The bMighty Blog -- Open Source
Can You Keep A Secret?
Posted by Matthew McKenzie Wednesday, Jul 9, 2008, 07:58 PM ET
A typical laptop computer is a disaster waiting to happen. There is a quick, cheap, simple, totally effective way to fix the problem -- preferably, before it fixes you.
A few ugly numbers tell the story: According to one major study, about 40 percent of all computer data-breach incidents during 2006 were due to lost and stolen laptops. Those incidents alone involved more than 30 million personal business, medical, government, and other individual records.
Just six percent of these laptops employed any sort of data protection. The rest contributed directly to a mess that will cost a fortune to clean up -- and would have cost almost nothing to prevent.
Of course, wayward laptops are just part of the problem: No matter where you store sensitive data, it can still fall into the wrong hands. Encryption software is the best way -- and, in fact, the only way -- to protect your data, no matter where it ends up or how it gets there.
Data-encryption software has a reputation for being complicated and hard to use. One of the best encryption tools available, TrueCrypt, is neither of these things. TrueCrypt is also completely free to use and distributed under an open-source license.
Over the past couple of years, TrueCrypt has evolved at a very impressive pace. The Windows version now supports both encrypted files and encrypted disks/partitions, including Windows system partitions. You can also mount encrypted RAID volumes, CDs or DVDs, and portable storage devices such as USB flash drives.
TrueCrypt can encrypt volumes as big as 1PB (that's 1,000 terabytes), and its performance got a huge boost with the ability to take full advantage of multi-core processors. That is an important feature, since TrueCrypt is an on-the-fly encryption tool; on a system with an encrypted drive partition, for example, data is retrieved and decrypted only when you need it.
While the Windows version of TrueCrypt is still the most mature, its Linux and Mac OS support has improved a great deal since the beginning of the year. All three versions, for example, now support hidden, encrypted partitions (more on that in a moment) -- and an encrypted storage volume created on one platform will open just fine on another.
Perhaps the most talked-about TrueCrypt feature involves what its developers refer to as "plausible deniability." Although TrueCrypt can create hidden, encrypted files and storage volumes, it takes the concept a step further:
"It may happen that you are forced by somebody to decrypt the operating system or to reveal the pre-boot authentication password. There are many situations where you cannot refuse to do so (for example, due to extortion). TrueCrypt allows you to create a hidden operating system whose existence will be impossible to prove. . . Thus, you will not have to decrypt or reveal the password for the hidden operating system."
This is encryption for the truly paranoid -- or the truly persecuted, given the number of countries where the very act of keeping a secret from the authorities can be a life-threatening act of defiance. Whether or not you ever need this sort of feature, however, it shows just how committed TrueCrypt's developers are to creating an effective, rock-solid data-security tool.
Also, like so many highly regarded security applications, TrueCrypt is open-source software. This is important, since proprietary encryption tools can -- and, in some cases, probably do -- include undocumented "back door" access to their users' protected data. You may trust the government, but do you also trust every programmer who may have worked on a proprietary encryption product?
Is TrueCrypt 100 percent secure? No, and neither is any other encryption tool -- past, present, or (forseeable) future. Fortunately, you don't have to protect your business data against a legion of NSA cryptanalysts or an evil genius with an IBM mainframe sitting in his secret lair. And unless I'm wrong on either of those points, looking askance at the security a tool like TrueCrypt has to offer is just plain foolish.
Keep one more important point in mind about TrueCrypt: While it is powerful and offers a lot of flexibility for advanced users, its default setup process is quick and easy enough for any computer user.
In other words, there really are no excuses.
Business & E-Business | Hardware & Software | Mobile | Open Source | Security | Windows
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
Spotlight on Solutions (Sponsored By Cisco)
Explore the bMighty Blog
Most Recent Posts
- Latest Intel Move Secures SSD Future For Servers
- Are Competitor Security Problems A Business Advantage Worth Talkng?
- You Can Send SMBs E-Mail, But You Can't Make Them Archive It
- Security Solutions Arriving for Virtualized Systems
- BitPim: A Smart(Phone) Move For Backing Up Mobile Data
bMighty Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 1-49
- Company Size: 250-999
- Company Size: 50-249
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Professional/Creative Services
- Retail
- Sales/Marketing
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Start-Ups
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- the rANT
- Transportation
- Travel
- Windows
- Women in Business
bMighty Bloggers
bMighty Blog Roll
- Ars Technica
- Business know-how
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- MonkeyBrains
- Scott Berkun
- Network Computing Blog
- Search Engine Land
- Search Engine Watch
- SmallBusinessHub
- Small Business Trends
- SmallBizResource
- SmallBizTechnology.com
- TechCrunch
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
bMighty email newsletter!
Browse by Category
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
goTech Term of the Day: journaling file system
TechEncyclopedia gives you the meaning of today's word, plus more than 20,000 additional IT terms and definitions.
![]() |
||||
![]() |
|
|||
![]() |
||||
![]() |
||||
![]() |
|
|||
![]() |
|
|||




















