a TPM module installed on you motherboard. You could use a vpn, and maybe choose an encrypted flash drive eg the Apricorn Aegis Secure FIPS Validated Key 32 GB USB 2.0 256-bit AES-CBC Encrypted Flash Drive, ironkey, etc.

There are also external drives that offer the same encryption. You won't find a worthy solution that isn't pricey if you go with the latter. Though, even then, in the end even if you use a password manager, or take further steps, in the end for most there is no guarantee that your system is absolutely safe from intrusion, or "private". Even the largest corporations, govts, aren't immune to the issues your post seeks to resolve.
 
Can you name any of such external drives that come with encryption? I mean, that pricey versions, which you consider worthy.

Why would it be breakable if it use some really strong encryption, and have lockdown against brute force attack?

When you say there is no guarantee that system is safe from intrusion or it is not private fully, do you mean some attacks through internet? Or you think if drive falls physically into hands of someone who is determined and equiped to try to hack into it?
 
I just made quick search for Apricorn Aegis Secure flash drive. As I can see it states 256-bit AES.

I can see item description states "Drive reset feature destroys data and allows redeployment of drive". But how it destroys data? Like simple deleting (which actually don't permanetly delete data) or something like zero-fill? I ask because if someone is determine to access, can take out memory chip from usb flash drive, and if is able to access it, that he can recover that data if it is not permanetly deleted.

I can also see that it have numeric keys on flash drive. Does it prevent brute force, or at least, software brute force? It would take really hard time to brute force it by typing every time guessed password by fingers :) . Again, if chip can be removed from flash drive, and accessed by software, to bypass numeric keys, that it would be exposed to brute force attack, right?

And, can you run OS from such flash drive? in that case, I suppose, it should have good 4K random write and read speeds. Is that the case?
 


Apricorn, Fantom Drives, also make external drives, numeric access, various features, pricey. Feel free to go on Amazon or Newegg and check them out. When I say there is no guarantee one's system is "private" I mean just that. Privacy in today's industrialized world exists for the very few. As to your other question, I'm unsure as to the various methods, even some of the terminology I've no idea of. You'd likely do better asking your queries at the forum over at black hat or as similar.
 
I had made contact today with company and discussed about technical details and security of flash drive.

Thay claim is :
- they do not know any case of breaking into that flash drive which uses 256-bit AES.
- they can't open locked drive on request, nor have any backdoor.
- it have brute force protection (you can adjust 4 - 20 failed attempts, than it will wipe out and lock).
- it can run OS from flash drive (I later looked into datasheed and it claim 4K random read and write speed both to be 10mb/sec. is it enough to run OS ?? )


Pity I do not have email now to copy answer, but as I understand and remember when we discussed about brute force security lockdown, and how data is really deleted, they claim something about encryption key and wiping / deleting data "like it is done on OPAL drive" (somethink like that, sorry I can't quote it identically).

What is OPAL drive?

As I understand from their claim, it would be imposible to recover any data after lockdown. I wonder, is it completely erased like, for example, when you do zero-fill with Parted Magic secury erase?


If all that claims are right, and if that can run OS (at least not creepy), and data is impossible to recover after lockdown, than it is drive to go.

But as I do not have any advanced knowledge about it, any opinions here from more educated members is appreciated 😉