bwestlake Posted June 14, 2013 Posted June 14, 2013 We are looking at encrypting our staff laptops. Installed W7 Enterprise thinking to use bitlocker... Need TPM these laptops do not have TPM. Looking for some free encryption software, easy for staff to use, and will encrypt the whole hard drive.
mats Posted June 14, 2013 Posted June 14, 2013 Truecrypt whole drive encryption works well for us. No TPM required, not dependent on windows version.
LeMarchand Posted June 14, 2013 Posted June 14, 2013 We use TrueCrypt if we can't use BitLocker, though it involves an additional password page which the staff don't like. Easy to use, though - the staff just input a password at boot, then everything is as normal.
Rawns Posted June 14, 2013 Posted June 14, 2013 Also TrueCrypt here. We use it on all of our USB drives. Works a treat.
3s-gtech Posted June 14, 2013 Posted June 14, 2013 (edited) Also on Truecrypt. Any laptops that leave the site have a password on boot, very simple. Their external HDDs are also encrypted. We went with it for the same reason - no TPMs (Lenovo X130e). Edited June 14, 2013 by 3s-gtech
sted Posted June 14, 2013 Posted June 14, 2013 you dont NEED a tpm for bitlocker it makes things easier but im sure it can be used with a flashdrive and pin if you dont have a tpm
maark Posted June 14, 2013 Posted June 14, 2013 You can still use bitlocker without tpm - use a flash drive as a key. Only problem is if staff lose/forget them then you have use recovery password to start the laptop. Advantage of bitlocker is that recovery keys are saved in active directory.
psydii Posted June 14, 2013 Posted June 14, 2013 And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost.
sted Posted June 14, 2013 Posted June 14, 2013 And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost. and if you have a tpm you can be a real swine and require usb/pin/tpm to get in
nicholab Posted June 14, 2013 Posted June 14, 2013 What happens if the laptop breaks? and the motherboard is replaced?
sted Posted June 14, 2013 Posted June 14, 2013 What happens if the laptop breaks? and the motherboard is replaced? with bitlocker you look up the recovery key in active directory shove the drive in another win7 pc (as either boot or extra drive) and type in the 40 digit code when it asks for it
LeMarchand Posted June 14, 2013 Posted June 14, 2013 You can still use bitlocker without tpm - use a flash drive as a key. Only problem is if staff lose/forget them then you have use recovery password to start the laptop. Advantage of bitlocker is that recovery keys are saved in active directory. Shouldn't that be when they lose them? What happens if the laptop breaks? and the motherboard is replaced? We have offline files set up, and all staff are briefed that anything not stored in the "documents" part of "My Documents" is not synced (that includes the rubbish they coat their desktops with as well as their dubiously obtained media) and that if the drive/laptop fails then such files will almost certainly be lost - so they should make their own backups. (I'm betting they don't, but that's not my problem and I will have no sympathy when the inevitable happens).
Ashm Posted June 14, 2013 Posted June 14, 2013 One other option is to use usb startup keys with the laptops without TPM or use Windows 8 which allows you to use password on startup as well as the usb startup option in Windows 7 for laptops without TPM.
sted Posted June 14, 2013 Posted June 14, 2013 for bitlocker if you have server 2008r2 (and i assume 2012 is the same or near enough) go to server manager, add features, remote server admin tools, feature administration tools, and tick the bitlocker drive encryption admin utils (for windows 7 install rsat tools then do the same as above). then in active directory users and computers you get an extra tab on computer accounts
ConradJones Posted June 14, 2013 Posted June 14, 2013 And the advantage of a usb is that it forms a form of second factor authentication to get onto the laptop. If they use them, they should keep them on their personal keyring, make them less likely to be lost. possibly might keep them on heavy key rings and damage the usb socket from the weight
free780 Posted June 14, 2013 Posted June 14, 2013 Anyway of scripting the truecrypt install and encryption? Thats its downside. Bitlocker is better but not really secure as staff will leave the usb stick in the laptop making it pointless. You really should be using truecrypt even if you have to install it manually The ico can fine if sensative data is lost.
Ephelyon Posted June 14, 2013 Posted June 14, 2013 As far as I know there's no way of scripting TrueCrypt; that's why we use this: Main Page/en - DiskCryptor wiki I can automate that as part of my staff laptop auto-build process.
Ephelyon Posted June 15, 2013 Posted June 15, 2013 It has a command-line version that accepts all necessary parameters. I've posted in detail about the scripting we use here to automate the entire re-imaging process here.
sted Posted June 15, 2013 Posted June 15, 2013 Anyway of scripting the truecrypt install and encryption? Thats its downside. Bitlocker is better but not really secure as staff will leave the usb stick in the laptop making it pointless. You really should be using truecrypt even if you have to install it manually The ico can fine if sensative data is lost. even with the pendrive in they still require a pin code or ot wont boot with bitlocker
Ashm Posted June 15, 2013 Posted June 15, 2013 even with the pendrive in they still require a pin code or ot wont boot with bitlockerThat's not true. No TPM, no pin option with Bitlocker. If you're thinking of deploying Windows 8, the password option is well worth a look for devices without TPM. I believe it allows standard users to change the Bitlocker boot password with the key benefit of the encryption keys being stored in AD in case you need to preform any recovery etc.
markwilfan Posted June 15, 2013 Posted June 15, 2013 You can defo do bitlocker without TPM or pin with a USB start up.
markwilfan Posted June 15, 2013 Posted June 15, 2013 AFAIK as long as the device has a TPM module you can do away with the USB. The USB does the same job as the TPM.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now