.

Full Disk Encryption - Is it time?

<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Thu Nov 23, 2006 3:43 pm

Full Disk Encryption - Is it time?

Windows Vista will include a cool new feature for full disk encryption called BitLocker. Two big issues is that it is still software based and it will only be offered in the Enterprise and Ultimate versions of Vista.

For easy to use, full drive encryption for the masses, look to the hard drive manufacturers. Here are a couple that exist now:

LaCie SAFE Mobile Hard Drive with DES/3DES Encryption

Seagate Momentus Laptop Drives with AES

I'm certain more are coming down the pipe as this makes it a no brainer to encrypt your data... I hope the VA is listening!

Anyone with any experience or thoughts on these? Do you think this will finally make data encryption hit a tipping point that will make it permeate all sectors of IT?

Don
CISSP, MCSE, CSTA, Security+ SME
<<

slimjim100

User avatar

EH-Net Columnist
EH-Net Columnist

Posts: 385

Joined: Wed Nov 08, 2006 12:50 pm

Location: Atlanta

Post Sat Nov 25, 2006 11:07 pm

Re: Full Disk Encryption - Is it time?

I think only when it's free or forced with most basic users use encryption because there is just not enough user education out there to explain the right reasons for it. I push “truecrypt” to everyone I talk with. Most people I talk to about encryption have no clue about it or where to start and why it’s so important. I think the Federal government will have to force industry and the vendors will have to force home users to get encryption on the hard drives. But this is just my option so take it with a grain of salt.

Slimjim100
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
<<

LSOChris

Post Sun Nov 26, 2006 1:08 am

Re: Full Disk Encryption - Is it time?

i doubt the govt will be pushing home users to encrypt their data.  too many 3 letter agencies make their money being able to read email and data off people's HDs to make life more difficult for them.

now will the govt start pushing other govt to do it, yes, its already starting to happen.
<<

funkybunch78

Newbie
Newbie

Posts: 12

Joined: Fri Oct 20, 2006 6:34 pm

Location: Maryland

Post Sun Nov 26, 2006 10:45 am

Re: Full Disk Encryption - Is it time?

Since the VA lost that laptop with all of those SSN's on it.  The govt (at least the agency I work for) is starting to require all laptops and mobile devices that contain sensitive data including personal data like SSN's to be encrypted.

Hopefully this is a start and will get some end users to understand why encryption is important and spread the word to other users.

On a second note I too also recommend TrueCrpyt to everyone I talk to for their personal data. I recommend they set it up on a usb thumbdrive and encrypt the entire drive to store their personal and financial data.
<<

don

User avatar

Administrator
Administrator

Posts: 4226

Joined: Sun Aug 28, 2005 10:47 pm

Location: Chicago

Post Sun Nov 26, 2006 11:23 am

Re: Full Disk Encryption - Is it time?

I'm sure all of you would have found this on your own, but just to make things easy:

http://www.truecrypt.org

Don
CISSP, MCSE, CSTA, Security+ SME
<<

slimjim100

User avatar

EH-Net Columnist
EH-Net Columnist

Posts: 385

Joined: Wed Nov 08, 2006 12:50 pm

Location: Atlanta

Post Tue Nov 28, 2006 12:23 am

Re: Full Disk Encryption - Is it time?

Thanks for the link Don I forgot to post it. :D

Slimjim100
CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
<<

dalepearson

Sr. Member
Sr. Member

Posts: 357

Joined: Thu Nov 09, 2006 10:03 am

Post Tue Nov 28, 2006 8:06 am

Re: Full Disk Encryption - Is it time?

Is anyone running Vista and BitLocker yet?
I will be moving to Vista this week and I am thinking of giving it a go.
I dont really store much data on my local machine so not to sure of the benefits for myself at this stage.
<<

mn_kthompson

User avatar

Jr. Member
Jr. Member

Posts: 58

Joined: Tue Sep 19, 2006 1:59 pm

Location: Mankato, MN

Post Tue Nov 28, 2006 3:05 pm

Re: Full Disk Encryption - Is it time?

We were evaluating Bitlocker, and ultimately decided to go with Pointsec for our full disk encryption needs.  My hope is that eventually all of our laptop computers will be protected by Bitlocker.

Truecrypt is a great program, but it depends on us being able to force our users to save their data to a certain folder.  We haven't even been able to get our users in the habit of saving data to their network share rather than their hard disk.  If we can't get them to use one folder of our choosing, how could we get them to use another?  We decided that the only way to really protect our data is to encrypt the entire drive.

The problem with Bitlocker is that it is dependent on a TPM 1.2 chip, which only started shipping in the first half of 2006.  If you don't have that chip, and you want to use bitlocker, then users will have to keep the key on a USB drive.  We decided that the most likely place that users will keep their USB drive is in the case with their laptop.  Pointsec allows us to encrypt the entire drive, and keep it completely transparent to our users.  That transparency will reduce resistance from the users hopefully.

Return to Hardware

Who is online

Users browsing this forum: No registered users and 0 guests

cron
.
Powered by phpBB® Forum Software © phpBB Group.
Designed by ST Software