Recommended Posts

Hi y'all, need help.

All of us have some documents they need protecting. I had a solution that worked great for me for years - a Keepass file for passwords, and a Truecrypt container for bank and credit statements. Both were saved in Dropbox and so were accessible from any computer I owned.

I recently bought an iPad to replace Nexus 7 that was driving me nuts with slowdowns and crashes. I ended up liking that iPad a lot more than I thought I would, despite lack of customization and control over OS the thing just works. I spend much more time actually _doing_ things on it. I barely touch the desktop anymore, unless I need to process some photos or do my bills. I have to do my bills from the desktop because that's the only way I can save the statements to my Truecrypt container.

So, here's the question.. What do you use for a protected file storage that can be shared between several different computers and an iPad ?

Is there a way on iOS to access a Truecrypt container from cloud storage ? Does it require caching the entire container locally ?

Is there an online solution that is proven safe ? I understand that nothing is 100% safe online, but a bank level security combined with some sort of file encryption would do.

Right now I am thinking of using AES encrypted 7zip archives with Box.com, but there's got to be a better way.

You do know your ipad data is already encrypted right?  Did you turn on passcode? And if you loose it you an just remotely wipe it

 

http://help.apple.com/icloud/#/mmfc0ef36f

Erase your device

Are you storing your account numbers, and SS# on these statements? Most statements no longer have this sort of info on them - and pretty much other than some numbers don't really contain all that much info that all that private.

You can turn off simple passcode and use a better password and even enable wipe on 10 failed.. I would think its secure enough to have some old bank statements on to be honest.

Yes I know iPad is encrypted, however I want to share data across devices. I need a central storage solution that works with all of my computers, not just one of them.

 

I have no control over what information is being put on statements. Can't rely on each provider making sure they don't put anything sensitive on them. This kind of data simply does not belong in the open.

 

It looks like Boxcrypt could work, I need to figure what it does on iPad.

Yes I know iPad is encrypted, however I want to share data across devices. I need a central storage solution that works with all of my computers, not just one of them.

 

I have no control over what information is being put on statements. Can't rely on each provider making sure they don't put anything sensitive on them. This kind of data simply does not belong in the open.

 

It looks like Boxcrypt could work, I need to figure what it does on iPad.

 

Boxcryptor doesn't do anything to or on the ipad itself.  It is an encryption wrapper on a computer that encrypts a file before sending it off to a cloud provider.  The iOS app just allows files from the cloud provider to download to the app itself and be viewed. 

Well, Boxcryptor could be it, but it's major limitation is that free version only links 2 devices and you need to unlink one of them to add another one. In a household with 4 tablets, 2 smartphones and a few computers, this won't suffice, and I am not paying $50 each year for a Pro subscription.

I decided to keep my Truecrypt container for archiving past data, and use encrypted zip files for current year's statements. Hopefully eventually someone would come up with a reasonable iOS encrypted container solution.

Who exactly are you protecting your files from?  They are encrypted on your ipad as we stated, they are encrypted in the cloud and they use an encrypted transfer method.

 

post-14624-0-51595900-1394623747.jpg

 

So your protecting your bank statements from the company your storing your files with?  Or the government?  Both of which prob have easier ways to access that information ;)

https://www.dropbox.com/help/27/en

https://sugarsync.custhelp.com/app/answers/detail/a_id/201/kw/security

 

Look up pretty much every cloud provider - they are very security aware.  I find it unlikely someone at dropbox is looking into your files and thinking - hey I can sell this info for identity theft, etc.  The first case of this would completely shutdown not only dropbox but pretty much every company like them.  So I think they take it pretty serious - prob more so than your CC company or online store you shop with that stores your CC numbers, etc.

 

Its more likely that say your CC company or a store you shop with employee's would sell of this data for profit where this data is just easy search in a database and prob 1000's of peoples info in a nice spreadsheet vs and employee of say dropbox weeding through users files looking for info that might be useful to sell for profit or use themselves..

 

While I agree everyone should be concerned with loss of your personal data..  Curious who guards your mailbox when statements come there? Keep in mind these companies are storing your data like where your original bank/company is storing the information they give you in the statement.  What your doing is hiding the information from the company you trust to store the data for you.. 

 

If your worried that online storage company has access to your encrypted data - I would look to spideroak, I believe their claim to fame is even they do not have access.

 

https://spideroak.com/whyspideroak

Complete Privacy Guaranteed

  • SpiderOak never stores or knows a user's password or the plaintext encryption keys which means not even SpiderOak employees can access the data
  • Our zero-knowledge privacy approach means we can never betray the trust of our users

 

But to me, this is a bit over the top for some bank statements ;)

Bank statements, credit card statements, tax documents, medical bills... a lot of them have date of birth, full address, full or part social security number - this info needs to be stored somewhere somehow. And most of it nowadays comes in electronic format. This is ID thief's heaven - the whole system of using SSN's is broken, but that's beyond the point.

 

You can leave this information unencrypted in Dropbox, but after several publicized accidents - one when Dropbox opened user accounts for hours to anyone to browse through - I don't trust them much. Or OneDrive, or Google. I have no choice but to trust banks but at least the banks are supposed to have a system in place to vet their employees, and have decades if not centuries of security obsessed corporate culture (not that it prevents any issues), and there are laws that make them responsible for at least some monetary losses of their customers due to internal breeches. I have no idea how cloud services vet their employees, and as far as I know they can read anything in anybody's account and have zero oversight and zero responsibility.

 

You can leave the statements on bank site of course, but good luck getting them if you switch banks, or if your bank is bought out. And many only let you go back 1-2 years.

 

Also, banks and medical offices simply don't have all of your info - just (important) bits related to your business with them.

 

Short of printing every record and locking it up in a safe somewhere - which is really not a good solution anyway - the only sensible approach, in my view, is to assume that some of your data may become compromised sooner or later, and prepare for this by encrypting access. A thief sophisticated enough and equipped well enough to break an AES encrypted file with 12-15 character password likely isn't after your individual data anyway.

Bank statements, credit card statements, tax documents, medical bills... a lot of them have date of birth, full address, full or part social security number - this info needs to be stored somewhere somehow. And most of it nowadays comes in electronic format. This is ID thief's heaven - the whole system of using SSN's is broken, but that's beyond the point.

 

You can leave this information unencrypted in Dropbox, but after several publicized accidents - one when Dropbox opened user accounts for hours to anyone to browse through - I don't trust them much. Or OneDrive, or Google. I have no choice but to trust banks but at least the banks are supposed to have a system in place to vet their employees, and have decades if not centuries of security obsessed corporate culture (not that it prevents any issues), and there are laws that make them responsible for at least some monetary losses of their customers due to internal breeches. I have no idea how cloud services vet their employees, and as far as I know they can read anything in anybody's account and have zero oversight and zero responsibility.

 

You can leave the statements on bank site of course, but good luck getting them if you switch banks, or if your bank is bought out. And many only let you go back 1-2 years.

 

Also, banks and medical offices simply don't have all of your info - just (important) bits related to your business with them.

 

Short of printing every record and locking it up in a safe somewhere - which is really not a good solution anyway - the only sensible approach, in my view, is to assume that some of your data may become compromised sooner or later, and prepare for this by encrypting access. A thief sophisticated enough and equipped well enough to break an AES encrypted file with 12-15 character password likely isn't after your individual data anyway.

 

And I thought I was paranoid.  The answer is simple: Don't store any of that information in the cloud.  You cannot prevent the individual companies from storing the information electronically and making it available to you over the internet but that doesn't mean you have to store it anywhere else and make it available.  Do this: Get a NAS and store those documents on the nas.  Then make sure that the storage device is not accessible to the outside world.  You could then use truecrypt to encrypt that storage if you are still paranoid.  Bing, bang, boom...all done.

 

Also...for redundancy and backups..backup the nas to an additional physical hard drive and place that hard drive in a safety deposit box.

  • 2 weeks later...

And I thought I was paranoid.  The answer is simple: Don't store any of that information in the cloud.  You cannot prevent the individual companies from storing the information electronically and making it available to you over the internet but that doesn't mean you have to store it anywhere else and make it available.  Do this: Get a NAS and store those documents on the nas.  Then make sure that the storage device is not accessible to the outside world.  You could then use truecrypt to encrypt that storage if you are still paranoid.  Bing, bang, boom...all done.

 

Also...for redundancy and backups..backup the nas to an additional physical hard drive and place that hard drive in a safety deposit box.

 

 

This is not an answer, it's a limitation.

 

I looked at SpiderOak and Wuala, but I don't think I am ready to trust them just yet.

 

Winzip AES256 solution works good for protecting statements, but is a royal PITA for editable documents... as they have to be re-zipped and re-uploaded afer each edit on iPad.

 

For now, I'm afraid that's the only safe, if cumbersome, method. Although CloudOn seem to support password protected Excel files... will check that one, too. None of my spreadsheets have any account #s in them, anyway.

There's an app called Disk Decipher that reads Truecrypt (and FreeOTFE and LUKS) volumes, even on Dropbox without having to cache the entire container locally.

 

Once I RTFM'd, I was able to open the container in Dropbox and read files. For now it's read only, but I can use Winzip for individual files & transfer them to TC container in bulk later.

 

Highly recommended.

There's an app called Disk Decipher that reads Truecrypt (and FreeOTFE and LUKS) volumes, even on Dropbox without having to cache the entire container locally.

 

Once I RTFM'd, I was able to open the container in Dropbox and read files. For now it's read only, but I can use Winzip for individual files & transfer them to TC container in bulk later.

 

Highly recommended.

 

That has to be the worst idea I have seen in a long time.  Talk about a convoluted and wrong implementation.  The moment I saw view only is the moment I said no.  Boxcryptor is what you are looking.  Stop being cheap and buy a subscription for it.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Apple has clarified Series 9 was left off the watchOS 27 compatibility list by mistake.
    • Signal accuses UK government of using child safety as cover for mass surveillance by David Uzondu Recently, the UK's Home Office announced a sweeping set of proposals to make Britain the "first country in the world" where children cannot share or view nude photos on their smart devices, an initiative that authorities claim will protect children from online predators and combat pornography. In response, Signal believes that while the government must keep children "safe" and "protected," it should do so through social services and education, not by "surveillance, funding cuts, and cover-ups." The company called the plan "dystopian" and warned that it violates everyone's fundamental right to privacy, arguing that scanning on the presumption of nudity will only strengthen the market dominance and data control of giant corporations like Apple and Google. The statement continues by accusing the government of hiding its true intentions under the guise of child safety. Signal argues that the Home Office is building an invisible surveillance infrastructure that remains ripe for exploitation by future administrations and authoritarian regimes. According to the company, this aggressive approach completely ignores the actual needs of young people, such as properly funded schools and mental health services. Tech companies like Apple and Google have a three-month window to implement these mandatory device-level filters across the United Kingdom. If these tech firms refuse to comply with the mandate, the government will pass emergency legislation to force them to comply, threatening massive fines and even going after the CEOs of these companies with criminal charges. The technology will work by blocking explicit images directly on the operating system of all smartphones and tablets by default. This system monitors the device camera and third-party apps to intercept nudity before anyone can upload or send the image. Adults can still view explicit content, but only after completing a strict age verification check to unlock their devices. Several bodies like the NSPCC and Barnardo's praised the Home Office's decision, arguing that device-level intervention stops the cycle of grooming before it starts. The Internet Watch Foundation (IWF) also supported the policy, claiming that tech companies can implement on-device checks "without threatening privacy or collecting any data."
    • Did you watch the keynote? It is way beyond what is described in this article. Looks interesting. Now it is time for them to deliver unlike what happened in 24.
    • It pretty much has to be compatible with MS Office or it is going nowhere. The rest of the world runs office including Europe. If it is not compatible it will not survive.
    • Incredible deal gets you free NVMe 512GB SSD with AMD AM5 B850 motherboard for only $150 by Sayan Sen Earlier this week we covered the story of an interesting PC case wherein you can build two full-size computers inside it as in it can house and run an AMD and an Intel system simultaneously. Speaking of building PCs, these are hard times to make one for sure as prices are often very high except during flash sales or discounts. If you are in the market for a 1080p gaming PC then Nvidia's 8GB RTX 5060 Ti is currently on sale for just $330 and you get the latest James Bond game too, for free. Speaking of which, right now there is another incredible sale going on as we can get a free 512 GB NVMe SSD from TeamGroup in the form of the G50 alongside the purchase of an AMD B850 socket AM5 motherboard for only $150 (purchase link under the specs table down below). Getting an AM5 motherboard now in 2026 will be a wise investment for sure, especially since AMD confirmed its commitment to support the socket till at least 2029. The MSI PRO B850M-P WIFI is a micro-ATX motherboard that is compatible with AMD Ryzen 9000 series processors. Since it is AM5, the motherboard works with DDR5 memory and includes MSI’s Memory Boost technology, along with EXPO and XMP support. Connectivity features include built-in Wi-Fi 7 paired with a 5G LAN solution. The board offers a PCIe 5.0 M.2 slot with MSI’s EZ M.2 Shield Frozr II thermal solution, that is said to help maintain SSD performance by providing ample cooling against overheating. The technical specifications of the MSI PRO B850M-P WIFI motherboard are given in the table below: Specification Value Form Factor Micro-ATX (mATX), 243.84 × 243.84 mm Chipset AMD B850 Socket AM5 Supported Processors AMD Ryzen 9000, 8000, and 7000 Series Desktop Processors Memory Slots 4 × DDR5 UDIMM Max Memory 256 GB Memory Speed DDR5 8200–5600 MT/s (OC), DDR5 5600–4800 MT/s (JEDEC) Display Outputs 1 × HDMI 2.1 (up to 4K 60Hz) 1 × DisplayPort 1.4 (up to 4K 60Hz) PCIe Slots 1 × PCIe 5.0 x16 (CPU) 3 × PCIe 3.0 x1 (Chipset) Audio Codec Realtek ALC897 Audio Channels 7.1-Channel High Definition Audio M.2 Slots 3 × M.2 slots M.2_1: PCIe 5.0 x4 (CPU) M.2_2: PCIe 4.0 x4 (CPU) M.2_3: PCIe 4.0 x2 (Chipset) M.2 Device Sizes M.2_1: 2280/2260 M.2_2: 2280/2260 M.2_3: 2280 SATA Ports 4 × SATA 6Gb/s RAID Support SATA: RAID 0, 1, 10 NVMe: RAID 0, 1, 5, 10 Rear USB Ports 4 × USB 2.0 2 × USB 5Gbps Type-A 1 × USB 10Gbps Type-A 1 × USB 10Gbps Type-C Front USB Headers 4 × USB 2.0 4 × USB 5Gbps Type-A 1 × USB 10Gbps Type-C LAN Realtek 8126VB 5Gb Ethernet Wireless Networking Wi-Fi 7 (802.11 a/b/g/n/ac/ax/be) Tri-band 2.4GHz / 5GHz / 6GHz MU-MIMO, MLO, 4KQAM Up to 2.9Gbps Bluetooth Bluetooth 5.4 Internal Power Connectors 1 × 24-pin ATX Power 1 × CPU Power 1 × PCIe Power (8-pin) Cooling Headers 1 × CPU Fan 1 × Combo Fan/Pump 3 × System Fan RGB Headers 3 × Addressable RGB Gen2 (JARGB_V2) 1 × RGB LED (JRGB) Additional Internal Headers 2 × Front Panel (JFP) 1 × Chassis Intrusion (JCI) 1 × Front Audio (JAUD) 1 × COM Port (JCOM) 1 × JDASH Tuning Controller 1 × TPM 2.0 Header The free TeamGroup T-FORCE G50 NVMe SSD is a PCIe Gen4 and as such it promises to deliver sequential read speeds of up to 5,000 MB/s, helping accelerate game loading, file transfers, and everyday computing tasks. The SSD features an InnoGrit controller and SLC caching technology to support consistent performance. An ultra-thin, patented graphene heatsink is included to aid in heat dissipation. The NAND flash is based on TLC which means it has plenty of endurance up its sleeve. The random performance may not be as amazing as other drives with DRAM though. Still it should be very good since it can access system memory via HMB to use it as its DRAM cache. The technical specifications of the TeamGroup 512GB G50 NVMe SSD are given in the table below: Specification Value Model / Part Number TM8FFE512G0C129 Form Factor M.2 2280 Interface PCIe Gen4x4 with NVMe Sequential Read Speed Up to 5,000 MB/s Sequential Write Speed Up to 2,500 MB/s Endurance (TBW) 325 TBW DRAM Cache No Cache Technology SLC Cache Controller InnoGrit Controller Solution Operating Temperature 0°C to 70°C Storage Temperature -40°C to 85°C Weight 7 g Dimensions 80.0 × 22.0 × 3.7 mm Vibration Resistance 80 Hz ~ 2,000 Hz / 20G Shock Resistance 1,500G / 0.5 ms MTBF 3,000,000 hours Get it at the link below: MSI PRO B850M-P WIFI AM5 AMD motherboard + Team Group T-FORCE G50 TM8FFE512G0C129 512GB SSD (free gift): $149.99 (Sold and Shipped by Newegg US) This Newegg deal is US-specific and not available in other regions unless specified. This is a first-party seller link (at the time of article publishing); ensure that you also purchase from a first-party seller link only. If you don't like it or want to look at more options, check out the previous deals that we have covered, OR you can also visit Amazon US deals page. Get Prime (SNAP), Prime Video, Audible Plus or Kindle / Music Unlimited. Free for 30 days. As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Very Popular
      Captain_Eric earned a badge
      Very Popular
    • One Month Later
      amusc earned a badge
      One Month Later
    • One Month Later
      DJC50PLUS earned a badge
      One Month Later
    • Week One Done
      DJC50PLUS earned a badge
      Week One Done
    • Proficient
      Eric Biran went up a rank
      Proficient
  • Popular Contributors

    1. 1
      +primortal
      503
    2. 2
      PsYcHoKiLLa
      223
    3. 3
      ATLien_0
      87
    4. 4
      Steven P.
      80
    5. 5
      +Edouard
      80
  • Tell a friend

    Love Neowin? Tell a friend!