Encrypted Volumes for Linux and Windows?
share_it asks: "On my Win PC I used a lot of encryption: I had encrypted small files for personal stuff, encrypted virtual disks for programs, music, video, etc. I used PGPdisk and mounted 3 big virtual disks (for a total of 170 gigs) on startup with just one single passphrase and those 'disks' were even quite fast. I have now switched to GNU-Linux for most of my interests, but sometimes I have to use Windows and I want my data to be encrypted and accessible from both OSes The only software that I found which can mount the same encrypted disk on both platforms is BestCript, but from Linux I can't store file with long names. Is there a better way to share encrypted data between when I dual-boot?"
yeah. EFS for linsux? there is no working LVM, 2.4 is barely useable from marcelo, 2.6 hasnt converged well, and EXT3 is completely half assed when compared to say, UFS+logging. cant wait until even MORE of you get fired for messing shit up in production using toys in production.
cart before the horse, you disgusting communists.
SHUT THE FUCK UP!
Thank you and go kill yourself, tool.
I know this is highly offtopic, but I just had to say it.
I just saw a freakin' FLASH banner ad on Slashdot. A FLASH banner for Christ's sake. Where are we going next?
I am a faggot slut.
want my data to be encrypted and accessible from both OSes The only software that I found which can mount the same encrypted disk on both platforms is BestCript, but from Linux I can't store file[s] with long names. Is there a better way to share encrypted data between when I dual-boot?
I understand you want it uh, instantly "to hand" regardless of the OS you boot, but for the love of god, why do you need long names for your porn files?
I mean, I mean, isn't "dnkymdgt.mpg" just as emotional moving as "donkey makes sweet, sweet love to gay midget.mpeg"?
Length isn't everything, man.
Opinions on the Twiddler2 hand-held keyboard?
The reason why could suggest a solution.
another nonsensical ad-hominem retort by an intellectually malnourished individual who seeks only to spread vitriol and not bring any technical truth to the table.
Those who disagree with Mister Linux Script Kiddie should be cast into the outer darkness, should be shunned, should starve? Sin is good for the soul? We can change the truth if we don't like it the way it is? These are all claims made recently by Mister Linux Script Kiddie. One of my objectives is to prescribe a course of action.
The worst kinds of atrabilious bottom-feeders there are serve as the priests in his cult of vindictive McCarthyism. These "priests" spend their days basking in Mister Linux Script Kiddie's reflected glory, pausing only when Mister Linux Script Kiddie instructs them to make us less united, less moral, less sensitive, less engaged, and more perversely puerile. What could be more officious? The complete answer to that question is a long, sad story. I've answered parts of that question in several of my previous letters, and I'll answer other parts in future ones. For now, I'll just say that it's sincerely a tragedy that his goal in life is apparently to rot our minds with the hallucinatory drug of totalitarianism. Here, I use the word "tragedy" as the philosopher Whitehead used it. Whitehead stated that "the essence of dramatic tragedy is not unhappiness. It resides in the solemnity of the remorseless working of things," which I interpret as saying that Mister Linux Script Kiddie's comrades often reverse the normal process of interpretation. That is, they value the unsaid over the said, the obscure over the clear. Even if one isn't completely conversant with current events, the evidence overwhelmingly indicates that even when the facts don't fit, Mister Linux Script Kiddie sometimes tries to use them anyway. He still maintains, for instance, that he has a duty to conceal the facts and lie to the rest of us, under oath if necessary, perjuring himself to help disseminate the True Faith of cronyism. I hope it will not disappoint you to learn that I have begged his vicegerents to step forth and tell Mister Linux Script Kiddie what we all think of him -- and boy, do I have some choice words I'd like to use. To date, not a single soul has agreed to help in this fashion. Are they worried about how Mister Linux Script Kiddie might retaliate? Well, while you're deliberating over that, let me ask you another question: How can someone who claims to be so educated and so open-minded dare to denigrate and discard all of Western culture? Now, not to bombard you with too many questions, but if you're the type who dares to think for yourself, then you've probably already determined that all of the anxious sighing, longing, and hoping of Mister Linux Script Kiddie's heart is directed to a time when juvenile vulgarians can incite pogroms, purges, and other mayhem. I'll probably devote a separate letter to that topic alone, but for now, I'll simply summarize by stating that as a concerned citizen, I will forge ahead in my brave quest to speak out against behavior and speech that is intended to contaminate or cut off our cities' water supply. Let's remember that. Mister Linux Script Kiddie has announced his intentions to take credit for others' accomplishments. While doing so may earn Mister Linux Script Kiddie a gold star from the mush-for-brains propagandism crowd, when I'm through with him, he'll think twice before attempting to force me to stampede into the abattoir.
Although Rop has moved on to other projects, Secure Notebook was a pretty good idea. The software may still be useful (documentation here, check the page for file signatures.)
IIRC, this was a secure-ified Debian with encrypted swap, encrypted partitions, running VMWare which ran Win2K as a guest o/s. The idea was to run Windows while treating it as a small child that keeps burning itself on the stove. Everything was filtered thru the Linux host o/s, including network and hardware access.
Also, I believe the encryption key was provided in two parts: a dongle containing part of the key, and then also a key requested of the user during boot.
Worth a look.
Big Daddy, Johnny, Burp, Aunt Zelda, Scott, Slurp, Big Momma
I have been around the crypto block a time or two and unless i completely missed it, I don't think there is a solution for what the poster is looking for other then bestcrypt.
I was once where the poster is, encrypting all my partitions including swap with a USB token required for boot. it was a nice excercise in orwellian paranoia and i learned a lot, but it is completely impractical and a total pain in the ass.
best of luck to the poster in his quest for ultimate, um, security.
Revolutions are never about freedom or justice. They're about who's going to be top dog. -- Kilgore Trout
mod the bastard down, but he is right.
I would also be paranoid as hell about my usb token. You ever consider copying it and storing one in a safe deposit box?
Photos.
First, you don't need the OS encrypted. The most you'll need is /var, /tmp, /home and swap (and /data or wherever you put your bulk data files). So, that takes care of having to get the OS to boot off an encrypted volume. /home and /data from windows. So, when you boot windows, fire up a virtual host program (either vmware, or a free alternative) to boot a linux kernel / mini distribution, which then mounts & exports /home and /data via samba, then use the virtual network connection to mount those volumes from windows.
Now, to make things easy, you probably will only need to access
Of course, in windows, you never know where it may leave temp files laying around, so you might want to encrypt the entire win volume using a seperate utility.
Just pulling a solution out of my arse. Have a fileserver on the network (unix of some kind), sharing files via Samba. Create an IPSEC tunnel and access the shares.
Man watching 6 MSCE's around a sun box, looks alot like the opening scene's of 2001:space odyssey...
1. STFW
2. Drop Linux, it's useless for any practical purposes (and if it's useful now and then, use colinux)
3. In your nice Windows(TM) machine, use SafeBoot; it's a $20 quite decent and flawless full disk encryption
4. If you want to have virtual encypted disks, there's a myriad of options, one of them is DriveCrypt.
5. Piss off.
I have been using BestCrypt for several years and it's great. Unfortunately it's the only solid product available on Linux and Windows that I know of.
Why can't you store long filenames on Linux? BestCrypt just provides a block device on which you can use any filesystem. FAT32/VFAT is fine for Linux-Windows work. I've formatted a Bestcrypt volume with fat, vfat, iso9660, ext2, ext3, reiserfs, all without any problem.
Another alternative is to use VMware and then use ext3 on Bestcrypt and serve Windows needs with Samba.
Continuing the offtopic thread....
;) ) and voila there your images appear
Disable loading of images by default which is the best thing to do
and when you get to a page where you need to view the images, just press 'g' (without quotes
That you can enable this per-tab is an extremely good option in Opera. In IE and Firefox enabling/disabling images seem to get applied to all windows/tabs which is quite annoying to say the least. I guess there'd be some plugin available for both those browsers but needless to say people like me would be too lazy to search for things
Well, I'm not sure if this is a mirror or the primary, but anyway check this out: Munitions - cryptographic software for Linux.
At home w/ SuSE I use cryptofs, but if you don't have SuSe here's something else that looks pretty good (And I think OpenBSD has this one too)-- CFS. I think there are actually a lot of options out there for you, just look around through Google.
I'm using BestCrypt with my container file on a 256Meg USB Pen Drive. Format the container as FAT32 and you can mount it on both W2k, XP or Linux.
Grab the evaluation versions and give it a whirl.
http://www.jetico.com/
what do you need ?
how about a file e.g. tar/zip of all your files that is encrypted each time you login/logout ?
use a standard AES/DES and secure deletion
whats wrong with this ?
slow
unsecure if power fails
but with everthing else you are at vendors mercy
I would use PGP disk or a secure online file server...
regards
John Jones
Ho ho!
And of course you wont be cleaning much spyware off their PC if they don't use IE either!
Sam
blog.sam.liddicott.com
how about having a file server with linux and which ever encryption you like, serving the files over nfs and samba ?
I've seen flash banner ads for well over a year now.
and how do you know where that few byte file is on a 10GB partition? If a filesystem is placed on an encrypted block device, you have no idea. It all looks like random shit.
If she asked nicely, would you turn her down?