You are not logged in.
Hi Guys,
This might be a stupid question, but...
I read the wiki entry on TrueCrypt (http://wiki.archlinux.org/index.php/TrueCrypt). I'm assuming the use-case for TrueCrypt would be if someone management to get hold of the hard-disk, the contents would be encrypted, so they stil couldn't be read?
However the tutorial mentions you can add the mount procedure to your startup scripts so it will auto-mount if the machine is rebooted.
My question is; if someone has your hard disk (say they plugged it in as a second drive on their laptop, which they did have root access to); wouldn't they be able to read the startup script file and then they would know the password to decrypt the fs?
Am I missing something..? :S
--Solved--
Last edited by tommed (2010-06-04 09:13:57)
Offline
that is true, but if your password is actually a keyfile, and that keyfile is stored on a usb, whenever you boot up with the usb connected, you can automout your encrypted volume.
this is also a matter of comfort vs security, since if you believe your machine can be compromised, you can remove it from begin auto mounted or leave it when you know your system is currently safe.
Offline
Ah good point about the usb device.. I knew I hadn't thought it all through completely!
Many Thanks!
Offline