- encrypted swap using random key on each boot
- encrypted /tmp using random key on each boot
- encrypted disk partition for sensitive data
On the other hand, I didn't find any formal analysis of BestCrypt either. But it also doesn't have any published weaknesses. It is a commercial piece of software, not very expensive, with two bonus features:
- hidden encrypted containers, and
- encrypted containers are readable on Win32.
Ah yes, my threat model, and why have I decided now to use disk encryption? Soon I'm going to travel around with my laptop and I don't want my work and personal data available to strangers if it gets stolen. So I'm moving all of my mails, work and private stuff to the encrypted partition. And all of the dot-files in my home directory. It's surprising how much data can be found there.
7 comments:
You should try Truecrypt, IMO the best encryption program on Windows and as a bonus it is free and open source.
http://www.truecrypt.org/
Nice advertisement. Oh, and I don't use windows for 99% of the time. Therefore, Truecrypt is pretty much useless to me.
The Linux version of TrueCrypt is available at http://www.truecrypt.org/downloads.php
:)
I don't like when someone starts to claim that some product is "the best", especially without stating their evaluation criteria.
"Best" is meaningless without true understanding of other people's needs. Since these needs are different, consequently, "best" does not exist.
Talking about best product is like talking about best religion...
the article has been updated, bestcrypt and truecrypt are also vulnerable to watermark attacks.
Thanks for the notice.
I use BestCrypt already for many years. As far as my knowledge goes, I can assure you that Bestcrypt is one of the best encryption programs I can think of. Used in Linux offcourse. There is only one con and that is that you have to install your kernel sources to be able to install BestCrypt. Another thing is that Jetico asks you to pay for the Linux version, but actually you are free to pay for it or not. The Linux version does not have a serial number check. I did pay for it but you can try it out fully featured for as long as you like.
My advise: use the Rijendael algorithm.
Friends of mine (and they have the gear to hack encrypted stuff) have tried to hack the containers, but no go.
and another nice thing about BestCrypt is that you can make hidden containers inside the original container. Used with different passphrases.
This is not ment als an add. I am just very enthousiastic about BestCrypt.
Have fun!
Post a Comment