Re: Stealth crypto

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi Michael,

On 04/15/2006 07:02 AM, Michael Garibaldi wrote:
| 3. Jari Ruusu's (or documented by him?) cryptoloop

Jari is the author of loop-aes.

| Now to my actual problem. I want to crypt my entire hard disks. No,
| not every partition of them, but everything, including the MBR (I
| intend to boot from USB). This option is not even mentioned in the

Follow the instructions in Jari's readme:

http://loop-aes.sourceforge.net/loop-AES.README

for encrypted root. That can be extended for the entire disk if you boot from
CDROM or USB using the entire disk /dev/sda for instance.

1. Follow the instructions to created an encrypted root partition that boots
from your USB or CDROM.
2. Boot knoppix, mount that partition, back it up to another machine temporarily.
3. Shred the drive
4. Set up loop-aes using the entire HD, then untar the install.
5. Ensure that you have an initrd where the CRYPTROOT is the entire disk, then
~ you can boot the entire drive.

Alternativey you can just use Knoppix and store your transient data alone on
the entire HD.

Sorry the above are general instructions, but if you can follow Jari's
instructions to create a fully encrypted /dev/sda1 then you can easily take
the above hint and use it on the entire HD.

Jari has also posted to this list about how to reference a portion of the disk
without a parition table:

http://mail.nl.linux.org/linux-crypto/2005-04/msg00001.html

Cheers,

- ---Venkat.

- --
http://rayservers.com/       skype: rayservers       +1-607-546-7300
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFEQSYxWdkW/RJDBSIRAlaLAJ95s9UWH9iwHU9NiR6yptu4KFmUfACffvAu
iRQi/oFbVtDjxoDPrbmyDUQ=
=/LaB
-----END PGP SIGNATURE-----

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/


[Index of Archives]     [Kernel]     [Linux Crypto]     [Gnu Crypto]     [Gnu Classpath]     [Netfilter]     [Bugtraq]
  Powered by Linux