How to encrypt & protect your portable data, on a USB HDD or memory stick

SilverNodashi

Expert Member
Joined
Oct 12, 2007
Messages
3,340
Reaction score
49
Location
Johannesburg, South Africa
I often travel with work, and most of the times I carry a portable USB HDD (in my case I have a 100GB laptop SATAII HDD, in a Vantec E-SATA / USB enclosure), or a large USB Memory Stick. The USB HDD enclosure basically dock's into a "docking station" in the PC, which then connects it to the high speed SATA II bus and I can use it as any other Hard Drive in my PC.

When I'm on the move, it works with USB ( I didn't want to carry an external power supply) and is small and lightweight.

The biggest problem I faced was that a lot of data on the portable HDD was private, and I didn't want other people to get their hands on it. I carry client's website projects (for when I want to work on it, or demo it to the clients), photos (for my photography - when I want to show it to someone, work on it, print it, etc), my business's accounting info, and other private documents.

I also work a lot between Linux & Windows machines, so I needed something which is compatible with both operating systems. Accessing Linux's EXT3 file system from Windows is fairly easy, and also accessing Windows FAT32 from Linux was easy, but I prefer to use Linux's EXT3 cause the average non-Linux user wouldn't know what todo with the drive if they got it. BUT, that doesn't mean that a Linux user can't access the data. So I needed better protection. After searching, and asking around, someone suggested TrueCrypt.

TrueCrypt can encrypt a disk, partition, or file and works very well. From what I've read on their website, there's no back door, and no way to crack the encryption (unless you have access to a RoadRunner, Cray or Blue Gene, or any other Super Computer) It supports many encryption algorithms and it can even create hidden encrypted partitions and operating systems.

From download, to install, to encrypting my first partition, was a breeze. It probably took me about 15 minutes in total. Once encrypted, I could mount the hidden Hard Drive, and safely store all my important data on it.

When on the move, I know that my data on is safe. I can just plug the hard drive / memory stick into another PC, install TrueCrypt, mount it and then use my data.

Last night I also encrypted my games Hard Drive on my PC, and soon I'll be ancrypting every other Hard Drive I own, to keep all my data safe from prying eyes & thieves.
 
Just remember that true-crypt will add overhead to your data access times. When it comes to something like gaming - do you really want the overheard of first having true-crypt decrypt the files then load them into the game etc?

Just a thought. I do like true-crypt, but even on a little 8 gig encrypted volume you can see performance degradation. Go into true-crypt and perform a benchmark on the various methods. You might want to reserve the slowest and best encryption for your most sensitive data, but for everyday stuff - choose an encryption method that is quick.
 
Last edited:
Walks up a flight of stairs, falls down and now can't remember his decryption passphrase...

:D

Scary scenario.

Albeit unlikely.

:D
 
Just remember that true-crypt will add overhead to your data access times. When it comes to something like gaming - do you really want the overheard of first having true-crypt decrypt the files then load them into the game etc?

Just a thought. I do like true-crypt, but even on a little 8 gig encrypted volume you can see performance degradation. Go into true-crypt and perform a benchmark on the various methods. You might want to reserve the slowest and best encryption for your most sensitive data, but for everyday stuff - choose an encryption method that is quick.

Well.... I suppose I could do a IO benchmark to see how much slower it is, but to be honest with you, I haven't noticed the difference yet. My HDD's are all SATA II, and with 4GB RAM & a Core 2 Duo CPU, I think my PC has more then enough resources to cope with it.

It's a tad bit slower on the USB side though, as expected, but I don't play games over USB - that's just not practical in any case.


Walks up a flight of stairs, falls down and now can't remember his decryption passphrase...

:D

Scary scenario.

Albeit unlikely.

:D

heh, and hopefully the data recovery will be able to fix the broken HDD as well :)

In my case, this HDD is a backup of all my important data, so the encryption is more a matter of if it get's lost / stolen, no one can access the data. P.S. I also use a "password protector" program to store some of my more difficult passwords, but even this program is hidden.
 
Encryption isn't backup!!! A backup, is another copy of your data. Encrypting your data won't keep it safe from corruption, hardware failure, data loss due to viruses, etc. You still need to make backups of your data.
 
I've been using Portable TrueCrypt for months - I have a 300MB encrypted drive on my USB stick. Only sensitive information goes in there, and the file gets backed up regularly. Nice for that, but I wouldn't encrypt an entire drive (although I'm considering it for my laptop, which I don't game on).
 
Encrypting a whole drive has a slight bit of performance boost, and it helps to protect the encrypted volume, since one can't accidentally delete it.

Before using TrueCrypt, I have labeled all my Linux encrypted drives as broken with some masking tape (in a way that I can identify with it) to help obscure really sensitive info. Encrypting a whole USB memory stick is very easy as well, and works the same as a encrypted file.
 
When on the move, I know that my data on is safe. I can just plug the hard drive / memory stick into another PC, install TrueCrypt, mount it and then use my data.
How about a solution that doesnt involve installing software?
 
well, the problem kinds is, that encryption isn't a standard thing on the average PC. So, you'll need some sort of application to encrypt & decrypt the data. So, I'm sure a bit of google search may turn up something.

I know many linux systems can encrypt / decrypt files, folders & partitions as well, but even then the encryption tools aren't always installed by default. BUT, since I work with, and on the internet the whole time, it's not a problem for me. I also created 2 partitions on my drive, a 500MB open partition (to store the TrueCrypt installation files for Windows & Linux), and the rest my encrypted partition.
 
Yes, but that will only work if the other machine(s) doesn't require admin rights to run privileged programs,

http://www.truecrypt.org/docs/?s=administrator-privileges quotes:

Using TrueCrypt Without Administrator Privileges

In Windows, a user who does not have administrator privileges can use TrueCrypt, but only after a system administrator installs TrueCrypt on the system. The reason for that is that TrueCrypt needs a device driver to provide transparent on-the-fly encryption/decryption, and users without administrator privileges cannot install/start device drivers in Windows.

And this relates to the traveler mode (which is how the http://portableapps.com version works. See this link for more info: http://www.truecrypt.org/docs/?s=truecrypt-portable
 
Top
Sign up to the MyBroadband newsletter
X