Hacker News new | ask | show | jobs
by mmaro 5411 days ago
Would there be any reason to use it over Lion's full disk encryption?
4 comments

People who want a fully open-source solution might prefer TrueCrypt. Are there any guarantees that Apple's solution doesn't have a backdoor?
If you don't trust Apple's FDE solution to not have a backdoor, you probably shouldn't use their operating system at all, as it has access to all of your data.
People usually aren't trying to protect their drive contents with encryption while the drive is mounted and the computer is running. If the drive is encrypted, anyone trying to gain access won't care if OSX has a backdoor because it will all be encrypted in the volume. The only thing that will matter is a backdoor allowing decryption of the volume.

You could use your argument to state that someone paranoid enough to use encryption just shouldn't use a computer at all.

i may be mistaken, but it's my understanding that TrueCrypt is not actually fully open source.
My understanding is that it's not considered "true" open source by many people, because of the license that it's released under, but their website gives easy access to all the source code.
I do not think it would offer anything over Lion's encryption. The real hope would be support, I think, for hidden OS. The TrueCrypt Boot Loader has been absent from the Mac versions because the full disk encryption has been. I do not know why.

I suppose, then, a reason to use it over Lion's encryption would be to gain the boot loader and hidden OS feature.

I wasn't under the impression this was 1> Pre-boot or 2> Actually the whole disk or 3> Functional and TRIMtastic with SSDs 4> Allowing central, on site management of backup keys

Do you have anything to show that it's comparable to say, PGP's offering?

Yes, for when you want portable virtual disks to put in places like DropBox. We don't trust drop box for sensitive/important stuff and we trust Truecrypt more.

Great for shuffling stuff to your accountant actually! And heck of a lot faster and cheaper than FedEx.

You're going to do full disk encryption, and then upload your entire disk to Drop Box? Seems kinda strange…
Answer in haste on a small screen and realize mmaro's question isn't on the top level. Bugger!

So, no is the answer and thanks for graciously pointing my mistake out and allowing me to correct. Truecrypt really is a great transport for smallish disks on an untrusted network. Whole disks on Dropbox probably = insane.