четвъртък, 2 февруари 2012 г.

TrueCrypt криптиране на целият харддиск

Using Truecrypt to Encrypt Your Entire Hard Drive

By Randy Jensen | Apr 29, 2008

If you’re as paranoid as I am, you more than likely appreciate the advancements that the TrueCrypt team has made with version 5.0. For me, the greatest thing they did was making whole disk encryption dead simple. Here’s how you do it.

Getting Started

  1. First you will need to visit the TrueCrypt site and download and install it on your system. I’m going to be using Windows XP for my demonstration, but they have since released very good and stable version for Mac OSX and Linux.
  2. Next, go ahead and open the main window by clicking on the TrueCrypt logo in the system tray. The window should look like this
    truecrypt1 Using Truecrypt to Encrypt Your Entire Hard Drive

Setting Up the Encryption Settings

  1. Click the the ‘Create Volume ‘ button
  2. On the next window, choose the radio button next to ‘Encrypt the system partition or entire system drivetruecrypt2 Using Truecrypt to Encrypt Your Entire Hard Drive
  3. You now have the option to ‘Encrypt the Windows system partition’ or ‘Encrypt the whole drive ‘. We will be choosing the latter for this example.truecrypt3 Using Truecrypt to Encrypt Your Entire Hard Drive
  4. For the next screen you can choose ‘Single Boot ‘ or ‘Multi-Boot’. More than likely you are only running one OS on your computer, so we will choose Single Boot.truecrypt4 Using Truecrypt to Encrypt Your Entire Hard Drive
  5. Now you can choose the encryption settings. Unless you really know what you are doing, the default settings are fine. AES is an incredibly powerful encryption algorithm and should be all you need. I would also leave the Hash Algorithm at RIPEMD-160
    truecrypt5 Using Truecrypt to Encrypt Your Entire Hard Drive
  6. Next you will need to create a password. Depending on how paranoid you are, you should choose a passphrase close to 20 characters in length. I would also recommend using Steve Gibson’s Perfect Passwords Generator to make sure you create a completely unique phrase.
    truecrypt6 Using Truecrypt to Encrypt Your Entire Hard Drive
  7. Next you will need to move your mouse around the TrueCrypt window to create randomized data. This is fairly important, so spend a minute or two moving your mouse to make sure you really randomize things.
    truecrypt8 Using Truecrypt to Encrypt Your Entire Hard Drive
  8. The next window should simply be showing you the keys that were generated for you. You can simply click next here.
    truecrypt9 Using Truecrypt to Encrypt Your Entire Hard Drive

Creating the Rescue Disk

  1. The next step is to create what TrueCrypt calls the ‘Rescue Disk’. This disk will be used in case the boot loader or Windows become corrupt or infected with malware, yu will always have a way to decrypt the system. This step is extremely important, and TC will not let you proceed until it is satisfied that you did everything correctly. Begin by clicking the ‘Browse ‘ button. This will bring up a dialog box. Browse to your desktop and name the file something like rescueDisk.iso. IMPORTANT: remember to append the .iso or your file will not work correctly.
    truecrypt10 Using Truecrypt to Encrypt Your Entire Hard Drive
  2. You should now see a window telling you the file was created successfully. It’s now time to burn the newly created .iso file to a cd. I strongly recommend using ImgBurn . If for some reason that doesn’t work, you can use something like CD Burner XP Pro . Click next
    truecrypt12 Using Truecrypt to Encrypt Your Entire Hard Drive
  3. Make sure you have a blank CD in your drive and open ImgBurn. Click on ‘Write image file to disc’
    imgburn1 Using Truecrypt to Encrypt Your Entire Hard Drive
  4. Next click on the ‘Browse for a file’ button
    imgburn2 Using Truecrypt to Encrypt Your Entire Hard Drive
  5. Finally click the giant ‘Write’ button towards the bottom
    imgburn3 Using Truecrypt to Encrypt Your Entire Hard Drive
  6. After you have the disc burned, leave it in the drive and click ‘Next’ in the TrueCrypt window
    truecrypt12 Using Truecrypt to Encrypt Your Entire Hard Drive
  7. If all went well you will be notified that the Rescue Disk was successfully verified
    truecrypt14 Using Truecrypt to Encrypt Your Entire Hard Drive

Pretest and Installing the Bootloader

  1. You can choose to wipe the drive to really give you an incredibly secure hard drive, or just choose none if you aren’t storing government secrets on your computer (not that the government is intelligent enough to encrypt hard drives).
    truecrypt15 Using Truecrypt to Encrypt Your Entire Hard Drive
  2. Next TC will begin the pretest to make sure everything is in working order before it begins the encryption process. This will also install the TrueCrypt boot loader on the boot sector of your hard drive. This is a major reason why this encryption is so great. There is virtually no way to boot into the Windows file system without having the decryption key. Click ‘Test
    truecrypt16 Using Truecrypt to Encrypt Your Entire Hard Drive
    A friendly warning:)
    truecrypt17 Using Truecrypt to Encrypt Your Entire Hard Drive
  3. After TC runs a few things you will be presented with a window to restart. Click ‘Yes
    truecrypt18 Using Truecrypt to Encrypt Your Entire Hard Drive
  4. After the computer boots back up, you should see a black and white screen. Enter your passphrase you created earlier.
    truecrypt24 Using Truecrypt to Encrypt Your Entire Hard Drive
  5. If all went well you will now see a new dialog box saying the pretest was completed successfully.
    truecrypt19 Using Truecrypt to Encrypt Your Entire Hard Drive
  6. Click ‘OK’ on the Rescue Disk information window
    truecrypt20 Using Truecrypt to Encrypt Your Entire Hard Drive

Finally! Encrypting the Drive

  1. Whew! If you’ve made it this far, congratulations! We are now ready to encrypt the drive. You should see a window similar to the one below. Simply click the ‘Encrypt’ button and depending on your wipe mode and your encryption algorithms, go have a cup of coffee or go to sleep and let it run overnight.
    truecrypt21 Using Truecrypt to Encrypt Your Entire Hard Drive
  2. When everything is done, you should see this
    truecrypt22 Using Truecrypt to Encrypt Your Entire Hard Drive

In Closing

If you were able to get through this tutorial, you should now feel much safer with your data knowing it’s now gone from incredibly insecure, to even the DOD or NSA would have trouble getting in (unless of course there was water boarding involved).
This is really helpful if you travel a lot and carry a laptop all the time. If something were to happen and it gets lost or stolen, yes, you lose the data but at least whoever has it can’t get it either. Of course this means we need some training in the art of backing up;)

Няма коментари:

Публикуване на коментар