Aftersettingup,
mountyour
encrypteddrives
foraccess.
encrypt the Windows partition, or the
entire drive (so all partitions on the
primary hard drive). If in doubt, encrypt
the system partition only – you may get
a warning when attempting to encrypt
the entire drive about losing access if it
has a so-called ‘inappropriately
designed’ BIOS.
The next step informs VeraCrypt
whether you have a single-boot or
multiboot system, and then it’s a similar
process as for creating an encrypted
virtual drive.
There’s just one caveat: you can only
protect your system drive with a strong
password; key files aren’t supported.
You also need to create rescue media
- don’t skip this step, because it’s
required to both permanently decrypt
your drive and provide protection
against corruption.
Different media is required
depending on whether your boot
mode is EFI (USB flash drive) or MBR
(CD/DVD) – just follow the prompts
to create and verify the media. The
recovery media is tied to your specific
PC and the current password you’ve
assigned to your boot drive. If you
make any hardware changes, you need
to recreate it.
You next see the Wipe Mode screen,
which enables you to securely overwrite
the unencrypted copies of your files
after they’ve been encrypted – the
more passes, the slower the process, so
unless you have reason to be truly
paranoid, none or just ‘1-pass’ should
be sufficient.
7HVW DQG HQFU\SW
You’renowreadyforthedrivetobe
encrypted– first,a pretestisrunto
verifyeverythingworksasit should
do.YourPCreboots,andyou’re
promptedtoenterthepasswordyou
justsetup.Whenpromptedforthe
PIM,justpressEnterunlessyou
manuallyspecifiedthisvalue.Waitfor
thepasswordtobeverified– then
Windowsbootsasnormal.
If thetestpasses,clicktheEncrypt
buttonandVeraCryptstartstoencrypt
yourdrive’scontents(aDeferbutton
isalsopresentif youwishtobackup
datafirst– you’rethenpromptedagain
thenexttimeWindowsisrestarted).
Unlikewithencryptingnon-system
volumes,youcancarryonusingyour
PCwhilethedriveisencrypted.Once
complete,yourcomputer’scontents
areprotectedagainsttheftandother
threats,ensuringanydatastoredon
thedriveissecure.
(QFU\SW HQWLUH GULYHV
VeraCryptcanalsobeusedtoencrypt
otherdrivesandpartitions,frominternal
datadrivestoUSBthumbdrives.Aswith
allmajoroperations,westrongly
recommendyoufirsttakea fullimage
ofyourharddrivebeforestarting
theprocess– justincase.Oncethedrive
issafelyencrypted,youcansafely
You need to balance security versus performance when picking an algorithm.
Windows 10
Protect your data
March 2020 | |^53