Encrypt/secure files on external HDD?

Page 1 of 2 12 LastLast

  1. Posts : 101
    Windows 7, 64bit pro
       #1

    Encrypt/secure files on external HDD?


    Hello, I would like to know how to completely secure/lock or encrypt files into an external HDD.
    Basically I want those files to be read-only, uncopiable, uneditable, etc. and of course I want to the external HDD to be uncopiable as well (not formatable, or copiable/clonable on another blank or formated HDD).

    Is that possible to achieve with any program or combination of them?
      My Computer


  2. Posts : 430
    Windows 7/8.1/10 multiboot
       #2

    Have you considered Veracrypt? I'm not sure I understand your requirements ... "unformattable?" Any disk can be reformatted, but if that is done anything that was on the disk gets erased anyway, so not sure why you would require the disk to be incapable of being reformatted.

    With Veracrypt you can create an encrypted "container" (basically, an encrypted file that can be opened as a separate drive letter) or you can encrypt an entire SSD/HDD partition, ala Microsoft's Bitlocker. The choice basically depends on how much content you want to store. Without the proper password to unlock the encrypted volume, nothing within the encrypted volume can be seen or accessed. With the proper password, though, it's just like any other directory in that you can read/copy/edit the files within. I don't know whether that meets your requirements or not.

    Take a look and see what you think. There is a "portable" version, so you can download it and give it a trial run. I suggest you test the portable version and create a small (2-10 GB) encrypted container and explore how to use it. That may be all you need. If you like the way it works but need something a lot larger, you could then move on to create a larger container or encrypt an entire partition, if desirable. And if it doesn't meet your needs, you can simply toss the Veracrypt folder and continue looking for something else.
      My Computer


  3. Posts : 101
    Windows 7, 64bit pro
    Thread Starter
       #3

    dg1261 said:
    Have you considered Veracrypt? I'm not sure I understand your requirements ... "unformattable?" Any disk can be reformatted, but if that is done anything that was on the disk gets erased anyway, so not sure why you would require the disk to be incapable of being reformatted.

    With Veracrypt you can create an encrypted "container" (basically, an encrypted file that can be opened as a separate drive letter) or you can encrypt an entire SSD/HDD partition, ala Microsoft's Bitlocker. The choice basically depends on how much content you want to store. Without the proper password to unlock the encrypted volume, nothing within the encrypted volume can be seen or accessed. With the proper password, though, it's just like any other directory in that you can read/copy/edit the files within. I don't know whether that meets your requirements or not.

    Take a look and see what you think. There is a "portable" version, so you can download it and give it a trial run. I suggest you test the portable version and create a small (2-10 GB) encrypted container and explore how to use it. That may be all you need. If you like the way it works but need something a lot larger, you could then move on to create a larger container or encrypt an entire partition, if desirable. And if it doesn't meet your needs, you can simply toss the Veracrypt folder and continue looking for something else.
    Hello, thank you for your answer, to put it simply: it's personal work I need to hand out temporarily to somebody who has to view it only. It's personal work that I don't want to be distributed or seen outside of the viewer I've chosen (basically the drive itself is a portfolio). That is why I needed that secrecy. Unformattable because, of course, I can reuse it to make someone else see it without reuploading it all again (in case the first person who views the content accidentally erases its contents... or even intentionally but that would make no sense). So I don't know if the password alone would do, as the person has full access with it (meaning he can copy the files and use them as he pleases). Hope that makes sense.

    If not, think about an artwork project: you have not only the final JPG of the image, but also the "source files" which have extra features (such as layer-based files, unlike JPG) and much more. I basically want to make the viewer (let's say, somebody who is probably going to hire me) to see what I can do on full extent (ergo: seeing that the JPG file was made with the combination of different softwares such as Gimp, MyPaint, Blender) and I want him to see the separate parts of the composition made in different programs. Of course, if he gets the files he can tell me "sorry I won't hire you" then use the files without permission since they may be not protected, fully accessible, practically in his hands. That's the point, and why I need the HDD to be read-only. Afterall, I wouldn't care if the person formatted it.
      My Computer


  4. Posts : 430
    Windows 7/8.1/10 multiboot
       #4

    Aha, now I see. That puts things in better context. Essentially, you're looking for some form of copyright or anti-tamper protection rather than simply security from hackers and prying eyes.

    Outside of water-marking, I'm not sure what else can be done. Maybe someone else has some ideas. Even "secure pdfs" can be stripped of their security, so that's not a solution. It's kind of like the age-old DVD copyright conundrum -- you can encrypt the DVD, but at some point it has to be decrypted for display on the TV, and then it's exposed to copying or screen capture. The solution there was to tie the DVD to dedicated hardware, but that won't be an option for your case.

    This is well outside my level of experience, but I wonder if a solution might lie in some sort of hybrid online delivery. For example, I think a pdf can be designed to pull in and display content dynamically from over the internet; perhaps your intended viewer has similar capability. If so, that might allow your webserver to control (and revoke, when necessary) access. I'm just shooting in the dark, though.

    Your best bet may be to browse around some photography forums rather than hardware forums. See what ideas photographers have used to protect their creations, and maybe there will be some ideas that you can modify for your situation.
      My Computer


  5. Posts : 2,495
    Windows 7 Ultimate x64
       #5

    Here is the catch: there isn't anything like "uncopiable" things. Once you grant read access to something, you can get the info and display it, but nothing really prevents you from writing it somewhere else you have write access to. Read implies knowing the data, and by knowing the data you can put it elsewhere.

    By handing out an external HD (or a pendrive, or an email attachment, or a webserver hosted file, literally, anything), you no longer are in control of it nor can restrict what the recipent can do with it. It's within their system now and under full control.
    Encryption would helped if you don't need the other guy to view it, but now, you're after something like "DRM", and as all we know, it's impossible in practice to have good results with it (that's why music and movies piracy is still a thing and still impossible to avoid).

    The only real solution to go to the meeting with your potential employeer with your own computer, open the files yourself, in your own screen, under your control, show whatever you need, then close the laptop and go away, carrying the lone copies with you. Of course this is not always practical or even possible.

    Other than that, I would stick to the mentioned techniques to "dumb down" the work so that it doesn't hurts too much if it leaks: watermarking, using a lower quality or resolution of images, show only a portion of them and the like.
      My Computer


  6. Posts : 68
    10
       #6

    I think the point would be that the contents are clearly intended for a third party but not all third parties. it means that if the drive got lost or onto the hands of someone else unintended then there is a fail safe in place.

    I would just use Bitlocker on the drive set with a password.
      My Computer


  7. Posts : 101
    Windows 7, 64bit pro
    Thread Starter
       #7

    Malneb said:
    I think the point would be that the contents are clearly intended for a third party but not all third parties. it means that if the drive got lost or onto the hands of someone else unintended then there is a fail safe in place.

    I would just use Bitlocker on the drive set with a password.

    That doesn't solve the contents from being copied, even knowing the password. The password itself is no use, I just want basically to make the entire drive "read only" and I mean truely read-only (no way to copy files or the drive).

    I realize that it is impossible so, I'll just give up I guess.

    - - - Updated - - -

    Malneb said:
    I think the point would be that the contents are clearly intended for a third party but not all third parties. it means that if the drive got lost or onto the hands of someone else unintended then there is a fail safe in place.

    I would just use Bitlocker on the drive set with a password.

    That doesn't solve the contents from being copied, even knowing the password. The password itself is no use, I just want basically to make the entire drive "read only" and I mean truely read-only (no way to copy files or the drive).

    I realize that it is impossible so, I'll just give up I guess.

    Well, not truely impossible, I mean... it would mean inventing my own hard drive with my own filesystem, accessible through my own software. But that's just a dream so it is possible, only in dreams, lol.
      My Computer


  8. Posts : 68
    10
       #8

    What? bitlocker is AES 256 encryption capable and means you cannot read the contents unless you know the key.

    mulambo said:
    Hello, I would like to know how to completely secure/lock or encrypt files into an external HDD.
    Basically I want those files to be read-only, uncopiable, uneditable, etc. and of course I want to the external HDD to be uncopiable as well (not formatable, or copiable/clonable on another blank or formated HDD).
    Is that possible to achieve with any program or combination of them?
    I think you are confused then tbh. You are literally asking about encryption in the OP and bitlocker is just that, use it.
      My Computer


  9. Posts : 1,933
    Windows 7 pro
       #9

    Malneb said:
    I think you are confused then tbh. You are literally asking about encryption in the OP and bitlocker is just that, use it.

    He isn't exactly trying to control who can access it but what can be done once it's accessed. Hard drive encryption wouldn't stop them from copying the files to another drive once they have his drive and his password. It would only keep them from accessing the files but he doesn't want that. He wants to allow access but prevent them from reusing his files.

    Using windows permissions you can provide read only access but that only applies to a system under your control and doesn't prevent them copying the files to another volume anyway. This is application based protections so it would have to be built into the application that you're using. For example pdfs can be protected so that the files are read only but that's built into the application and not windows. I'm afraid that this is beyond us. You should try a forum specializing in the applications that you are using. If they have such protections that would be more affective than what computer systems provide. The only thing that I know that you could do would be to have some kind of meeting (be it in person or virtual like zoom or webex), you pull up the files on your system and let them inspect them. You control the situation and when you are gone they lose access.

    Consider this, do you really want to work for an employer that would do the kind of back stabbing that you're trying to prevent? You wouldn't ever feel like you could trust them.
      My Computer


  10. Posts : 101
    Windows 7, 64bit pro
    Thread Starter
       #10

    townsbg said:
    He isn't exactly trying to control who can access it but what can be done once it's accessed. Hard drive encryption wouldn't stop them from copying the files to another drive once they have his drive and his password. It would only keep them from accessing the files but he doesn't want that. He wants to allow access but prevent them from reusing his files.

    Using windows permissions you can provide read only access but that only applies to a system under your control and doesn't prevent them copying the files to another volume anyway. This is application based protections so it would have to be built into the application that you're using. For example pdfs can be protected so that the files are read only but that's built into the application and not windows. I'm afraid that this is beyond us. You should try a forum specializing in the applications that you are using. If they have such protections that would be more affective than what computer systems provide. The only thing that I know that you could do would be to have some kind of meeting (be it in person or virtual like zoom or webex), you pull up the files on your system and let them inspect them. You control the situation and when you are gone they lose access.

    Consider this, do you really want to work for an employer that would do the kind of back stabbing that you're trying to prevent? You wouldn't ever feel like you could trust them.

    Anything goes, you know. If not the boss, somebody else (data theft, unloyal employees, whatever). I just wanted to reduce risks to the bare minimum and also give the time to check all the files when he wants and for all the time he wants. So the idea was to hand the drive over and take it back after (and this is already some kind of trust I'm giving).
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 20:23.
Find Us