Menu

Volume automounted without requesting password

2024-09-16
2024-09-22
  • - Wanderer -

    - Wanderer - - 2024-09-16

    I'm (still) using VC 1.25.9 until i make sure i don't have any older volumes not supported by the new version.

    Today i experienced something strange which made me worry a bit. I have a master volume (non-system) with a certain password. I had mounted it and was using the PC for more than an hour. I had a job so i left the pc open and returned about half-an-hour later. I sat down, unlocked the pc and decided to mount two additional volumes which happen to have the same password as the master one. Both of them were mounted without asking for a password! All mounts were performed via command-line (example: /q /SecureDesktop /m ts /l K /a /v ...)

    I'm attaching my configuration. Any idea why this has happened?

     
  • - Wanderer -

    - Wanderer - - 2024-09-16

    Well, that's why i attached the config file... :)

    This behavior worries me because:

    1. VeraCrypt GUI did not appear at all because as i said, everything was initiated from command-line.
    2. In the config file, it is shown that "cache driver passwords" is not checked, only "temporarily cache passwords" is enabled and the time between the first mount and the other two was more than 1 hr. I expect that "temporarily" does not last that much.
    3. Hibernation and Fast Startup are disabled (HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Power\HiberbootEnabled = 0).

    Hasn't happened to me before, so i find it strange.

     

    Last edit: - Wanderer - 2024-09-16
  • Mounir IDRASSI

    Mounir IDRASSI - 2024-09-16

    The temporary cache setting only applies when mounting favorite volumes simultaneously and it is cleared once the operation is complete. Therefore, this cannot be the issue.

    Did you check if the 'Wipe Cache' button was enabled in the VeraCrypt UI? This would indicate that your password was somehow cached.

    Unless you accidentally ticked the 'Cache passwords and keyfiles in memory' checkbox in the password dialog, I don't see how this could have happened.

     
    • - Wanderer -

      - Wanderer - - 2024-09-16

      -> 'Wipe Cache' button was enabled in the VeraCrypt UI

      You mean in the first mount? No i don't remember. I didn't notice at all if something was accidentally pressed in the first mount, i do remember though that i gave the password twice because the first time i entered it was wrong. Since i'm using "secure desktop", are the dialog checkboxes reset in this case or if i check something and enter a wrong password, it will remain checked the second time the dialog opens?

      P.S.: i tried unmounting a volume and remounting it 5 mins ago, it still does not ask for a password...

       

      Last edit: - Wanderer - 2024-09-16
  • - Wanderer -

    - Wanderer - - 2024-09-16

    OK, after a restart, it was fixed so i guess the "cache passwords" might have been checked the first time. A small issue i see here is that there is no way to "uncache" it. Only restart. Perhaps there should be an additional menu item in the context menu of the tray icon to "clear cached passwords".

    Anyway, thanks both for the help.

     
  • Mounir IDRASSI

    Mounir IDRASSI - 2024-09-16

    You can wipe the password cache using the command line:
    VeraCrypt.exe /wipecache /q

    To be sure, add this command at the end of your mount script to ensure that no password is cached.

     
  • - Wanderer -

    - Wanderer - - 2024-09-16

    Great, thanks.

    Can i add it at the end of the existing mount command or it has to be a separate execution of veracrypt?

     
  • Mounir IDRASSI

    Mounir IDRASSI - 2024-09-16

    Since the cache needs to be wiped after the mount is performed, you will need to run this command in a separate execution once the mount is complete.

     
  • - Wanderer -

    - Wanderer - - 2024-09-16

    OK, will do so. Many thanks.

     
  • Enigma2Illusion

    Enigma2Illusion - 2024-09-16

    @wanderer51

    Well, that's why i attached the config file... :)

    I never download or execute files from unknown sources. :)

     

    Last edit: Enigma2Illusion 2024-09-16
    • - Wanderer -

      - Wanderer - - 2024-09-17

      I never download or execute files from unknown sources. :)

      :) Well, might make life a little difficult but a lot safer :)

       
  • David

    David - 2024-09-20

    Hi, I have this same problem, but maybe simpler! For 5 months I have been using a new Asus laptop, running Windows 11 fully updated. I have Bitlocker enabled on only the system drive C, and there are 3 partitions protected separately by VeraCrypt version 1.26.7 (D,E,F drives). Normally, when I boot up, I need to enter the password for each partition into the VC windows that pop up, which I feel safer doing rather than setting it up for automatic unlocking. However, today for the 3rd time only in 5 months, the 3 VC windows opened by themselves without requiring the passwords. This worries me. How can this happen? I can categorically say that when closing last night I did nothing different to usual. Any suggestions please? Thank you!

     
  • - Wanderer -

    - Wanderer - - 2024-09-20

    Hi. As @enigma2illusion said in post #2 of this thread, maybe Fast Startup is enabled. In this mode, when you shutdown the PC it actually hibernates so when you start it up again, it just returns to the previous session...

     
  • David

    David - 2024-09-22

    Thanks for your thoughts! I checked and Fast Startup is enabled. But why has it only done this 3 times out of maybe 150? I have always had to enter the passwords, except for these 3 times. I always thought computers do what they are told to do, so I expect bootup to work exactly the same each time - but it is randomly doing things differently. I find this odd!

     

Log in to post a comment.