Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 19 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Hardwarearrow Full Disk Encryption - Is it time?
Ethical Hacker Community Forums
November 22, 2008, 10:24:32 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Full Disk Encryption - Is it time?  (Read 3631 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2347


Editor-In-Chief


View Profile WWW
« on: November 23, 2006, 02:43:41 PM »

Windows Vista will include a cool new feature for full disk encryption called BitLocker. Two big issues is that it is still software based and it will only be offered in the Enterprise and Ultimate versions of Vista.

For easy to use, full drive encryption for the masses, look to the hard drive manufacturers. Here are a couple that exist now:

LaCie SAFE Mobile Hard Drive with DES/3DES Encryption

Seagate Momentus Laptop Drives with AES

I'm certain more are coming down the pipe as this makes it a no brainer to encrypt your data... I hope the VA is listening!

Anyone with any experience or thoughts on these? Do you think this will finally make data encryption hit a tipping point that will make it permeate all sectors of IT?

Don
Logged

CISSP, MCSE, CEH, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 363



View Profile WWW
« Reply #1 on: November 25, 2006, 10:07:19 PM »

I think only when it's free or forced with most basic users use encryption because there is just not enough user education out there to explain the right reasons for it. I push “truecrypt” to everyone I talk with. Most people I talk to about encryption have no clue about it or where to start and why it’s so important. I think the Federal government will have to force industry and the vendors will have to force home users to get encryption on the hard drives. But this is just my option so take it with a grain of salt.

Slimjim100
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1038


View Profile WWW
« Reply #2 on: November 26, 2006, 12:08:21 AM »

i doubt the govt will be pushing home users to encrypt their data.  too many 3 letter agencies make their money being able to read email and data off people's HDs to make life more difficult for them.

now will the govt start pushing other govt to do it, yes, its already starting to happen.
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
funkybunch78
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #3 on: November 26, 2006, 09:45:49 AM »

Since the VA lost that laptop with all of those SSN's on it.  The govt (at least the agency I work for) is starting to require all laptops and mobile devices that contain sensitive data including personal data like SSN's to be encrypted.

Hopefully this is a start and will get some end users to understand why encryption is important and spread the word to other users.

On a second note I too also recommend TrueCrpyt to everyone I talk to for their personal data. I recommend they set it up on a usb thumbdrive and encrypt the entire drive to store their personal and financial data.
Logged
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2347


Editor-In-Chief


View Profile WWW
« Reply #4 on: November 26, 2006, 10:23:37 AM »

I'm sure all of you would have found this on your own, but just to make things easy:

http://www.truecrypt.org

Don
Logged

CISSP, MCSE, CEH, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 363



View Profile WWW
« Reply #5 on: November 27, 2006, 11:23:21 PM »

Thanks for the link Don I forgot to post it. Cheesy

Slimjim100
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
dalepearson
Full Member
***
Offline Offline

Posts: 153


View Profile
« Reply #6 on: November 28, 2006, 07:06:31 AM »

Is anyone running Vista and BitLocker yet?
I will be moving to Vista this week and I am thinking of giving it a go.
I dont really store much data on my local machine so not to sure of the benefits for myself at this stage.
Logged

mn_kthompson
Jr. Member
**
Offline Offline

Posts: 58



View Profile WWW
« Reply #7 on: November 28, 2006, 02:05:43 PM »

We were evaluating Bitlocker, and ultimately decided to go with Pointsec for our full disk encryption needs.  My hope is that eventually all of our laptop computers will be protected by Bitlocker.

Truecrypt is a great program, but it depends on us being able to force our users to save their data to a certain folder.  We haven't even been able to get our users in the habit of saving data to their network share rather than their hard disk.  If we can't get them to use one folder of our choosing, how could we get them to use another?  We decided that the only way to really protect our data is to encrypt the entire drive.

The problem with Bitlocker is that it is dependent on a TPM 1.2 chip, which only started shipping in the first half of 2006.  If you don't have that chip, and you want to use bitlocker, then users will have to keep the key on a USB drive.  We decided that the most likely place that users will keep their USB drive is in the case with their laptop.  Pointsec allows us to encrypt the entire drive, and keep it completely transparent to our users.  That transparency will reduce resistance from the users hopefully.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.051 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.