Menu

Second pssword for Drive wipe

Anonymous
2018-09-10
2019-05-18
  • Anonymous

    Anonymous - 2018-09-10

    Just like the removal of the bootloader (which I Still haven't got a response for) this would be to assist people in keeping data hidden. Obviously this feature will wipe the entire drive and people who use it take full responability of it's feature.

    when you reach the "enter password" page, next to "use PIM" you could have another button called "2nd password for drive wipe". Once selected you'll be asked to enter a different password, just like the Hidden OS. and for example, if you're forced to reveal a working password to Launch the OS. but when you enter this password you will get a prompt saying "The system is corrupt, would you like to repair?" or "are you sure you'd like to fully decrypt the drive?" so that the person entering the false password thibks it has worked but tequires additional steps. once they select the feature it will begin to say something like "repairing OS" or "Decryption status (%)" but obviously instead of decrypting or repairing it is in fact wiping the drive clean.

    this is a more aggresive approach to the Hidden OS idea, but it allows for more HDD space and if you're willing yo lose all the protected data on your drive it's perfect!

    Looking forward to a response and hopefully positive feedback.

     
  • Samsonov #14 "C"

    I like that idea a lot! But it have to integrate original bootloader screen, because then anyone can't know that's actually wipe screen.

    Maybe create two passwords? One to decrypt, one to wipe whole drive? No one can't know that you actually tell wipe password and it start wiping process and show typical text until it's finish.

    • S
     
    • Anonymous

      Anonymous - 2018-09-13

      very true, Within a year from now everyone would know that this feature exists. But we would still need a method to keep the computer on while it's wiping. If it's been several hours on the password verifying screen, the attacker is bound to either reboot the bootloader or shut down the PC. I'm not sure of any other methods to make the attacker think what he's done is correct. But I'm sure we could all think of an idea and post it here :)

       
  • Anonymous

    Anonymous - 2018-09-11

    +1 !!!!!!!!!!!!!!!!!!!!!!!!! <3
    3x incorrect password = start wiping process !!

    <3

     
  • Anonymous

    Anonymous - 2018-09-13

    I would personally say 3x incorrect attempts = wipe is too insecure, sometimes people accidently type their passwords in wrong, even though they know it. Having two passwords on the other hand would allow you to enter your password wrong as many times as you want without any consequeses. It's only until you're forced to reveal your password or just want to wipe your drive that you would provide the 2nd password for wiping. This way your data is safe from mistyping or forgetting, but still secure in the sense you'll never have to reveal your real password to an attacker. If there was a good way to convince the attacker he has completed the operation sucessfully but either the PC is corrupt or is just booting very slow, this concept would be great.

    I'd still love to see something like this in VeraCrypt, Not everyone wants to have 2 operating systems to deter a forced password attack. Even though this could land you into some trouble, it's still a very secure concept and if pulled of correctly be an amazing new feature to VeraCrypt

     
  • Enigma2Illusion

    Enigma2Illusion - 2018-09-13

    Using a second password to wipe has been discussed and rejected in the past.

    https://sourceforge.net/p/veracrypt/discussion/features/thread/632d265a/#1448

    NOTE: With SSDs and thumbdrives, the wipe may not actually remove the original headers and data.

    https://www.veracrypt.fr/en/Wear-Leveling.html

    https://www.veracrypt.fr/en/Reallocated%20Sectors.html

    On the old CodePlex site, a ticket was created for the "Panic Button" feature to wipe the headers and bootloader.

    • Allow user to run panic button from GUI.
    • Allow user to create "Hot Keys" to run the panic button.
    • Allow pre-configuration of the actions performed by the panic button.

    .
    Options in the pre-configuration page...

    • Wipe the header and backup header locations on all attached drives.
    • Wiping the bootloader if it exists.
    • Wipe only user defined drives header and backup header locations.

    Unencrypted Drives Options ( if it is possible to work out which are unencrypted )

    After header and backup header areas are wiped on all drives attempt to reduce data exposure on unencrypted drives.

    Wipe MFT / GPT first.
    Attempt full wipe of drive, time permitting.

     

    Last edit: Enigma2Illusion 2018-09-14
  • eil

    eil - 2019-03-10

    +1 for Second Pass for Deletion. i'd prefer to lose data than to give it away.

     
  • yozas

    yozas - 2019-04-15

    the interested person can make a sector by sector copy before playing around, so such function is questionable

     

Log in to post a comment.

MongoDB Logo MongoDB