Page 2 of 2

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Tue Jul 02, 2013 5:17 am
by TeraByte Support(PP)
It certainly is good to be able to restore completely to a new/wiped drive, but most restores probably won't fall into that category. Since your drive consists of a single partition I would recommend that you create a backup of the entire drive and restore the entire drive instead of just the partition (the unpartitioned space won't be backed up). When you restore the drive image the alignment is retained automatically. Otherwise, when restoring the single partition you would need to enable 2048 alignment (in Settings or just for the destination when restoring) so the partition is restored in its proper location.

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Tue Jul 02, 2013 9:35 pm
by crawfish
Will do.

This was interesting. I have Samsung 830 256 GB and Intel X25-M 120 GB SSDs as boot drives in my two Windows 7 x64 systems. The Samsung has a 220 GB system partition with the rest unallocated, and the Intel is formatted to capacity with a single partition. The Samsung has 111 GB in use, while the Intel has 26 GB in use. Both use Truecrypt system encryption. Even though I back them up in the encrypted state without mounting them in Truecrypt, the backups compressed to 110 GB and 25 GB, respectively. I am able to use WinPE on my X25-M system, and examining the disk in WinHex without mounting it in Truecrypt, the data is indeed encrypted, but there is a ton of zeroed sectors. I guess this is the result of TRIM, which is the reason it compressed so well. Does this make sense? I wasn't expecting it after reading the KB article.

Unfortunately, the WinPE disc I made a couple of years ago doesn't work on my new Z87 system, which has the Samsung SSD, so without moving it to the other system, I couldn't look at it outside of it being mounted in Truecrypt in Windows, and I'm inferring the zeroed sectors for it based on similarity to my Intel SSD results. The USB keyboard doesn't work in WinPE on the Z87 system, and the new motherboard doesn't have a PS/2 connector. Any idea how to get WinPE to work in such a system? If not, it would be great if the IFL GUI disc included some diagnostic tools. Actually, that would be great regardless. Does IFL come with anything like a disc sector editor or gparted? I would really love to be able to do everything I needed to do the last few days all in IFL.

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Wed Jul 03, 2013 6:57 am
by TeraByte Support(PP)
It would have to be from TRIM or if you wiped the drive and then restored mounted in IFL. Normally, all the sectors contain data (at least they do when first encrypted).

Is the WinPE disc you're using based on Windows 7? You could try TBWinPE/RE with Windows 7 or 8. If you're using USB 3.0 ports you may need to add USB 3.0 drivers. I've only seen rare cases where standard USB keyboards or mice didn't work properly in WinPE. Usually, USB support is very good.

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Wed Jul 03, 2013 12:24 pm
by TeraByte Support(TP)
crawfish wrote:
> Will do.
>
> Actually, that
> would be great regardless. Does IFL come with anything like a disc sector
> editor or gparted? I would really love to be able to do everything I needed
> to do the last few days all in IFL.

The IFL boot disk has a text mode hex editor 'hexedit' that will run in a terminal window. For example, you would use 'hexedit -s /dev/sda' to look at the first hard drive sector by sector. Or to to look at the first partition, it would be 'hexedit -s /dev/sda1'. Here's the man page for it: http://linux.die.net/man/1/hexedit

The boot disk has 2 text mode partitioning tools:
fdisk for MBR drives: http://linux.die.net/man/8/fdisk (e.g. 'fdisk -l /dev/sda' to list partitions on the first hard drive)
gdisk for GPT drives: http://linux.die.net/man/8/gdisk

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Wed Jul 03, 2013 6:44 pm
by crawfish
Paul, I think it's got to be TRIM that is responsible. What about after restoring an image of an encrypted partition? It seems like I would need to run Intel SSD Toolbox or Samsung Magician to "optimize" the SSD, because I don't see how IFL could avoid writing those zeroed sectors or know they are unused and issue TRIM commands on them after writing them. I did run these tools after doing the system encryption, as I'm unclear whether TRIM commands are issued as TrueCrypt is performing the encryption. Its documentation only says it doesn't block TRIM commands, and I don't know if they're being issued for the free space it encrypts.

Tom, thanks for the info on the Linux tools. I will check them out next time I'm in IFL.

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Thu Jul 11, 2013 9:55 pm
by crawfish
It looks like my concerns about data leakage were unfounded for an SSD with working TRIM. See this thread for more:

http://forums.truecrypt.org/viewtopic.p ... torder=asc

So my plans now are to back up to the unencrypted state, restore, and then perform system encryption, relying on TRIM to wipe out any data leakage that may have occurred due to wear-leveling.

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Sun Jul 14, 2013 6:38 am
by userX
Paul said:

> "Note that when using IFL GUI it's possible to mount the encrypted Windows partition using TrueCrypt. You can then do a more normal backup of used sectors, use compression, etc. This type of backup can be restored back into its encrypted state by mounting the partition with TrueCrypt and then restoring to the mount point."

Hi, Paul. I have a question about this procedure. I just want to be clear what you meant exactly. If I understand you right, you meant that the encrypted partition could be mounted with Truecrypt after booting into IFL. Then, while mounted, the IFL procedure could be applied to it and the backup data saved to another disk. Were you implying that the disk to which it was backed up could be itself encrypted or not? Were you implying that it would retain its encrypted state when the backup data was saved to another disk? It seems like you were meaning such, but I am not certain.

Additionally, can you tell me whether this same procedure could be done when the original disk had whole disk encryption with preboot authentication?

Re: IFL Settings for backing up Truecrypt System Partition

Posted: Sun Jul 14, 2013 5:36 pm
by TeraByte Support(PP)
The TrueCrypt mounted partition will be seen as unencrypted (IFL can back up used sectors, etc.). Whether or not the backup image (TBI file) is encrypted depends on how it's created. If you save it to a standard unencrypted partition it will not be encrypted. If you encrypted it with IFL it will be encrypted via that method. If you save it to another TrueCrypt mounted partition it will be encrypted by TrueCrypt as it's written.

When mounting partitions that require preboot authentication you must select that option when mounting. Otherwise, the procedure is the same.