If you've used VeraCrypt before, you've probably defaulted to a file container — it's the option everyone recommends first, and for good reason: it's portable and flexible. But if the job your USB stick actually has is "carry sensitive data between machines," encrypting the stick's own partition beats a container file in two concrete ways:
- No visible container file sitting in a directory for anyone to spot and get curious about.
- VeraCrypt manages the whole device directly, instead of wrapping a file inside a filesystem that's wrapped inside another filesystem.
This is a focused, Linux-GUI walkthrough for setting one up, using VeraCrypt 1.26.29 (released June 9, 2026). If you want the cipher theory, PIM math, and threat-model reasoning, that lives in the companion VeraCrypt security deep dive — this post sticks to the hands-on steps.
Before You Start
- Install VeraCrypt 1.26.x. Linux GUI operations on partitions need root, and VeraCrypt will prompt for elevation itself via
pkexec. If you don't see a prompt at all, that's usually your desktop session blocking it — not VeraCrypt rejecting your password. - Back up everything on the stick first. Encryption overwrites the partition. "I'll copy it off after" doesn't count — do it now.
- Identify the device. Run:
lsblk -o NAME,SIZE,MODEL,MOUNTPOINT
Note the exact device path and size. /dev/sdb1 (a partition) is one character away from /dev/sdb (the whole drive) — mixing them up is how people encrypt the wrong thing. Confirm the size matches your stick, not your system disk.
- Disarm desktop automounters. GNOME's gvfs (and equivalents elsewhere) grab removable media the moment it appears. If the stick auto-opens or auto-mounts, release it first:
udisksctl unmount -b /dev/sdb1
A partition VeraCrypt won't open cleanly is almost always an automounter fighting you in the background, not a tool failure.
Step 1: Create the Partition
VeraCrypt encrypts an existing partition — it doesn't partition the drive for you.
- Open GParted (or GNOME Disks).
- Select the USB device. Double-check the model and size before touching anything.
- Create one partition covering the space you want. The filesystem you pick here doesn't matter — VeraCrypt replaces it during formatting. If you're asked about an EFI system partition or disk alignment, "no" and default alignment are both fine.
- Apply the change, then unmount the partition again if the desktop auto-mounts it.
Step 2: Start the Wizard
- Open VeraCrypt → Create Volume.
- Choose Encrypt a non-system partition/drive → Next.
- Choose Standard VeraCrypt volume → Next.
- On the device list, select your partition (e.g.
/dev/sdb1). The wizard will warn you that existing data will be overwritten — confirm only once both the device path and size match whatlsblkshowed you earlier.
Step 3: Encryption and KDF Choices
Encryption algorithm: AES. It's hardware-accelerated on virtually any modern CPU and the right default unless you have a specific reason to run a cascade (AES-Twofish-Serpent, etc.). This choice is locked in once the volume is created — there's no in-place re-encryption, only recreating the volume from scratch.
KDF (key derivation function): pick Argon2id. It's new in 1.26.29 for non-system volumes, and it's memory-hard — each password guess costs an attacker RAM, not just CPU time, which closes off much of the GPU/ASIC dictionary-attack advantage that PBKDF2 hands over. It's the sensible default for any volume you're creating now.
Hash algorithm (used for randomness generation during creation, not for the KDF itself): SHA-512 is fine.
Step 4: Password and PIM
- Enter a passphrase. Long beats complicated — a 30+ character passphrase built from a few unrelated words will outperform an eight-character monster full of symbols.
- Check Use PIM only if you want to tune iteration cost yourself:
- Leave PIM empty (or 0) for the Argon2id defaults — equivalent to PIM 12, around 416 MiB of memory cost. Mounts fast enough that you won't notice.
- A custom PIM is part of your credentials. Get it wrong and you'll see the same "Incorrect password" error as an actually-wrong password — there's no separate signal.
- VeraCrypt enforces a minimum PIM of 12 for Argon2id when your password is under 20 characters, specifically so you can't accidentally trade away security for mount speed on a weak password.
- Record the password, PIM, and volume location in your password manager right now, while they're fresh in your head. Not on the stick. Not on a sticky note next to it.
- Keyfiles are optional — skip them for a USB stick unless you already run a keyfile routine elsewhere. Lose the file, lose the volume.
Step 5: Filesystem and First-Fill Random
- Filesystem: exFAT if the stick needs to work on Windows/macOS without extra drivers, ext4 for Linux-only use. NTFS works too, but it drags Windows-specific semantics along for no real benefit here.
- Uncheck Quick Format. This is the step people skip and shouldn't. With Quick Format off, VeraCrypt writes random data across the entire partition before it finishes:
- Every sector gets overwritten, so there are no untouched regions that could hint at how full the volume actually is.
- The cost is real time — a 32–64 GB stick can take anywhere from tens of minutes to a few hours over USB 2.0/3.0. Let it run.
- Quick Format is fine only for a throwaway volume where footprint privacy genuinely doesn't matter. If you ever want to carry a "there might be more hidden here" argument, full format is non-negotiable.
- Wiggle the mouse and type while it formats. VeraCrypt polls the system for entropy while generating keys — an idle machine feeds it a thinner randomness pool.
When formatting completes, the wizard briefly displays portions of the generated master key and header key before you close it.
Step 6: Header Backup
A corrupted header means a permanently dead volume. One bad yank mid-write, one controller glitch — and it's gone, no recovery.
- Select the new volume in the main window (don't mount it yet).
- Go to Volume → Backup Volume Header, and save it somewhere on your computer.
- Store that backup file, the password, and the PIM together — in your password manager or a physical safe. Never on the same stick as the volume itself.
Refresh the backup after any password or PIM change (Volume → Change Volume Password updates the header too).
Step 7: Test Mount
Trust nothing until it actually opens.
- Select the volume → Mount. Enter the password (and PIM, if you set one).
- If it fails, work through this checklist in order:
- "Incorrect password" with a custom PIM set → try re-entering the PIM. A wrong PIM and a wrong password look identical by design.
- Immediate failure on Linux → almost always an elevation problem. Try running the GUI as root once to rule it out.
- Slow mount with a high custom PIM → autodetection is trying multiple Argon2id trials at that PIM cost. Set the KDF explicitly to the one you chose at creation instead of leaving it on Autodetect.
- Copy a test file in, unmount, remount, and confirm it survived the round trip. Only then put real data on it.
Mount Discipline
Encryption's value collapses the moment the volume sits mounted while you walk away. A few habits prevent almost every real-world problem:
- Mount only when you need it, unmount before everything else — sleep, unplugging, handing the machine to someone else. Right-click → Dismount, or over CLI:
veracrypt -d /media/veracrypt1
- Never unplug a mounted volume. Unmount first. Flash writes aren't the only casualty — journal state on the stick matters too.
- Stale mountpoints after an unclean shutdown will swallow later mount attempts with cryptic errors. Check and clear them:
mount | grep veracrypt
sudo umount -l /media/veracrypt1
- Treat a mounted volume as an open door. VeraCrypt protects data at rest — not from anyone sitting at a logged-in keyboard.
Two Caveats
Flash wear leveling. USB controllers relocate writes under the hood. Overwriting "deleted" files on the stick later may leave the originals sitting in spare blocks the filesystem no longer references. VeraCrypt's full-format pass makes a fresh volume clean, but treat deleted files on an already-used stick as potentially recoverable — route sensitive deletions through a full reformat, not the trash bin.
Whole drive instead of a partition? Same wizard — just select the device itself with no partitions on it. Encryption then covers the entire stick, and there's no partition table left visible at all. Go this route if the stick will never hold anything unencrypted. Stick with the partition route (what this guide covers) if you want room for an unencrypted partition alongside it.
Conclusion
The full sequence, end to end: partition the stick → Create Volume → non-system partition → AES + Argon2id → long passphrase → uncheck Quick Format → wait out the random fill → back up the header → test mount → unmount before you blink.
Ten minutes of attention at creation, one credential record in your password manager, and the stick becomes a volume nobody — vendor, thief, or otherwise — can open without what you just set up.