William Kenworthy wrote: > > > On 6/7/20 2:37 pm, Dale wrote: >> William Kenworthy wrote: >>> Hi Dale, I looked at Veracrypt and ran into the fact that it on windows >>> Veracrypt MUST be installed by an administrator which is a blocker for >>> using USB keys on computers I don't control (such as transporting files >>> securely between locations - i.e., where there is potential to lose the >>> usb key): >>> >>> see >>> https://www.veracrypt.fr/en/Using%20VeraCrypt%20Without%20Administrator%20Privileges.html >>> >>> BillK >>> >> >> Does that mean that on windoze a person can open a encryted USB stick >> without a password? From what I read, it sounds like it doesn't put >> the stick at risk, as long as you are not using key files or sharing >> your password by storing it somewhere. It just means you have to be >> admin to install Veracrypt but not to access a encrypted USB stick. >> From the way it sounds, you insert USB stick, run Veracrypt, enter >> password, do what you want with the stick, close it and then remove >> the stick. Or am I missing something? >> > It means that an administrator must install veracrypt first - if you > cant do that, you cant access the stick. It also makes the point that > any adminstrator will have access to the sticks data - not just the > user (same as root under Linux). The blocker for me was that I could > not get veracrypt installed. >
Ah I see what you are saying now. It's a privately owned laptop so that won't be a issue. She may even use a desktop system. >> I might add, when I use cryptsetup and mount a external drive I use, >> I do that as root. Since my password is only in my head, no >> password, no access root or not, right? >> > Maybe, maybe not ... > >> I'm new to this encrypted thing. I'm learning but don't know all of >> it and may never know all of it. I figured out the other day that >> when I select a two part or three part encryption, it actually >> encrypts the thing twice or three times. It's like having to pick >> two or three locks on a door instead of one. Only they have to be >> done in order and you don't really have a way to know if you did it >> right until you figure out the rest. I bet that drives the NSA and >> other Govts nuts. lol >> >> By the way, the USB stick will have instructions about things after >> I'm buried or whatever. I plan to keep the USB stick in a safe and >> share the password with the person that will be taking care of >> things. When I'm gone, they can open the USB stick to access files >> on what to do and such. Until I'm gone, they won't know what is on >> the stick or have access to it. Getting older makes one think about >> these things. :/ External drives will have things that when I'm >> gone, they gone too. >> > Paper in a sealed envelope in a safe (bank safety deposit box etc) ... > too many things to go wrong with an encrypted USB. > > Don't have a bank safety deposit box and even if I get one, that will cause issues when I kick the bucket. >> I just wonder how many encryption tools have been cracked that we >> don't know about. It's not like they going to tell us or anything. >> >> Dale >> >> :-) :-) > > Yep :) > > BillK > I'm just hoping the newer ones, after Snowden, don't have back doors etc. Now let us pray. ;-) Dale :-) :-)

