Follow Us

Deciphering laptop encryption

Three hard disk encryption programs. But which one to choose?

During the past two weeks, I started up a disk encryption project, one of the technology initiatives under my company's intellectual asset protection program.

Our goal with the disk encryption effort is to prevent the loss of intellectual property stemming from the theft of a laptop. On several occasions, executives' laptops have gone missing or been stolen. One of those missing laptops contained intellectual property and sensitive data, including information on a pending acquisition, product strategy and road maps. Luckily, it was recovered.

Should something like that happen again, we want the data on the laptop's hard drive to be illegible, which means we have to encrypt the entire hard drive. I assembled a team of representatives from our help desk, Windows engineering and Web applications groups and my information security team. After the initial project meeting, which familiarised everyone with the scope of the project and the state of the technology, we considered three products: Microsoft’s Encryption File System (EFS), PGP’s Whole Disk and Pointsec Mobile Technologies' Pointsec for PC.

EFS was attractive in that it comes built into Windows and is therefore basically free. Plus, Microsoft is a large company and we already have a relationship with it, so its viability and support structure aren't unknowns. But we wanted a product that would encrypt the entire hard drive and not just individual files, require no change in the way users utilized their laptops and be compatible across all of our platforms.

So, as appealing as EFS was, it was quickly eliminated, mostly because it can't encrypt the entire volume. Besides that, there are some issues regarding sharing files between Windows XP and Windows 2000, and there's a good chance that files could end up in areas of the drive that aren't encrypted. It's true that we could get around that last problem by using group policies to control the configuration of users' laptops, but the project team had decided against group policies. Finally, EFS doesn't support Linux, which would leave out many of our engineers.

On to PGP. I like PGP, and we use it for e-mail encryption. Almost every security professional I know has a PGP key, and I thought we could integrate that technology with the whole-disk encryption. Unfortunately, the PGP full-disk encryption offering is new, and the project team felt more comfortable with a product that has been around a while and has a history of large deployments.

This left us with Pointsec for PC, which does in fact meet all of our requirements. It also has offerings for the Palm OS and Pocket PC operating systems and for some of our smart phones. Pointsec for PC uses a preconfigured agent that, when installed on a user's laptop, will seamlessly encrypt the entire hard drive and then modify the master boot record (MBR) so that a user must authenticate to the software embedded in the MBR before being allowed access to the PC.

As you probably know, the MBR is the information in the first sector of a hard drive that identifies where the operating system is located so that it can be booted into memory. Modifying the MBR is risky; if the hard disk is encrypted and the MBR becomes corrupted, the data on the drive is essentially gone. This is a risk that will have to be dealt with through proper backups.

Users, however, will still use their enterprise credentials and authenticate only one time. The software within the MBR will pass the authentication credentials through to the operating system log-in. Once authenticated, the user should see no noticeable degradation in service. The idea is that we'll configure the agent and place it on one of our intranet Web pages. Users who need or simply want to use full-disk encryption will contact the IT department and acquire the software and appropriate instructions.

As with any global deployment, we need to define a help desk support model. Pointsec accomplishes this with a Web-based tool that lets help desk administrators access a single management system to assist users in the event that they are locked out of a mobile device.

One of the concerns was what to do when employees leave the company or when a laptop has to be reviewed as part of an investigation or other legal/HR matter. Pointsec (as well as the other products mentioned) offers a key-escrow functionality that includes the concept of a "god key" that enables the laptop to be decrypted by a trusted authority. In our company, that trusted authority will most likely be me.

The next step in the project is to start a proof of concept to allow the team to become comfortable with the technology and to give us the opportunity to test the software against our extremely dynamic environment.

Unlike in financial services, health care and some other regulated industry, our users have all sorts of what I like to call funky applications installed on their laptops. For example, some engineers and developers have various debugging tools and employ multiboot environments, all of which will have to be tested at length. In addition, we are a global company, so we have to ensure that the product can be used on laptops with language packs or an operating system in another language.

But I'm fairly confident that we will have a successful deployment and will soon be providing this disk encryption software to address the current and future needs of the company.



Comments

Masclat Pete said: Doesnt the free program Truecrypt do full disk encryption

David Lawrence said: This is a great article - but it is getting pretty dated Pointsec is still the leading solution but implementation is now much easier Services like Alertsec offer hard disk encryption as a fully managed service They provide protection for all information stored on laptops and PCs in an easy convenient and cost-effective way By using industry leading Check Point Full Disk Encryption former Pointsec software Alertsec has created a web based encryption service that radically simplifies deployment and management of PC encryption It is a heck of a lot easier for an enterprise than trying to manage all those laptop encyptions on your own




Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Optimise Performance For Global eCommerce

Global is all the rage: eBusiness teams are feverishly building new international initiatives in...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Techworld UK - Technology - Business

Part 2 of your journey to virtualisation

You can still access part 2 of our virtualisation journey - explore how you can improve your servers, storage and networks by developing your infrastructure.

Watch now...
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *