Jump to content

Recommended Posts

Posted

Hello,

 

so I've been asked to "check out" Full Disk Encryption for Windows 7 Laptops for teachers Within my secondary school, Any recommendations?

Posted

Do your laptops have TPM chips? If so, how about Bitlocker?

 

We've tested out TrueCrypt here and are quite happy with the results, but we're also Sophos AV users and have noticed that we'll get their disk encryption product bundled in for no additional cost, so we're also going to be seeing how that fairs.

Posted

I am aware of Bitlocker and ive heard of Truecrypt but never had the pleasure of using them, any good?

 

as for TPM chips, I advised which supplier to go with yet, Dell, IBM etc but once I do ill try and ensure they have the TPM chips.

Posted
If they are Dell Latitude they will have a TPM, assuming they are 5 years old or less?

 

they will be brand new, its a Brand new building with Brand new equipment.

Posted

I use DiskCryptor for full-disk encryption as it's free and I can script it as part of the auto-build process for laptops.

 

BitLocker is used for staff USB stick encryption, customised to make it the "deny write to non-encrypted removable storage" GPO setting per-user rather than per-computer (though some AutoIt devilry).

Posted
Truecrypt here, staff also get the option to encrypt their memory sticks etc. Been well received, it's very good but the interface is confusing for non-techie users.
  • Thanks 1
Posted

We're starting to use Truecrypt on our staff laptops (started with the new Heads one since he's not officially with us until September so wanted any data he's been provided nice and secure :))

 

We already use it on staff USB drives, but we will likely roll it out to all staff laptops starting with SMT ones as and when we get them in for updates.

Posted

Be aware that only Windows 7 enterprise supports Bitlocker. Win7 pro does not. Windows 8 pro does.

 

Thanks M$

 

We're trying Sophos as we have the av subscription already. Also looking at Intel anti theft, supported by some of their chipsets, although the main thing you find on google about that is problem reports.

Posted
Bitlocker it's built into Windows 7. If you have a TPM you don't need a boot password.

+1 for the same reasons. Plus these...

 

  1. The recovery keys are stored safely in Active Directory.
  2. MDT and SCCM can automate the initial encryption of the drive.
  3. You can access the files on an encrypted drive in Windows PE (after you have supplied the recovery password). Good if you can't boot into Windows 7 or 8 and need to get the data off the drive.
  4. Windows 8 can encrypt just the space occupied with data which saves a lot of time with large HDDs. Both TrueCrypt and Windows 7 have to encrypt everything (even the empty space).
  5. eDrive support in Windows 8 means you can encrypt drives in a few seconds. Hard drives that have built-in hardware-based encryption are also supported (there should be less of a performance hit with these).
  6. Bitlocker To Go seems simpler for staff to understand compared to TrueCrypt and doesn't required any additional software to be installed.
  7. Can be controlled through Group Policy.

http://i.imgur.com/lZsw5px.png

  • Thanks 1
Posted (edited)

*Windows 8 can encrypt just the space occupied with data which saves a lot of time with large HDDs. Both TrueCrypt and Windows 7 have to encrypt everything (even the empty space).

Further to this Windows 8 allows for a user password on boot method for devices without TPM rather than the only option being the USB startup key method with Windows 7. Plus I believe standard users can change the TPM pin & the new user password method, where as with Windows 7 they had to be an administrator user. Edited by Ashm
Posted

I was recommended Bitlocker for Windows 7, not used it myself but good reviews.

 

I have used McAfee Endpoint Encryption (was Safeboot), once setup its quite a good product, have also used the Sophos one thats good too but would personally go down the TrueCrypt route if it was for a handful of laptops.

 

Sophos and Safeboot both integrate with AD.

Posted
Sophos do an encryption program which will allow a laptop disc to be encrypted. We have used it on XP only, not tried it on Windows 7.
  • 3 months later...
Posted

Sophos usb encryption will encrypt any removable storage inserted. Correct? If not is there a policy to allow only read only access for non-encrypted storage?

 

I've found that the performance hit with TrueCrypt is larger than expected on a new dual core laptop. Windows experience index is unaffected however.

Posted
+1 for the same reasons. Plus these...

 

  1. The recovery keys are stored safely in Active Directory.
  2. MDT and SCCM can automate the initial encryption of the drive.
  3. You can access the files on an encrypted drive in Windows PE (after you have supplied the recovery password). Good if you can't boot into Windows 7 or 8 and need to get the data off the drive.
  4. Windows 8 can encrypt just the space occupied with data which saves a lot of time with large HDDs. Both TrueCrypt and Windows 7 have to encrypt everything (even the empty space).
  5. eDrive support in Windows 8 means you can encrypt drives in a few seconds. Hard drives that have built-in hardware-based encryption are also supported (there should be less of a performance hit with these).
  6. Bitlocker To Go seems simpler for staff to understand compared to TrueCrypt and doesn't required any additional software to be installed.
  7. Can be controlled through Group Policy.

http://i.imgur.com/lZsw5px.png

 

I agree, BitLocker here (Windows 7). SCCM Task Seq turns it on and backs up Recovery Key to AD. BLTG for USB pens also with Recovery Key backup to AD.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...