Disk encryption

  1. Anfinuo Member

    So I have a disk divided into 4 partitions. I want to encrypt it (probably TC\VC, maybe DC, but it looks "strange").
    So I have some questions:
    • if I encrypt partitions one by one, is the whole disk encrypted ?
    • if the disk\partition is formattted, are the "deleted" files still encrypted ?
    • how "strong" AES 256 is (assuming long, complicated, complex as hell password, etc.)? Semi-interested script kiddie ? Police ? FBI ? NSA ?
  2. Old_Coder Member

    I may not understand your question so forgive me if I am wrong, but encrypting partitions one by one will not give you a full system level encryption. Meaning things like the boot sector will not be encrypted. I am forced to run a full disk encryption on one of my machines and that is fully encrypted but be warned... if you are not careful in the configuration then it will turn your machine into a dog as it inefficiently encrypts and decrypts all your data back and forth. Also, you will still be vulnerable if the machine is up and running. Once you sign in then someone hopping on to your machine would have access to those files. So you still want to have file level encryption for those really really want to encrypt files. One easy way that meets most peoples needs without too much headache is some form of block device setup where you can target a partition, a file system, anything and have all back and forth with said device be encrypted. I prefer an external source where I can keep my actual data but not encrypt all my programs and other things that do not really need it. You will deter most trivial attacks with anything, but you get the Feds on your Sh^% (Stuff) then you are toast unless you really set up some serious fail safes.

    So, simple answer is no the way you stated above with not encrypt the "entire" drive. However, you will get the same bang for the buck if you make sure that you encrypt smartly so as to only take the hit on processing speed when you have too.
  3. Anfinuo Member

    Thank you for answering.
    I'm not that worried about it being monitored, accessed while being active, I'm worried about it being seized psychically, and then accessed.
    Please elaborate on "doing it smart", etc.
    And how about those two other questions ?

