Confused about shared folder encryption key

Currently reading
Confused about shared folder encryption key

16
0
NAS
DS1621xs+, DS1621+
Operating system
  1. macOS
  2. Windows
Mobile operating system
  1. iOS
I've tried to dig up as much as I can on setup and use of shared folder encryption keys, and I'm still confused as my NAS isn't treating them as I expect from reading Synology's guidance as well as various posts here. Based on this thread: Synology NAS Encryption: Forensic Analysis of Synology NAS Devices by Elcomsoft, and these 2 Synology articles: How to encrypt and decrypt shared folders on my Synology NAS & Manage Keys of Encrypted Shared Folders, I set up an encrypted test folder, set a long "Encryption key" passphrase for it, set up the Key Store location as a USB stick with another Passphrase for that (not System Partition), after which it downloaded an encryption "key" file to my computer. Isn't this key file what's supposed to be stored on the USB stick? Why did it choose to download another copy to my computer?

My understanding was that with this setup, and ideally for the most secure system, because I did not use the System Partition, I would need to have 3 things to decrypt that folder (based on what Oleg said in the post above) 1: the HD, 2: the USB stick, 3: the passphrase (I'm guessing that means the first Passphrase specific to that folder labeled Encryption key, not the second Passphrase labeled Passphrase when I set up the Key Store location. 🤯

But when I remove the USB stick, restart the NAS (complete power off then power on), I'm able to decrypt that folder simply by providing the folder passphrase, no need for the USB key. Is it still using the system partition somehow for this folder key? If so how do I remove it and force it to need the USB key? If I go into Shared Folder > Action > Key Manager, the Shared Folder dropdown says "System Partition" as the only option when I don't have the USB stick inserted.

If I do have the USB stick inserted, going to Key Manager requires a Passphrase, after which it lists my encrypted test folder. Going to Configure shows that the Key store location for that folder is the USB stick.

I'm thoroughly confused, I'm certainly missing something on how this is supposed to work.

Appreciate any guidance.
 
I have one folder (personal financial information) encrypted. I store the passphrase in my password wallet. Of course it’s less convenient (than the other methods) but it depends on what you want (security vs. convenience)

SpaceRex might explain it for you…

To view this content we will need your consent to set third party cookies.
For more detailed information, see our cookies page.
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

Thank you for the useful suggestions, I am going to investigate this more. Much appreciated.
Replies
6
Views
2,166
It was trusted people who was helping me but same noobs like me. I sent to hacker several emails, but...
Replies
6
Views
3,401
Replies
15
Views
3,260
As the share is mounted as NFS on another machine all the files that gets created are mapped as admin...
Replies
5
Views
1,097
  • Question
Thanks for your help, appreciate it. Definitely helped to reset the time manually in SSH session, then the...
Replies
5
Views
2,977
  • Solved
If it is of interest, when I got caught by the 143 character limit, I used an app 'Path Length Checker' on...
Replies
7
Views
2,760

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Back
Top