<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Commentaires sur : Détecter truecrypt : TCHunt vs FI TOOLS</title>
	<atom:link href="http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/</link>
	<description>A draft for /b/tard guys.</description>
	<lastBuildDate>Tue, 14 Feb 2012 14:13:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>Par : Question sur le chiffrement de disque &#124; Artiflo Inside</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2288</link>
		<dc:creator>Question sur le chiffrement de disque &#124; Artiflo Inside</dc:creator>
		<pubDate>Tue, 01 Sep 2009 18:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2288</guid>
		<description>[...] est capable de suspecter des fichier TC mais pas encore des partitions : http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/ et aussi [...]</description>
		<content:encoded><![CDATA[<p>[...] est capable de suspecter des fichier TC mais pas encore des partitions : <a href="http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/" rel="nofollow">http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/</a> et aussi [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Rob Zirnstein</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2160</link>
		<dc:creator>Rob Zirnstein</dc:creator>
		<pubDate>Fri, 24 Jul 2009 16:30:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2160</guid>
		<description>FI TOOLS was developed with no knowledge of TC Hunt.  We used our own technologies to acomplish the ability to identify encrypted files and, in some cases, that a headerless encrypted file was created with TrueCrypt.  The methods that TC Hunt uses (at least in version 1.0) are clearly described, and they are completely different than our methods.  To assume that we copied them is wrong.

TC Hunt identifies files as being TrueCrypt or not.  Our software identifies 3,300+ different types of files.  One of those is Encrypted Data (Headerless), another is TrueCrypt Data.  The two false positives in the TC Hunt test appear to have been incorrectly labeled as TrueCrypt.  In the FI TOOLS test, those files appear to have been correctly identified as Encrypted Data (Headerless).  Since the author admitted that those files actually are encrypted, with a method other than TrueCrypt, they should be counted as correct positives for FI TOOLS.  That moves FI TOOLS to 7 correct identifications out of 8 files, and TC Hunt to 5 correct identifications out of 8.

I do not see any proof of the jouib6.sys file being identified incorrectly by FI TOOLS.  Please make all of these test files available for testing by other people and/or provide all of the details about the files tested.

The 5+ minutes required for FI TOOLS to identify these files indicates that the test may have been run on a slow computer (or slow virtual environment).  FI TOOLS has to read the entire file for some file types, when configured to read beyond the first megabyte, in order to maintain our high accuracy.  I didn&#039;t think that slower configuration was the default, but I will look into it.  Would the author/tester please document any configuration changes that they made before the test?

Since these two tools use completely different methods, I recommend that FI TOOLS be used to identify all of the files on a hard drive, then use TC Hunt to get a second opinion on the files that FI TOOLS identifies as Encrypted Data (Headerless).  The files that FI TOOLS identifies as TrueCrypt Data are identified with even higher accuracy and should not require the use of TC Hunt.  The TrueCrypt identification in FI TOOLS works on Formatted Dynamic True Crypt files.  All other TrueCrypt files are identified as Encrypted Data (Headerless).

Rob Zirnstein
Forensic Innovations, Inc.</description>
		<content:encoded><![CDATA[<p>FI TOOLS was developed with no knowledge of TC Hunt.  We used our own technologies to acomplish the ability to identify encrypted files and, in some cases, that a headerless encrypted file was created with TrueCrypt.  The methods that TC Hunt uses (at least in version 1.0) are clearly described, and they are completely different than our methods.  To assume that we copied them is wrong.</p>
<p>TC Hunt identifies files as being TrueCrypt or not.  Our software identifies 3,300+ different types of files.  One of those is Encrypted Data (Headerless), another is TrueCrypt Data.  The two false positives in the TC Hunt test appear to have been incorrectly labeled as TrueCrypt.  In the FI TOOLS test, those files appear to have been correctly identified as Encrypted Data (Headerless).  Since the author admitted that those files actually are encrypted, with a method other than TrueCrypt, they should be counted as correct positives for FI TOOLS.  That moves FI TOOLS to 7 correct identifications out of 8 files, and TC Hunt to 5 correct identifications out of 8.</p>
<p>I do not see any proof of the jouib6.sys file being identified incorrectly by FI TOOLS.  Please make all of these test files available for testing by other people and/or provide all of the details about the files tested.</p>
<p>The 5+ minutes required for FI TOOLS to identify these files indicates that the test may have been run on a slow computer (or slow virtual environment).  FI TOOLS has to read the entire file for some file types, when configured to read beyond the first megabyte, in order to maintain our high accuracy.  I didn&#8217;t think that slower configuration was the default, but I will look into it.  Would the author/tester please document any configuration changes that they made before the test?</p>
<p>Since these two tools use completely different methods, I recommend that FI TOOLS be used to identify all of the files on a hard drive, then use TC Hunt to get a second opinion on the files that FI TOOLS identifies as Encrypted Data (Headerless).  The files that FI TOOLS identifies as TrueCrypt Data are identified with even higher accuracy and should not require the use of TC Hunt.  The TrueCrypt identification in FI TOOLS works on Formatted Dynamic True Crypt files.  All other TrueCrypt files are identified as Encrypted Data (Headerless).</p>
<p>Rob Zirnstein<br />
Forensic Innovations, Inc.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : TCHunt 1.1 : June 7Sortie de TCHunt 1.1 le 7 juin ! &#124; Artiflo Inside</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2154</link>
		<dc:creator>TCHunt 1.1 : June 7Sortie de TCHunt 1.1 le 7 juin ! &#124; Artiflo Inside</dc:creator>
		<pubDate>Fri, 24 Jul 2009 06:35:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2154</guid>
		<description>[...] TCHunt FAQ has been updated, with the appearance of 2 links to the ticket that I had written comparing TCHunt and FI Tools with a comment a little spicy to FI Tools;). The authors of TCHunt be more confident in the rate of [...]</description>
		<content:encoded><![CDATA[<p>[...] TCHunt FAQ has been updated, with the appearance of 2 links to the ticket that I had written comparing TCHunt and FI Tools with a comment a little spicy to FI Tools;). The authors of TCHunt be more confident in the rate of [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Hidden Operating System &#124; Artiflo Inside</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2150</link>
		<dc:creator>Hidden Operating System &#124; Artiflo Inside</dc:creator>
		<pubDate>Thu, 23 Jul 2009 16:26:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2150</guid>
		<description>[...] caché dans des fichiers chiffré. Il est uniquement possible de détecter des fichiers chiffré (TCHUNT). Les méthodes de Forensic évoluant vite, des vulnérabilités peuvent [...]</description>
		<content:encoded><![CDATA[<p>[...] caché dans des fichiers chiffré. Il est uniquement possible de détecter des fichiers chiffré (TCHUNT). Les méthodes de Forensic évoluant vite, des vulnérabilités peuvent [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Florian Cristina</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2045</link>
		<dc:creator>Florian Cristina</dc:creator>
		<pubDate>Sun, 31 May 2009 12:59:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2045</guid>
		<description>Thanks for your post, I updated my article.</description>
		<content:encoded><![CDATA[<p>Thanks for your post, I updated my article.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : TS</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2023</link>
		<dc:creator>TS</dc:creator>
		<pubDate>Tue, 19 May 2009 13:09:06 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2023</guid>
		<description>Just to be clear, TCHunt came out in January 2009. Long before FI Tools. TCHunt also publicly disclosed the modulo 512 issue. Before TCHunt, this was not common knowledge. FI Tools simply copied TCHunt&#039;s methodology, but they did not seem to implement it very well.</description>
		<content:encoded><![CDATA[<p>Just to be clear, TCHunt came out in January 2009. Long before FI Tools. TCHunt also publicly disclosed the modulo 512 issue. Before TCHunt, this was not common knowledge. FI Tools simply copied TCHunt&#8217;s methodology, but they did not seem to implement it very well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Florian Cristina</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2022</link>
		<dc:creator>Florian Cristina</dc:creator>
		<pubDate>Tue, 19 May 2009 13:06:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2022</guid>
		<description>Non, non tu as raison, je me drogue :/ Ce sont les même fichier mais dans des répertoires différent.</description>
		<content:encoded><![CDATA[<p>Non, non tu as raison, je me drogue :/ Ce sont les même fichier mais dans des répertoires différent.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Vincent Varlet</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2021</link>
		<dc:creator>Vincent Varlet</dc:creator>
		<pubDate>Tue, 19 May 2009 07:43:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2021</guid>
		<description>kbdno56.dll 	80Mo 	AES-Twofish-Serpent 	Whirlpool 	C:\WINDOWS\system32\

J&#039;ai raté un épisode ?</description>
		<content:encoded><![CDATA[<p>kbdno56.dll 	80Mo 	AES-Twofish-Serpent 	Whirlpool 	C:\WINDOWS\system32\</p>
<p>J&#8217;ai raté un épisode ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Florian Cristina</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2020</link>
		<dc:creator>Florian Cristina</dc:creator>
		<pubDate>Tue, 19 May 2009 07:38:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2020</guid>
		<description>Ce sont kbdno56.dll et oembios.bin :)</description>
		<content:encoded><![CDATA[<p>Ce sont kbdno56.dll et oembios.bin <img src='http://www.artiflo.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Par : Vincent Varlet</title>
		<link>http://www.artiflo.net/2009/05/detecter-truecrypt-tchunt-vs-fi-tools/comment-page-1/#comment-2019</link>
		<dc:creator>Vincent Varlet</dc:creator>
		<pubDate>Tue, 19 May 2009 07:23:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.artiflo.net/?p=743#comment-2019</guid>
		<description>Sympas toussa ! Quels sont les faux-positifs ?</description>
		<content:encoded><![CDATA[<p>Sympas toussa ! Quels sont les faux-positifs ?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

