Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Laptop encryption

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 10-Mar-2008, 10:34 AM
skulkerboyo's Avatar
skulkerboyo skulkerboyo is offline
Valued Member
Posts: 131
Points: 339 skulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 points
Power: 8
None
Join Date: 06 May 2006
Location: Bristol
Age: 27
Certifications: A+,MCP 270+290,ITIL V3,SSC geddit?
WIP: 290 + Mac stuff
Laptop encryption

Oweing to recent mishaps by other organisations and (apparently) pending legislation. My company wants to implement full disc encryption solutions for our 20+ laptop users.

Not sure why I've been handed this one as we have a security guy

Looking at a few solutions and the same names keep coming up. Was wondering what you guys use and why also any pitfalls to look out for?


Nothing pains some people more than having to think
 
Reply With Quote
  #2  
Old 10-Mar-2008, 11:57 AM
Ozzy2k7's Avatar
Ozzy2k7 Ozzy2k7 is offline
Registered Member
Posts: 83
Points: 0 Ozzy2k7 has no points
Power: 3
None
Join Date: 02 Apr 2007
Location: Scotland
Age: 25
WIP: A+ Network+
I use whole drive encryption on my laptop, I'm not part of a business that needs it but I travel a fare bit.

I use truecrypt, its free and the guys that do it seem to really know what they are doing. I haven't noticed any performance loss at all.

The only thing with it is that you can't put the laptop into hibernation but I never use that anyway.

http://www.truecrypt.org

Cheers

Ozzy

 
Reply With Quote
  #3  
Old 10-Mar-2008, 12:32 PM
skulkerboyo's Avatar
skulkerboyo skulkerboyo is offline
Valued Member
Posts: 131
Points: 339 skulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 points
Power: 8
None
Join Date: 06 May 2006
Location: Bristol
Age: 27
Certifications: A+,MCP 270+290,ITIL V3,SSC geddit?
WIP: 290 + Mac stuff
Truecrypt is indeed a good solution but for whole disc encryption doesnt support extended/logical partitions which we use here. I'm trying to find software that will encrypt the entire disc regardless of partition layout. We need the transistion to be seamless and to set up encrypted containers and migrate the data to them would take too much time.

Until I found that out it was my first choice but at least I've found something I can use at home


Nothing pains some people more than having to think
 
Reply With Quote
  #4  
Old 10-Mar-2008, 07:18 PM
GiddyG's Avatar
GiddyG GiddyG is offline
w00t! Davros is back!
Posts: 1,240
Points: 727 GiddyG has over 500 pointsGiddyG has over 500 pointsGiddyG has over 500 pointsGiddyG has over 500 pointsGiddyG has over 500 pointsGiddyG has over 500 pointsGiddyG has over 500 points
Power: 21
None
Join Date: 16 Aug 2007
Location: UK
Age: 45
Certifications: MCITP; MCTS; MCDST; MCP; A+; N+
WIP: 70-630; 70-290; 70-270; 70-291
Had a look at Becrypt?


"He looks like a man, but he's a legend, and his name is... Boson Michael."

Dr Who - next episode starts at 7:10pm on BBC1 on Saturday 28th June 2008...

Certs: MCITP:EST; MCTS:Vista; MCDST; MCP; A+; Net+; ITIL v3 Foundation
 
Reply With Quote
  #5  
Old 10-Mar-2008, 09:25 PM
warrmr warrmr is offline
Valued Member
Posts: 108
Points: 33 warrmr has between 1 & 100 points
Power: 3
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 22
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
The one we use at work for the wireless laptops in guardian Angel, and on the other contract i worked on they used, Safeguard Easy


they both work very well. i dont know how easy it is to break the encription( thats why we have penn testers im just a support analyst)

the easyest one to support is Guardian angel as if they forget there password you just have to ask them there username and last login date that is printed on the screen put it in a funky piece of software and it comes out wiht a 26 digit code the user needs to type in there laptop to reset the password

where as SGE you need to tell them to press a button to get the password and leave the laptop as it is while you generate the codes

both very simple but im 100% sure that accountants are alot stupider than the police when it comes to IT as the police "just know what to do " and get on with it and accountants winge when you tell them to press buttons and type long strings of numbers in to reset there passwords.

 
Reply With Quote
  #6  
Old 10-Mar-2008, 09:35 PM
Bluerinse's Avatar
Bluerinse Bluerinse is offline
Senior Moderator
Posts: 7,370
Points: 2479 Bluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 pointsBluerinse has over 2000 points
Power: 107
None
Join Date: 29 Jun 2003
Location: The Gold Coast, QLD Australia
Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
WIP: None but considering SBS
You could use EFS if it's W2K or XP Pro or Vista versions other than the home ones..

http://en.wikipedia.org/wiki/Encrypting_File_System


"A child of five could understand this. Fetch me a child of five." <Groucho Marx>
 
Reply With Quote
  #7  
Old 10-Mar-2008, 09:40 PM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 715
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
We have just completed a roll out of SafeBoot to all the laptops at work, hundreds of them! For the same reasons as most organisations are implementing encryption on all mobile devices, we don’t want to end up on the nine o’clock news if a user ‘misplaces’ their laptop.

 
Reply With Quote
  #8  
Old 10-Mar-2008, 09:56 PM
hbroomhall hbroomhall is offline
Premium Member
Posts: 5,975
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 85
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
<Dons Mystic Meg outfit>
This will be persued with enthusiasm until a senior director forgets his password....
</>

Harry (the cynic).

 
Reply With Quote
  #9  
Old 10-Mar-2008, 10:05 PM
vlb vlb is offline
Registered Member
Posts: 96
Points: 0 vlb has no points
Power: 2
None
Join Date: 26 Aug 2007
Location: Scotland
Certifications: MCDST, MCP 70-294
WIP: MCSE
hey

i do it for a bank and they use a prog called Pointsec.

you need to login to pointsec before the o/s loads, must be decent as they have used it for aslong as i can remember.


Granny says "if you dont have anything nice to say... say nothing atall
 
Reply With Quote
  #10  
Old 10-Mar-2008, 10:08 PM
AJ's Avatar
AJ AJ is offline
Administrator
Posts: 6,136
Points: 1095 AJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 pointsAJ has over 1000 points
Power: 81
None
Join Date: 28 Jun 2003
Location: Northampton
Age: 43
Certifications: MCSE, MCSA (messaging)
WIP: Looking at doing ..................
posts merged from duplicate thread


AJ

Putting a computer in front of a child and expecting it to teach him is like putting a book under his pillow, only more expensive.
Anon

Remember that GREEN is good Go Premium
 
Reply With Quote
  #11  
Old 11-Mar-2008, 12:35 PM
skulkerboyo's Avatar
skulkerboyo skulkerboyo is offline
Valued Member
Posts: 131
Points: 339 skulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 points
Power: 8
None
Join Date: 06 May 2006
Location: Bristol
Age: 27
Certifications: A+,MCP 270+290,ITIL V3,SSC geddit?
WIP: 290 + Mac stuff
In the process of evaluating safeboot, pointsec and guardian edge. We need centralised management so these look up to it. I am veering towards safeboot though. Seems very solid

First thing I looked at was EFS but its only file level. We want preboot authentication and total disc encryption

Amen to the enthusiasm until a director forgets his password

Hey Nightwalker any feedback on safeboot. All I've heard is good stuff but wouldnt mind opening a channel of communication with someone that uses it as opposed to a salesman


Nothing pains some people more than having to think

Last edited by skulkerboyo : 11-Mar-2008 at 12:36 PM. Reason: bad spelin
 
Reply With Quote
  #12  
Old 11-Mar-2008, 07:17 PM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 715
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
Hey skulkerboyo. Safeboot is actually pretty good. It does complicate the administration a little, users have two lots of passwords to set and remember, their SafeBoot and their domain user account.

Central administration from a server side application (not seen much of that end, the security admin chaps deal with that side of things). The client end is pretty tidy. Its written into the MBR so requires a valid user name and password before windows will boot, then again before you get the Ctrl + Alt + Del screen for windows logon. Once installed on a laptop it will work away in the background encrypting the hard drive, takes about an hour and a half to two hours we found, then they are good to go. The user can still work while its encrypting, the machine is a little sluggish but usable. Hardly any noticeable performance hit once its all installed and enabled. We run mostly HP 4200 and 4400 laptops. You have to overwrite the MBR if you re-ghost the laptop back to a default image, a small extra step.

When they are on the network the current username/password information is synchronised with the server, this can be a bit slow. It depends how often the users are in the office and how often you make the users change the password as to whether this may pose any problems. Users forgetting passwords results in long strings of numbers having to be read out over the phone, but other than that, and considering how intrusive it is to the machine, its been pretty much set it and forget it.

 
Reply With Quote
  #13  
Old 12-Mar-2008, 09:25 AM
skulkerboyo's Avatar
skulkerboyo skulkerboyo is offline
Valued Member
Posts: 131
Points: 339 skulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 points
Power: 8
None
Join Date: 06 May 2006
Location: Bristol
Age: 27
Certifications: A+,MCP 270+290,ITIL V3,SSC geddit?
WIP: 290 + Mac stuff
Sounds good. I like the fact that you can recover the passwords for the user. I have looked at some software that doesnt or that function is provided by their support-naff. Glad to hear about the lack of performance degradation.

I might turn this thread into a rolling blog of the project. This technology is going to become more more commonplace/essential especially with so many endpoint devices being mobile these days.

I've whittled my evaluation software down to 3: Safeboot,Guardianedge and Pointsec. Dont know a great deal about the latter and ruled out double figures worth of software prior to coming to this shortlist.

Nothing to do now but wait for evaluation software


Nothing pains some people more than having to think
 
Reply With Quote
  #14  
Old 14-Mar-2008, 02:37 PM
skulkerboyo's Avatar
skulkerboyo skulkerboyo is offline
Valued Member
Posts: 131
Points: 339 skulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 pointsskulkerboyo has over 250 points
Power: 8
None
Join Date: 06 May 2006
Location: Bristol
Age: 27
Certifications: A+,MCP 270+290,ITIL V3,SSC geddit?
WIP: 290 + Mac stuff
Have recieved my trials for Safeboot and Guardianedge.

Bit surprised at the minimum requirements to run Gardianedge compared to Safeboot. S'ok though I'll get the intern (he's bloody good) to set me up a virtual server that meets the requirements (distant sound of whip cracking).

Will start looking at them next week


Nothing pains some people more than having to think
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
laptop screen problem Sandbro Hardware & Upgrading 6 20-Dec-2007 07:48 PM
Laptop Batteries Fergal1982 Just for Laughs 1 20-Dec-2007 10:28 AM
Laptop TFT panel help TimoftheC Hardware & Upgrading 6 30-Nov-2007 01:16 AM
PRNG bug that allows prediction of OS encryption keys ffreeloader Security & Viruses 1 22-Nov-2007 08:27 PM


All times are GMT. The time now is 08:22 PM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages