How to create a user with data encryption

Hi,

When I create a user and provide password. does it mean user data (like documents or photo) will be encrypted using that password? If not, is there any way to make user data encrypted? Just for a case if laptop is stolen or lost and someone can read the hard drive and see all the data.

The Password is only a normal Password. The Installation is not encrypted but You can choose Encryption during the Installation.

Alternatively, You could use an Encryption Program after the Installatino to encrypt Your System.

I do not want to encrypt the entire system. With family laptop where few people use it, it is not convenient to have two passwords. One during the boot, and the second one for the user. Windows for example allows to encrypt the data and the user's password only required. Based on your answer I assume there is no such option.

Are there any other apps/packages which could enable such feature? I wish this could exist out of the box.

You might look into Gnome ENCFS:

There is also a Qt built SiriKali you can try,, but Gnome ENCFS would mesh with Zorin OS better.

Thanks. I have just checked that app (https://www.youtube.com/watch?v=UvKPhZ0Y6yA).

It looks over complicated to me. You have to create some extra folders and mount and god knows what. I don't think that app can be used by normal humans.

I also saw CryptKeeper which looks the same.

If it was like when you create a user you can tick a box to encrypt user data and you forget it.

Any other solutions?

I think we need to redefine "normal".
The two above really are easy GUI solutions.

A more complex one would be using ecryptfs.

What is unfamiliar or new may look daunting; this does not mean impossible or difficult once you try.

So to start working I have to do the following things.

  1. Log into the system by typing my password,
  2. Open Encfs program,
  3. Type my password one more time because of Encfs,
  4. Click to mount the folder,
  5. Remember that I cannot use documents or Photos folder as default, but to use those specific ones created by Encfs.

As you can see I would spend more time by managing all of that, so I cannot accept that which will kill all my life for clicking all those buttons. It's not efficient, and I don't understand why such apps exist.

I have another question. If I have Firefox and saved passwords for banking and accounting web app. Does it mean that someone having an access to the hard drive (like if it was lost/stolen), can have an access to all my banking / accounting stuff? Is such information stored unencrypted?

Other data include:

  • emails,
  • contacts,
  • calendars,
  • invoices,
  • browser saved passwords (like banking web app),
  • photos, ids, credit cards, projects,

So as you can see the Encfs is not a solution to me.

Years ago, Ubuntu offered what you are asking for with ecryptfs, but they have largely dropped it, now.
You might be able to replicate what used to exist using fscrypt and PAM, to log in once.
But I would need to look up how - I have not done it myself. And I know it is a bit involved.

No, just having access to a stolen drive is not enough.

Firefox uses Network Security Services cryptography to encrypt the login data.
That said; a thief that stole your notebook computer, that also has strong hacking skills can use tools to decrypt the passwords.
It is a stretch... But plausible.

On Firefox, you can add an additional layer of protection in its settings by setting Primary Password.

Reasonably, you are left with choices. If your notebook computer being stolen and sensitive information is a high level concern to you; Following the necessary steps to secure what is yours is a price you must pay.

GnuLinux is not the Two Trillion+ dollar industry that Microsoft is.

Another password? How many passwords should I type? It's nightmare.

Can it be just one single USER password when I log in in to the system?

Security and Convenience cannot mix.
It is like Particle Physics: You cannot nail down an exact position and an exact speed at the same time; The more exact you are with one, the less accurate the other becomes.

It is a trade off: You are either careful with your equipment and ensure protection boundaries outside of the notebook computer - or you are going to rely on layers of protection within the computer. You cannot have your cake and eat it, too.
A browser, like Firefox, will offer the Primary password option as a layer of security if wanted; but they are not in control of O.S. level passwords.

If your primary concern is password reduction: Encrypting the drive with LUKs is the road forward.

I don't need to encrypt the entire system. It's not convenient and the performance is very low. Also as I mentioned, everyone who uses the computer needs to remember that password as well.

Encrypted Home solves all those issues (browser, email client, files).

Have you seen this article? EncryptedHome - Community Help Wiki
It says it's there but in Zorin I cannot see such option "Encrypted Home" when a new user is being created.

This is what I was referring to above:

You will note that what you linked to says:

This is a known, wishlist issue that we hope to solve for Ubuntu 10.04.

So that was written before Ubuntu 10.04 was released in 2010.

Zorin OS 18 is built on Ubuntu 24.04.

Ok, then it looks like there is a big issue in linux world. I am not sure if I can use linux today after what I just revealed. completely unsecured.

What you revealed is that you must put some effort of your own into setting up a desired outcome instead of having it handed to you.
I repeat: Microsoft is a Two Trillion Dollar plus industry.
Canonical only netted a few million dollars in the last fiscal cycle.

You can do exactly what you say you want done: But not with s single click the checkbox and be done.

This is not a Big Linux issue. It is an End User issue. The vast majority of users are not trying to lock down their browser, sole user account and simultaneously disable password protection.

This topic was automatically closed 90 days after the last reply. New replies are no longer allowed.