Portable IFL media & encryption
Posted: Tue Jun 17, 2014 1:10 am
I am thinking about a situation for IFL involving backup & restore of encrypted data on a secondary disk, one which can be unmounted while a Linux OS is running from the primary disk. Supposing the encrypted disk, for example, were made with LUKS/dm-crypt as the "last" layer of abstraction on top of a regular file system, or even one made with LVM, and this inner layer included separate partitions or volumes, which I would like to backup separately, instead of the entire, huge disk. This would not be an uncommon scenario.
Looking over the information in TeraByte's knowledge base, there appear at least a couple of ways to handle this backup procedure. I saw this article, http://www.terabyteunlimited.com/howto/ ... _linux.htm , showing how to add IFL separately to an existing Linux distribution. Using that method under these conditions, I could install IFL and boot into the OS normally while then having access to the OS's tools for handling LUKS. With it I then should be able to mount the decrypted disk, open the volumes using the tools of the OS, or using the LVM tools provided with IFL itself, and I could procede to backup or restore the individual partitions or volumes, whichever the case may be. It seems to me that this should work unless I am overlooking something.
Alternatively, it may be the case that I do not or cannot install IFL onto the Linux OS disk directly, but I may be able to accomplish the same thing by using an installation of IFL on a small USB flash drive. I have not seen that there is a ready-made portable version of IFL for use in this case. Nonetheless, I see no reason why I could not insert a USB disk into the machine's USB port, format it with a Linux file system, mount it from the OS and then install the IFL program to its drive. This would allow me, just like before, to have access to its functionality while I was running the machine's regular Linux OS. At this point, the procedure described above for accessing the secondary, encrypted disk would be just the same.
Either of these two approaches seems fairly straightforward. I suppose a third approach, one which might in fact have additional merit, would be to use a small USB flash drive to install an entire Linux OS, along with IFL, making sure to include just the required tools necessary for accessing the inner partions or volumes, including the LUKS/dm-crypt program since IFL already has included LVM. I could then boot the machine from this small device independently of its existing OS. This sort of method would have the additional benefit of being usable on many other machines as well.
It would be swell if IFL already included tools for working with LUKS/dm-crypt encryption. It might be worth considering now that Truecrypt is no longer supported. It appears to have been abandoned by the developers since Windows XP, on which it was used extensively, has reached the end of support too. Furthermore, from what I have seen in quite a few places, Truecrypt is probably no longer safe to use, having been compromised in its latest rendition. Even if one only used a pre-existing copy of the program, it is not being developed and maintained. It will become irrelevant soon enough.
Looking over the information in TeraByte's knowledge base, there appear at least a couple of ways to handle this backup procedure. I saw this article, http://www.terabyteunlimited.com/howto/ ... _linux.htm , showing how to add IFL separately to an existing Linux distribution. Using that method under these conditions, I could install IFL and boot into the OS normally while then having access to the OS's tools for handling LUKS. With it I then should be able to mount the decrypted disk, open the volumes using the tools of the OS, or using the LVM tools provided with IFL itself, and I could procede to backup or restore the individual partitions or volumes, whichever the case may be. It seems to me that this should work unless I am overlooking something.
Alternatively, it may be the case that I do not or cannot install IFL onto the Linux OS disk directly, but I may be able to accomplish the same thing by using an installation of IFL on a small USB flash drive. I have not seen that there is a ready-made portable version of IFL for use in this case. Nonetheless, I see no reason why I could not insert a USB disk into the machine's USB port, format it with a Linux file system, mount it from the OS and then install the IFL program to its drive. This would allow me, just like before, to have access to its functionality while I was running the machine's regular Linux OS. At this point, the procedure described above for accessing the secondary, encrypted disk would be just the same.
Either of these two approaches seems fairly straightforward. I suppose a third approach, one which might in fact have additional merit, would be to use a small USB flash drive to install an entire Linux OS, along with IFL, making sure to include just the required tools necessary for accessing the inner partions or volumes, including the LUKS/dm-crypt program since IFL already has included LVM. I could then boot the machine from this small device independently of its existing OS. This sort of method would have the additional benefit of being usable on many other machines as well.
It would be swell if IFL already included tools for working with LUKS/dm-crypt encryption. It might be worth considering now that Truecrypt is no longer supported. It appears to have been abandoned by the developers since Windows XP, on which it was used extensively, has reached the end of support too. Furthermore, from what I have seen in quite a few places, Truecrypt is probably no longer safe to use, having been compromised in its latest rendition. Even if one only used a pre-existing copy of the program, it is not being developed and maintained. It will become irrelevant soon enough.