-
All replies
-
Helpful answers
-
-
Oct 11, 2015 11:21 AM in response to antdudeby MrHoffman,★HelpfulMove the data on the external device somewhere else temporarily, then use Disk Utility to reformat the device while selecting HFS Extended Journaled Encrypted. Probably as one partition, and encrypted. You can also create encrypted disk images or sparse bundles on the external storage, and which might be preferable in some cases; that doesn't require encrypting the whole device. That too uses Disk Utility, via the new disk image mechanism.
-
Oct 11, 2015 11:21 AM in response to Kappyby antdude,Kappy wrote:
Why?
Why ask why, Rocky J. Squirrel? Security!
-
Oct 11, 2015 11:25 AM in response to MrHoffmanby antdude,MrHoffman wrote:
Move the data on the external device somewhere else temporarily, then use Disk Utility to reformat the device while selecting HFS Extended Journaled Encrypted. Probably as one partition, and encrypted. You can also create encrypted disk images or sparse bundles on the external storage, and which might be preferable in some cases; that doesn't require encrypting the whole device. That too uses Disk Utility, via the new disk image mechanism.
Wow, no way to avoid those? Thanks.
-
Oct 11, 2015 11:31 AM in response to antdudeby Kappy,Why do you need the security, antman? Are you an NSA employee? If you don't really need encryption, then don't use it. It will prove more trouble than it's worth. Just something to chew on. You don't need to reply. Just give it some thought before you do it.
-
Oct 11, 2015 11:36 AM in response to Kappyby antdude,Kappy wrote:
Why do you need the security, antman? Are you an NSA employee? If you don't really need encryption, then don't use it. It will prove more trouble than it's worth. Just something to chew on. You don't need to reply. Just give it some thought before you do it.
Why don't you share your data with us like your financial records?
-
Oct 11, 2015 12:07 PM in response to antdudeby Kappy,Sure. If you know where I live come knock on the door. Otherwise, I'd say my records are pretty secure. My computers are behind hardware routers requiring passwords for access, so I think my info is fairly secure. And, any data I really want to be secure I don't keep on the computer. I lock it in a safe off-premises.
Besides, I doubt seriously that you have enough wealth for anyone to be interested in your files. And, if you really had wealth the records on your computer would not be of much value to anyone. What's on the computer would not give someone access to the money.
I didn't wish to make a debate out of this, but I guess that is your intent given your reply.
-
Oct 11, 2015 12:42 PM in response to antdudeby MrHoffman,antdude wrote:
Wow, no way to avoid those? Thanks.
No way to avoid what? Disk Utility? Well, you can certainly use the command line, if you're so inclined. hdiuti and diskutil, etc. Either an entire partition on the volume, or via a sparse bundle on an existing partition and existing file system.
Unlike Kappy apparently, I do use encryption on (some) external storage. There are trade-offs with using and not using encryption on removable storage, of course.
-
Oct 11, 2015 12:55 PM in response to MrHoffmanby antdude,MrHoffman wrote:
antdude wrote:
Wow, no way to avoid those? Thanks.
No way to avoid what? Disk Utility? Well, you can certainly use the command line, if you're so inclined. hdiuti and diskutil, etc. Either an entire partition on the volume, or via a sparse bundle on an existing partition and existing file system.
Unlike Kappy apparently, I do use encryption on (some) external storage. There are trade-offs with using and not using encryption on removable storage, of course.
The reformat part. I noticed FileVault can encrypt and decrypt on the fly on the internal drives. I was hoping Mac OS X could do the same with external TM drives.
Trade offs as in slower speeds with encryption?
-
Oct 11, 2015 3:42 PM in response to antdudeby MrHoffman,★Helpfulantdude wrote:
The reformat part. I noticed FileVault can encrypt and decrypt on the fly on the internal drives. I was hoping Mac OS X could do the same with external TM drives.
That uses diskutil. I much prefer a copy as — if something blows up part way through the encryption process, what is left readable and what is not? — but if you're exceptionally brave, you can convert in place using diskutil.
Trade offs as in slower speeds with encryption?
Potentially. Hard disks are glacial, which means the encryption isn't that much of an added burden. The usual trade-offs are the loss of keys, difficulties with portability across operating systems, and the need for a long and random key for reasonable security.
-
Oct 11, 2015 3:44 PM in response to MrHoffmanby antdude,MrHoffman wrote:
antdude wrote:
The reformat part. I noticed FileVault can encrypt and decrypt on the fly on the internal drives. I was hoping Mac OS X could do the same with external TM drives.
That uses diskutil. I much prefer a copy as — if something blows up part way through the encryption process, what is left readable and what is not? — but if you're exceptionally brave, you can convert in place using diskutil.
Trade offs as in slower speeds with encryption?
Potentially. Hard disks are glacial, which means the encryption isn't that much of an added burden. The usual trade-offs are the loss of keys, difficulties with portability across operating systems, and the need for a long and random key for reasonable security.
Thanks. Wow, those trade offs scare me. Portable across OSes? Like Windows? I didn't think Windows could read Mac's FS. Long and random keys? I thought FileVault used the Mac OS X's accounts' passwords if enabled.