You found me…
Posts tagged truecrypt
EvilMaid versus Full Disk Encryption (TrueCrypt & PGP)
Oct 16th
The Evil Maid Attack is an attack type against whole system disk encryption in a form of a small bootable USB stick image that allows to perform the attack in an easy “plug-and-play” way. The whole infection process takes about 1 minute, and it’s well suited to be used by hotel maids.
The Invisible Things blog goes into great detail on how most whole disk encryption is vulnerable in a relatively simple way. The scenario we consider is when somebody left an encrypted laptop e.g. in a hotel room. Let’s assume the laptop uses full disk encryption like e.g. this provided by TrueCrypt or PGP Whole Disk Encryption. Many people believe, including some well known security experts, that it is advisable to fully power down your laptop when you use full disk encryption in order to prevent attacks via FireWire/PCMCIA or ”Coldboot” attacks. So, let’s assume we have a reasonably paranoid user, that uses a full disk encryption on his or her laptop, and also powers it down every time they leave it alone in a hotel room, or somewhere else.
Now, this is where our Evil Maid stick comes into play. All the attacker needs to do is to sneak into the user’s hotel room and boot the laptop from the Evil Maid USB Stick. After some 1-2 minutes, the target laptop’s gets infected with Evil Maid Sniffer that will record the disk encryption passphrase when the user enters it next time. As any smart user might have guessed already, this part is ideally suited to be performed by hotel maids, or people pretending to be them.
So, after our victim gets back to the hotel room and powers up his or her laptop, the passphrase will be recorded and e.g. stored somewhere on the disk, or maybe transmitted over the network (not implemented in current version).
Now we can safely steal/confiscate the user’s laptop, as we know how to decrypt it. End of story.
15+ Must-Have Thumb Drive Apps for Geeks
Jan 2nd
A portable app is a computer program that you can carry around with you on a portable device and use on any Windows computer. When your USB flash drive, portable hard drive, iPod or other portable device is plugged in, you have access to your software and personal data just as you would on your own PC. And when you unplug the device, none of your personal data is left behind!
I personally have a large memory card on my Windows Mobile phone… so I can use something that I always have with me anyway as a way to carry around software. Pretty handy…
So let’s start with the mac daddy, the PortableApps Suite:
PortableApps.com Suite™ is a complete collection of portable apps including a web browser, email client, office suite, calendar/scheduler, instant messaging client, antivirus, audio player, sudoku game, password manager, PDF reader, minesweeper clone, backup utility and integrated menu, all preconfigured to work portably. Just drop it on your portable device and you’re ready to go.
All versions of the PortableApps.com Suite include the integrated PortableApps.com Menu (pictured at right) and the PortableApps.com Backup utility along with a set of custom icons, an autoplay configuration, folders and a quick start shortcut. In addition, the packages include:

Mozilla Firefox, Portable Edition (web browser)
Mozilla Thunderbird, Portable Edition (email)
Mozilla Sunbird, Portable Edition (calendar/tasks)
ClamWin Portable (antivirus)
Pidgin Portable (instant messaging)
Sumatra PDF Portable (PDF reader
KeePass Password Safe Portable (password manager)
Sudoku Portable (game)
Mines-Perfect Portable (game)
CoolPlayer+ Portable (audio player)
OpenOffice.org Portable* (office suite)
- Writer (word processor)
- Calc (spreadsheet)
- Impress (presentations)
- Base (database utility)
- Draw (drawing)
*Note: The Light Suite includes
AbiWord Portable (word processor) instead of OpenOffice.org Portable.
Portable apps doesn’t have it all… so let’s look at some of the rest:
Most other portable software can be found at PortableFreeware. While most people can get away with the PortableApps Suite there are a few things missing that I consider crucial to your portable arsenal.
- Truecrypt - TrueCrypt creates virtual encrypted disks within a file and mount them as a real disk. It supports a full range of encryption algorithms, including AES-256, which is used within the government for information as high up as Top Secret classification.
- NotePad++ – Notepad++ is one of the few source code text editors that supports folding. In addition, it features multi-language syntax highlighting, auto-completion, regular expression search/replace, macro recording and playback etc. This is my preferred FREE text editor, it’s fast, light, and easy to use. And let’s face it… how often do you really need a full blown Word Processor when on the run. If you’ll need one, plan ahead and take your laptop!
- CCleaner – CCleaner is a system optimization and privacy tool. It removes unused files from your system and cleans traces of your online activities such as your Internet history. Additionally, and most importantly to me, it contains a fully featured registry cleaner.
- uTorrent – µTorrent is a small BitTorrent client that uses very little system resources. This is my favorite BitTorrent client for the desktop, and while I wouldn’t suggest you run it full time from a portable USB device it could be handy in a pinch if you needed to grab something that requires a torrent download.
- Foxit Reader Portable – Ok look, PDF’s suck. I hate them… seriously. More than that I hate Acrobat Reader since it’s a huge bloated application that takes forever to launch even on a fully modern PC. Having said that, there’s a LOT of PDF’s out there. Enter Foxt Reader which is a small and fast PDF viewer that is compatible with PDF Standard 1.6. Don’t think you’re limited to only the portable version, there is also a desktop version… ditch Acrobat for good!
- 7-Zip – Oddly absent from the portableApps Suite is a compression utility. 7-Zip is a file archiver that supports just about every compression format you can think of.
- FileZilla – A really good portable FTP client.
Just a note that most all of these portable apps can be integrated right into the PortableApps suite menu. The PortableApps.com Menu can automatically add apps in PortableApps.com Format. Just download the file you’d like to add (like FileZilla Portable, for instance). Then, in PortableApps.com Menu, click Options – Add a New App – Install and then select the FileZilla Portable .paf.exe file you just downloaded. The PortableApps.com Menu will automatically install it to the proper location for you.
