<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[Be able to encrypt and decrypt your entire system after install]]></title>
    <link>http://brainstorm.ubuntu.com/item/23/</link>
    <description><![CDATA[Currently I can encrypt an ubuntu system during install, but if I did not I have to reinstall to get encryption. I would like a simple way to tell ubuntu to encrypt the system or a part of it, such as:<br /><br />Swap<br />Home<br />Root<br />All<br />
<br />


<b>[787 votes] Solution #1: Auto-generated solution of idea #23</b>
<br />

<br />
<br />



]]></description>

    <language>en-us</language>
    <pubDate>Thu, 28 Feb 2008 14:43:33 +0000</pubDate>
    <lastBuildDate>Fri, 17 Apr 2009 02:29:23 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/23/</guid>
        <item>
  <title>Comment from Veejay</title>
  <description><![CDATA[You might want to look into the likes of truecrypt (http://www.howtoforge.com/truecrypt-with-gui-on-ubuntu-7.10), that could suit your needs.]]></description>
  <pubDate>Thu, 28 Feb 2008 14:48:39 +0000</pubDate>
</item>
        <item>
  <title>Comment from will_in_wi</title>
  <description><![CDATA[That doesn't allow me to encrypt existing volumes with existing data, it just allows me to encrypt new volumes. Also, if I were to encrypt the root partition, it could not be booted from. Lastly, ubuntu uses a different encryption tech than truecrypt, and if possible I would like to use the ubuntu standard encryption. Ideally, If I were to install ubuntu and _then_ enable encryption, I would get the exact same system as if I were to install ubuntu _with_ encryption.]]></description>
  <pubDate>Thu, 28 Feb 2008 15:04:53 +0000</pubDate>
</item>
        <item>
  <title>Comment from chunk08</title>
  <description><![CDATA[It would still require a Live CD. You can't encrypt a partition while it is mounted...]]></description>
  <pubDate>Fri, 29 Feb 2008 01:43:51 +0000</pubDate>
</item>
        <item>
  <title>Comment from d3xter</title>
  <description><![CDATA[The alternate CD is completly mess. When I booted from alternate CD, my wi-fi didn't work and installer was hanged-up after setting the partitions.<br /><br />The only good solution is to adapt standard installer and make a support for encrypted volumes.<br />]]></description>
  <pubDate>Fri, 29 Feb 2008 09:04:59 +0000</pubDate>
</item>
        <item>
  <title>Comment from dei</title>
  <description><![CDATA[absolutely against it!<br />if someone (most likely noob) screws up his system and asks for help he will most likely not know his encryption-key and his data is lost. --> Ubuntu will be the "bad Guy" who has eaten up all the data<br /><br />disc-encryption is a feature for rather professional or geek use, which know what they're installing]]></description>
  <pubDate>Fri, 29 Feb 2008 10:36:48 +0000</pubDate>
</item>
        <item>
  <title>Comment from jwoods</title>
  <description><![CDATA[Partially encrypting a disk is a really bad idea.  In the past, full disk encryption wasn't available, so partial encryption was the best compromise we could get.<br /><br />The options should be full disk encryption or no encryption.<br /><br />If I encrypt data, I expect it to be inaccessible.  Now, consider that the data has to be decrypted to work with.  What if I have data files in my home directory which are encrypted, but are loaded into an application to work with?  Now, it's entirely possible that the data will be swapped to disk.  If swap isn't encrypted, the data is vulnerable.<br /><br />Also consider that many files may write to various temporary directories which aren't encrypted.<br /><br />Partial encryption is a bad idea -- there are simply too many possibilities for data leak, especially for inexperienced users, to consider.  If it's worth encrypting, it's worth doing right.]]></description>
  <pubDate>Fri, 29 Feb 2008 13:19:25 +0000</pubDate>
</item>
        <item>
  <title>Comment from rawsausage</title>
  <description><![CDATA[Technically the best is to use appropriate md crypt plugins and encrypt the LVM volume. You shouldn't use file containers on top of any journaled fs - there are real reasons for that.<br /><br />Enabling the full disc encryption on the run is not impossible. All it requires is X gigabytes of unallocated space for a temporary partition. Move everything there, modify grub config, reboot into configuration mode, remove the previous partitions / lvm. Create new one as encrypted, initialize it, create new fs, copy the stuff from temp partition back, fix bootloader, reboot. Voila.<br /><br />The problem is... How to make it really reliable. It can screw up things. A lot.]]></description>
  <pubDate>Fri, 29 Feb 2008 22:26:48 +0000</pubDate>
</item>
        <item>
  <title>Comment from casteyde</title>
  <description><![CDATA[With partial encryption, it's really simple to make clear text attack (on standard binaries/configuration files). So partial encryption is quite as useless as no encryption at all. However, full encryption is not safe either. Metadata tends to be constants and can be guessed, so clear text attack are still feasible with full encrypted filesystems.]]></description>
  <pubDate>Sun, 02 Mar 2008 08:29:31 +0000</pubDate>
</item>
        <item>
  <title>Comment from pturing</title>
  <description><![CDATA[<br />It is possible to in-place encrypt an unencrypted partition, and to reverse this.<br /><br />However, this is very dangerous because if the system loses power, etc. while this operation is being done, the partition is hosed.]]></description>
  <pubDate>Mon, 03 Mar 2008 16:39:58 +0000</pubDate>
</item>
        <item>
  <title>Comment from scubanator87</title>
  <description><![CDATA[Maybe some work with true crypt could be done to port their M$ implementation of it. Also would it be such a bad idea to include trucrypt by default for better security practices. ]]></description>
  <pubDate>Mon, 10 Mar 2008 03:30:16 +0000</pubDate>
</item>
        <item>
  <title>Comment from Eldmannen</title>
  <description><![CDATA[Please I need encryption!<br /><br />During the Vietnam War, my commanding officer, Colonel Morrison, gave us orders to rob the Bank of Hanoi to help bring the war to an end. We succeeded in our mission, but on returning to our base four days after the end of the war, we found our C.O. murdered by the Viet Cong and his headquarters burned to the ground. Therefore no proof existed that the we were acting under orders, and we were sent to prison by a military court. We were sent to Fort Bragg, from which we escaped before we could actually stand trial.<br /><br />We are a group of United States Army Special Forces who work as soldiers of fortune while being on the run from the military for a "crime we didn't commit".<br /><br />This is why we need encryption!]]></description>
  <pubDate>Thu, 13 Mar 2008 00:53:31 +0000</pubDate>
</item>
        <item>
  <title>Comment from michaelzap</title>
  <description><![CDATA[Full-disk encryption is absolutely essential to anyone who values the privacy of their data, and the current possibilities are confusing and difficult to implement. The installer could warn newbies not to do this unless they fully understand the risks. For many people this is not an optional extra but a must-have feature, so I think it's foolish to be so afraid that some noobs might mess it up and complain that you argue against implementing it altogether.]]></description>
  <pubDate>Thu, 13 Mar 2008 03:52:36 +0000</pubDate>
</item>
        <item>
  <title>Comment from jcdutton</title>
  <description><![CDATA[In windows, a program called becrypt allows one to do whole disk encryption.<br />It encrypts the entire disk while it is being used. I.e. While it is mounted.<br />One can even shutdown the PC during the encryption process.<br />It prompts for a password on cold boot and return from hibernate.<br />It would be nice to have a Linux whole disk encryption that could do the same. When translated into Linux, the password would be asked for before the GRUB prompt.<br /> ]]></description>
  <pubDate>Fri, 26 Sep 2008 18:43:48 +0000</pubDate>
</item>
        <item>
  <title>Comment from matsonfamily</title>
  <description><![CDATA[    This isn't a idea for privacy-freaks only; this is a great idea for a laptop.  Laptops are very commonly stolen, and getting data off of most windows/osx/*nix (r) partitions is something that anyone can do... no hacker needed.  I think the average user just needs the /home/ partition encrypted, though... not swap, /, etc...  they just need enough protection so that when their laptop is stolen, they are only out the money, and do not have to worry about their credit ratings, their bills, their financial accounts, their very personal emails and files, etc...]]></description>
  <pubDate>Sun, 21 Dec 2008 08:36:09 +0000</pubDate>
</item>
        <item>
  <title>Comment from danielldf</title>
  <description><![CDATA[well in a few days Jaunty will be on the streets<br /><br />there any news about full disk encryption in this new version???<br /><br /><br />thankz]]></description>
  <pubDate>Fri, 17 Apr 2009 02:29:23 +0000</pubDate>
</item>
      </channel>
</rss>
