<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Stealth: The Web Edition</title>
	<atom:link href="http://twosandals.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://twosandals.wordpress.com</link>
	<description>Encryption and Security Information and Rants</description>
	<lastBuildDate>Wed, 19 Dec 2007 18:47:36 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='twosandals.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Stealth: The Web Edition</title>
		<link>http://twosandals.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://twosandals.wordpress.com/osd.xml" title="Stealth: The Web Edition" />
	<atom:link rel='hub' href='http://twosandals.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Federal ruling on compelling passwords from defendants</title>
		<link>http://twosandals.wordpress.com/2007/12/19/federal-ruling-on-compelling-passwords-from-defendants/</link>
		<comments>http://twosandals.wordpress.com/2007/12/19/federal-ruling-on-compelling-passwords-from-defendants/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 18:47:36 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/12/19/federal-ruling-on-compelling-passwords-from-defendants/</guid>
		<description><![CDATA[More detail here: http://www.news.com/8301-13578_3-9834495-38.html?tag=nefd.blgs The short summary is that a Federal judge ruled that a defendant could not  be forced to reveal his encryption password due to 5th Amendment protection. This is good news for privacy lovers out there, but I&#8217;m sure that the Govt&#8217; will try to get this one overturned. We&#8217;ll see how [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=11&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>More detail here: <a href="http://www.news.com/8301-13578_3-9834495-38.html?tag=nefd.blgs" title="News.com" target="_blank">http://www.news.com/8301-13578_3-9834495-38.html?tag=nefd.blgs</a></p>
<p>The short summary is that a Federal judge ruled that a defendant could not  be forced to reveal his encryption password due to 5th Amendment protection.</p>
<p>This is good news for privacy lovers out there, but I&#8217;m sure that the Govt&#8217; will try to get this one overturned. We&#8217;ll see how it pans out.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=11&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/12/19/federal-ruling-on-compelling-passwords-from-defendants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Full&#8221; disk encryption in Ubuntu 7.10</title>
		<link>http://twosandals.wordpress.com/2007/11/07/full-disk-encryption-in-ubuntu-710/</link>
		<comments>http://twosandals.wordpress.com/2007/11/07/full-disk-encryption-in-ubuntu-710/#comments</comments>
		<pubDate>Wed, 07 Nov 2007 15:18:02 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/11/07/full-disk-encryption-in-ubuntu-710/</guid>
		<description><![CDATA[With the 7.10 release, Ubuntu now lets you setup &#8220;full&#8221; drive encryption right from the install disk. Granted, it is the &#8220;alternate&#8221; install disk that is for power-users and doesn&#8217;t feature a graphical installer. What it does is make a small boot only partition, with the kernel and loader files, and partitions the rest of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=10&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>With the 7.10 release, Ubuntu now lets you setup &#8220;full&#8221; drive encryption right from the install disk. Granted, it is the &#8220;alternate&#8221; install disk that is for power-users and doesn&#8217;t feature a graphical installer. What it does is make a small boot only partition, with the kernel and loader files, and partitions the rest of the disk with one encrypted volume that contains the root and swap partitions. Keep in mind that it won&#8217;t encrypt every sector in the partition at install time; only encrypted sectors that contain files. So you should really wipe your drive with DBAN or something before installing this.<br />
The only problem I had was with my graphics: when it asks for your password it changes display mode (apparently) and my on-board graphics chipset wasn&#8217;t quite up to the task. Plugging in an actual video card fixed the problem.<br />
I&#8217;ve only been using it for a few days and it seems pretty slick. Like DCPP, it doesn&#8217;t seem to slow down drive access noticeably. The only thing that I&#8217;m not too happy with is the fact that not only the boot loader, but the entire Linux kernel, exist in an unencrypted state on the boot partition. It would seem to be a pretty easy thing to install a trojaned kernel configured to log keystrokes or whatever (I&#8217;ll do a little testing to see how difficult it would be to switch from a boot partition to a boot CD; something that would be a little harder to modify). Also, the encrypted partition is pretty obviously encrypted. If you created some type of boot cd and overwrote the boot partition, installed FreeDOS or something, you would still be out of luck since the encrypted partition announces its encrypted nature with header data. So you can&#8217;t do the &#8220;totally hidden OS&#8221; trick with this like you can with DCPP.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=10&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/11/07/full-disk-encryption-in-ubuntu-710/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>EnCase Computer Forensics Demo</title>
		<link>http://twosandals.wordpress.com/2007/05/04/encase-computer-forensics-demo/</link>
		<comments>http://twosandals.wordpress.com/2007/05/04/encase-computer-forensics-demo/#comments</comments>
		<pubDate>Fri, 04 May 2007 18:21:30 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/05/04/encase-computer-forensics-demo/</guid>
		<description><![CDATA[Here is a small video I worked up showing EnCase in action. It is pretty brief since EnCase is a pretty complicated application. However, I think it illustrates how effective forensic software is at analyzing data. Sorry the YouTube video is hard to see. It got resized, but I think it is still pretty obvious [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=9&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here is a small video I worked up showing EnCase in action. It is pretty brief since EnCase is a pretty complicated application. However, I think it illustrates how effective forensic software is at analyzing data. Sorry the YouTube video is hard to see. It got resized, but I think it is still pretty obvious what is happening.</p>
<span style="text-align:center; display: block;"><a href="http://twosandals.wordpress.com/2007/05/04/encase-computer-forensics-demo/"><img src="http://img.youtube.com/vi/O4ce74q2zqM/2.jpg" alt="" /></a></span>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/9/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/9/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=9&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/05/04/encase-computer-forensics-demo/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>Window&#8217;s Autorun</title>
		<link>http://twosandals.wordpress.com/2007/05/03/windows-autorun/</link>
		<comments>http://twosandals.wordpress.com/2007/05/03/windows-autorun/#comments</comments>
		<pubDate>Thu, 03 May 2007 15:14:02 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/05/03/windows-autorun/</guid>
		<description><![CDATA[This will probably be a &#8220;well duh&#8221; statement for many people but the implications are pretty severe. If Window&#8217;s autorun &#8220;feature&#8221; is turned on it will still operate even if you have locked your screen. In other words it is very easy to install trojans etc. unless you turn it off. In most cases it [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=7&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>This will probably be a &#8220;well duh&#8221; statement for many people but the implications are pretty severe.</p>
<p>If Window&#8217;s  autorun &#8220;feature&#8221; is turned on it will still operate even if you have locked your screen. In other words it is very easy to install trojans etc. unless you turn it off.</p>
<p>In most cases it it best to turn your computer off when you can&#8217;t be physically present, but I admit to leaving for a while and just relying on my screen lock only.</p>
<p>So the moral of the story is: &#8220;Turn off autorun!&#8221; and <strong>test </strong>it to make sure it is really off.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=7&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/05/03/windows-autorun/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>DriveCrypt Plus Pack 3.9</title>
		<link>http://twosandals.wordpress.com/2007/02/28/drivecrypt-plus-pack-39/</link>
		<comments>http://twosandals.wordpress.com/2007/02/28/drivecrypt-plus-pack-39/#comments</comments>
		<pubDate>Wed, 28 Feb 2007 16:50:28 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/02/28/drivecrypt-plus-pack-39/</guid>
		<description><![CDATA[I finally got around to looking at DCPP 3.9 and had a few observations that might be interesting to those who are interested in that sort of thing . In previous versions of DCPP, the only unencrypted data was in the boot sector: if you searched your HD for the string &#8220;DCPP&#8221; the only place [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=6&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I finally got around to looking at DCPP 3.9 and had a few observations that might be interesting to those who are interested in that sort of thing <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> .</p>
<p>In previous versions of DCPP, the only unencrypted data was in the boot sector: if you searched your HD for the string &#8220;DCPP&#8221; the only place you would see it would be in the boot sector. However, with the current version the boot sector code has been replaced with a &#8220;stub&#8221; that points to sections of the disk that are unencrypted and contain more boot code. Where do these come from? Well, when you install BootAuth, DCPP creates some &#8220;bootauth.sys&#8221; files in the root of C drive. The sectors that hold these files are apparently *not* encrypted. So any modifications to these files inside the OS are visible to someone examining the encrypted drive forensically and vice-versa. In practice I don&#8217;t think this is any more of a security problem than just having the boot sector unencrypted as has always been the case. However, it might be possible for an attacker to use these files to load trojans into the system. Before, someone wanting to do this had to work only with the boot sector code which doesn&#8217;t give you a lot of extra space. Now, entire files are exposed unencrypted. We&#8217;ll see how it all pans out. Incidentally, the procedure I give below for &#8220;fully hidden&#8221; DCPP installations still works fine with this version. In fact, it gets rid of the exposed files on disk since they reside in the &#8220;outer&#8221; OS.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=6&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/02/28/drivecrypt-plus-pack-39/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>Fully Hidden Drive Crypt Plus Pack Installation</title>
		<link>http://twosandals.wordpress.com/2007/01/10/fully-hidden-drive-crypt-plus-pack-installation/</link>
		<comments>http://twosandals.wordpress.com/2007/01/10/fully-hidden-drive-crypt-plus-pack-installation/#comments</comments>
		<pubDate>Wed, 10 Jan 2007 17:25:41 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/01/10/fully-hidden-drive-crypt-plus-pack-installation/</guid>
		<description><![CDATA[DCPP, which lets you encrypt your entire HD (except for the boot sector of course), also has the ability to install a second &#8220;hidden&#8221; OS in the free space of another, &#8220;outer&#8221;, DCPP installation. How this is supposed to work is that you keep all sensitive data off of the outer installation and only use [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=5&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>DCPP, which lets you encrypt your entire HD (except for the boot sector of course), also has the ability to install a second &#8220;hidden&#8221; OS in the free space of another, &#8220;outer&#8221;, DCPP installation. How this is supposed to work is that you keep all sensitive data off of the outer installation and only use your inner, &#8220;hidden&#8221; installation for sensitive work. The theory is that if you are forced to reveal your password, you can give them the outer, fake, password and they shouldn&#8217;t be able to tell you have a second hidden OS since encrypted data in freespace should appear to be random. You could have random data from using a disk wiping program for instance.<br />
The problem I have with this is that even though you have a &#8220;safe&#8221; password to give out, any govt&#8217; investigator worth their salt will know about DCPP&#8217;s hidden OS function. If they think that this is what is happening, I wouldn&#8217;t put it past them to try to muscle/intimidate/trick you into revealing this is the case or giving out your real password.<br />
After working with it a while, I now have a method to have an actual DCPP hidden OS in freespace with these features</p>
<ul>
<li>Actual, non password protected, bootable OS</li>
<li>No trace of encryption software on the HD, including boot sectors</li>
<li>Bootable only through rescue floppy/CD</li>
</ul>
<p>Now, you can have an outer OS that can be scanned freely and should not turn up any &#8220;red flags&#8221; except random data in freespace. But, like I said, a disk wiping program can cause that. Many companies and savvy individuals are routinely wiping their HDs before getting rid of them, so this shouldn&#8217;t be that unusual.<br />
To do this, I have used two drives: the one I am preparing and another one that contains the tools I use to prepare the first. This way, sensitive tools (Encase, WinHex, DCPP) are never present in the &#8220;fake&#8221; OS. Also, I am using DCPP 3.0. There are newer versions of DCPP, and when I get a hold of them I will try to test this procedure out and make sure it still works right.. Ready? Here goes:</p>
<ol>
<li>Get your target drive and wipe it. I used Darik&#8217;s Boot and Nuke (DBAN). I had two problems with DBAN: It zeroed out the drive on it&#8217;s final pass, I wanted it to leave random-ish data. And second, it didn&#8217;t get the boot sector of the HD (first 63 sectors). The drive I used was used previously for DCPP and so, had the special boot sector. I finally just copied the boot sector from a non-encrypted computer and used that. Verify all of this with EnCase or WinHex</li>
<li>Format with <strong>FAT32</strong> (&lt;- Very important and we can change this for your real OS) and install Windows and all programs that you might use and that wouldn&#8217;t be suspicious. No encryption software, no security stuff, nothing like that. Just a basic Windows installation. If you want to make it look even more realistic then use the system for a couple of weeks. This will be the system that people will see when inspecting your HD.</li>
<li>Install this drive as a secondary and run a defrag. program from another drive on this one. I used O&amp;O Defrag and was very impressed. You have to make sure that *no* data gets positioned too far down the disk: everything needs to be at the top of the drive to make the largest amount on contiguous free space possible.</li>
<li>Copy your clean boot sector with DD like this (Google &#8220;forensics acquisition tools&#8221;):<br />
<font color="#ff0000">dd ibs=512 count=63 if=\\.\\physicaldrive1 of=winbs.bin</font><br />
That reads in the first 63 blocks of 512 bytes on your hard drive and saves it in the file <strong>winbs.bin</strong>. This should be your boot sector. Verify this with Encase or WinHex. Note that you will have to do this operation as a user with Administrative access since accessing the raw disc is a protected operation on Windows.</li>
<li>On your defragmented HD find the last sector that has data on it. For a regular XP installation this should be around the 2 to 3 Gig mark. Note the sector number in Encase (If you are using WinHex make sure you don&#8217;t get this number in HEX). Add a little to it and then copy your entire &#8220;fake&#8221; os with a command like this.<br />
<font color="#ff0000">dd ibs=512 count=YOURCOUNT if=\\.\\physicaldrive1 of=origos.bin</font><br />
Where <strong>YOURCOUNT</strong> is the last block you want to copy. Don&#8217;t be afraid to give your self a little extra room when you copy. Note that this is the command line for a secondary HD, your primary should be <strong>physicaldrive0.</strong></li>
<li>Now reboot with the drive you are preparing and install DCPP as a Hidden OS. Give yourself lots of extra space when starting your hidden OS, I did 800Megs. This way, if your real OS takes up 2.5Gigs, then your hidden OS will start at approx. the 3.3Gig point on your disk. Read DCPP&#8217;s docs on hidden OS creation but here it is in broad strokes:
<ul>
<li>Install DCPP on a FAT32 installation of Windows.</li>
<li>Create 2 key stores in two <strong>different</strong> files with two <strong>different</strong> keys and <strong>different</strong> passwords (real and fake)</li>
<li>Install BootAuth (the DCPP bootsector) and encrypt the drive with your fake keystore/key</li>
<li>Reboot, log into your fake keystore with DCPP and select the FAT32 drive. You will see the <strong>Hidden OS</strong> button enable, click it:</li>
<li>Give it the path to your real keystore and your real password. As I said before give yourself lots of space before the real OS start point. Also, you can tell it to use NTFS and the file system for the real OS. Click &#8220;Create Hidden OS&#8221;</li>
<li>It will create a hidden OS. After it finished reboot using your <strong>real</strong> password</li>
<li>In DCPP, log into your real keystore and select your current drive. You will have to re-encrypt at this point as the hidden OS is created unencrypted</li>
<li>Reboot and if it works, make yourself a few rescue disks as this is how you will have to boot your system when we are finished</li>
</ul>
</li>
<li>Make sure you have a few good boot disks. This is how you will always have to start your real OS.</li>
<li>Reboot, using the drive used to copy the boot sectors and OS. Copy your boot sector on your DCPP drive again. You will want to save a copy of this boot sector in case you ever need it. For instance, you will have to re-install it to make more DCPP boot disks, and then re-install your &#8220;clean&#8221; boot sector.</li>
<li>Copy your clean OS back onto your DCPP drive with:<br />
<font color="#ff0000">dd ibs=512 count=YOURCOUNT of=\\.\\physicaldrive1 if=origos.bin</font><br />
Make sure YOURCOUNT is the same as before</li>
<li>Done! That was easy huh &gt;;-&gt;</li>
</ol>
<p>Boot your fake OS (without your boot disk) to make sure it works. However, you should try to not use it much at this point. You should have a good bit of space before you would start stomping on your hidden OS&#8217;s data but it is something you shouldn&#8217;t risk too often.<br />
So at this point you should have what looks like normal HD, free from encryption tools or anything that would arouse suspicion, that boots without a password and can be freely inspected (though I would use a BIOS password to prevent curious people from starting your fake OS up and mucking around in it). Double check your boot sector with Encase or WinHex to make sure it contains only the Windows default boot sector. If you see the string &#8220;DCPPBOOT&#8221; or &#8220;DCPP&#8221; you aren&#8217;t completely clean. Enjoy!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=5&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/01/10/fully-hidden-drive-crypt-plus-pack-installation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>EnCase by Guidance Software</title>
		<link>http://twosandals.wordpress.com/2007/01/10/encase-by-guidance-software/</link>
		<comments>http://twosandals.wordpress.com/2007/01/10/encase-by-guidance-software/#comments</comments>
		<pubDate>Wed, 10 Jan 2007 17:21:43 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/01/10/encase-by-guidance-software/</guid>
		<description><![CDATA[We have all heard the horror stories of government agents seizing people&#8217;s computers and through their hi-tech govt&#8217; software, finding all the CP and Warez that the owner supposedly had on the system; even though they tried their best to hide them. Well, this is pretty much true. Government quality computer forensics software is pretty [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=4&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>We have all heard the horror stories of government agents seizing    people&#8217;s computers and through their hi-tech govt&#8217; software, finding all the    CP and Warez that the owner supposedly had on the system; even though they tried    their best to hide them. Well, this is pretty much true. Government quality    computer forensics software is pretty bad-ass. It has perfected screwing people    over to a fine art. EnCase is such a tool.</p>
<p>EnCase, all I can say is:<strong> learn how to use this software!</strong> EnCase    is probably the most popular forensics software for govt&#8217; snoops. Knowing how    to use it is knowing how the &#8220;enemy&#8221; works and thinks. Also, it will    allow you to verify that the security procedures (file over-writing, free-space    wiping, temp file deleting) you are taking are actually working. I&#8217;ve been surprised    a couple of times when I thought that I had removed all relevant evidence from    my computer only to have EnCase turn up something that I had either overlooked    or did not know existed. EnCase supports FAT12, FAT16, FAT32, NTFS, HFS, HFS+,    CDFS, EXT2, UFS, RAID drives, Palm PDA&#8217;s and *all* file system types in RAW    mode! Still think the fact that you run NetBSD is going to throw off the snoops?    Encase will let you create a boot disk that lets you do a full disk capture    of a target machine over parallel or network cable without ever having to boot    the hard drive. One of the things that learning to use EnCase will show you    is what really comprises good security: For instance, if you&#8217;re like me you    would think that renaming a file will serve to hide it&#8217;s true contents. Who    would think that <strong>Metallica.wav</strong> would really be just a renamed    copy of <strong>Terrorist Bomb Plans.doc</strong>? Nobody right? Wrong! EnCase    has a little feature known as Signature Analysis. Basically SA will search all    the files on a file system and flag every file that has an extension that doesn&#8217;t    match what EnCase believes the content to be from looking at the actual file.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=4&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/01/10/encase-by-guidance-software/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome to Stealth!</title>
		<link>http://twosandals.wordpress.com/2007/01/09/welcome-to-stealth/</link>
		<comments>http://twosandals.wordpress.com/2007/01/09/welcome-to-stealth/#comments</comments>
		<pubDate>Tue, 09 Jan 2007 17:08:53 +0000</pubDate>
		<dc:creator>twosandals</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://twosandals.wordpress.com/2007/01/09/welcome-to-stealth/</guid>
		<description><![CDATA[The government(s) is(are) freaking out. They make up new computer laws and then vigorously pursue and prosecute anyone who violates them. Even if someone uses your computer for something illegal and gets caught, it still reflects badly on you. If someone wanted to do you some harm and planted a bunch of CP on your [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=3&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The government(s) is(are) freaking out. They make up new computer laws and    then vigorously pursue and prosecute anyone who violates them. Even if someone    uses your computer for something illegal and gets caught, it still reflects    badly on you. If someone wanted to do you some harm and planted a bunch of CP    on your HD and then tipped off the cops, what would happen? You&#8217;d be screwed.    Why? Because computer technology and the Internet have snuck up on governments    and industry, and they realize that their bizarre laws are going to be much    harder to enforce than they originally thought. That translates into stiff penalties    for the people they catch (or believe that they have caught).<br />
Why on Earth would someone make computer data illegal? It&#8217;s stupid. It&#8217;s data  folks, ones and zeroes. It&#8217;s not going to kill anybody (directly anyway), it&#8217;s  not going to molest kids, it&#8217;s not going to steal valid products that people  have worked hard to produce. The only thing that it&#8217;s going to do is cut into  the bottom lines of companies who develop software and &#8220;content&#8221; (not    necessarily a bad thing I&#8217;d argue) and make it harder for governments to enforce    their random codes of civil (not moral) ethics.<br />
So what do you do? Aside from running Freenet, cover your tracks. That&#8217;s what  I hope that this site will help you do. I don&#8217;t know everything about computer  security, but I know a little bit that should help people be better equipped  to conceal what they do on their systems, and better understand how government  snoops work and collect &#8220;evidence&#8221;. I mainly work on the Windows platform    so not all of this information will be helpful to the Unix folks out there.    But I&#8217;d guess that most Unix people use Windows more than they would like to    admit. Even I have an OpenBSD machine sitting beside me, but it doesn&#8217;t run    everything that I need&#8230;&#8230;..</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/twosandals.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/twosandals.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/twosandals.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/twosandals.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/twosandals.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=twosandals.wordpress.com&amp;blog=669873&amp;post=3&amp;subd=twosandals&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://twosandals.wordpress.com/2007/01/09/welcome-to-stealth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/2144732b5d69233b44d897fd59e428ad?s=96&#38;d=identicon" medium="image">
			<media:title type="html">twosandals</media:title>
		</media:content>
	</item>
	</channel>
</rss>
