I wanted to play with Sean's idea from the Newsreal 9/22 show of throwing an encrypted server in an inaccessible place and leaving a 'blinking light' box out as a decoy in the event that a wog should be raided. Some random thoughts on the subject:
Would it be enough to setup an encrypted fileserver using something like
CryptoNAS or
FreeNAS or would it be necessary to augment the crypto further using an ssh or OpenVPN tunnel?
My current network already uses a central gateway machine that is naturally the blinking light/decoy machine. Logging can be turned off, sent to the NAS or put on an encrypted filesystem of its own just to add another layer of obfuscation.
How would be the best way to hide the physical location of the NAS? CAT cable is obvious and needs to be physically hooked to the rest of the network. Anyone paying attention will notice a red light on the switch. Wireless is not secure.
What kind of discipline needs to be practiced to make sure that all this effort isn't compromised by a random CD or USB drive? If more people practice the discipline on mundane information then it becomes harder to insinuate that a particular piece of encrypted information is incriminating. And the look on the investigator's face when they realize there are only pictures of cute kittens...