kaphc Posted June 26, 2013 Posted June 26, 2013 One of the recommendations from the audit was the staff using laptops running Windows 7 use the built-in encryption to secure data on their hard drives. I've had a look and assume that the auditors were referring to Bitlocker. Unfortunately, this only seems to be available in Windows 7 Enterprise and Windows 7 Ultimate, and we are running Windows 7 Professional. Can anyone recommend any free third-party software that would do similar to Bitlocker? Ease of use for the end user if a high priority!
rush_tech Posted June 26, 2013 Posted June 26, 2013 TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows 7/Vista/XP, Mac OS X and Linux 1
kaphc Posted June 26, 2013 Author Posted June 26, 2013 That looks great and exactly the sort of thing that the auditors were on about. However, I can't see the school agreeing to use it because of the implications if a teacher forgets their password and the hard drive becomes permanently locked! I can see this school implementing a policy of never saving to the hard drive and only using encrypted USB storage for files instead.
Rawns Posted June 26, 2013 Posted June 26, 2013 +1 for TrueCrypt. Awesome piece of software! We use it on all of our external drives.
kaphc Posted June 26, 2013 Author Posted June 26, 2013 Am curious about the size of the school where this is implemented - I'm at a small primary school this morning with 7 classes, about 25 staff and therefore about 10 laptops this would apply to. Are we using a sledgehammer to crack a nut??!
rush_tech Posted June 26, 2013 Posted June 26, 2013 That looks great and exactly the sort of thing that the auditors were on about. However, I can't see the school agreeing to use it because of the implications if a teacher forgets their password and the hard drive becomes permanently locked! I can see this school implementing a policy of never saving to the hard drive and only using encrypted USB storage for files instead. When you encrypt the HDD you can make a recovery CD to recover the drive if the password is forgotten
cogrady84 Posted June 26, 2013 Posted June 26, 2013 When you encrypt the HDD you can make a recovery CD to recover the drive if the password is forgotten I was under the impression the recovery CD is only used to unlock the encrypted drive in the event of hardware failure and needing to slave the drive to recover the data, but the password is still required?
Garacesh Posted June 26, 2013 Posted June 26, 2013 about 10 laptops this would apply to. Are we using a sledgehammer to crack a nut??! I wouldn't say so. The device can be taken off-site and thus the data should be encrypted by law, as far as I'm aware. (Although realistically any device can be taken off-site, reasonable measures apply. Servers are kept behind locked doors, etc. Laptops are made to be portable, so encryption is a must if they're storing any school data) While I've never used TrueCrypt (as we have Enterprise here) the hundreds of +1's I've seen make it sound like a good choice. Also I know there are recovery options available for if the password is lost etc. Realistically you could order that the staff do not use passwords similar to their logon passwords and that they give you a copy of it which you would store in a secure location i.e. part of the network only you can get to.
LukeC Posted June 26, 2013 Posted June 26, 2013 (edited) +1 Truecrypt. Works very well here, we set up true crypt on the laptops before they go out and record the password somewere secure as well as keeping a copy of the rescue disk. We are also a small school we have this on around 35 staff laptops. Edited June 26, 2013 by LukeC
cogrady84 Posted June 26, 2013 Posted June 26, 2013 When you encrypt the HDD you can make a recovery CD to recover the drive if the password is forgotten Just to clarify, an exceprt from the TruCrypt FAQ on the rescue disk: "Note that even if you lose your TrueCrypt Rescue Disk and an attacker finds it, he or she will not be able to decrypt the system partition or drive without the correct password." The rescue disk simply provides access to the boot loader for your encrypted volume, in case it becomes corrupted on the drive itself, the password is still required to gain access
theriver Posted June 26, 2013 Posted June 26, 2013 I was under the impression the recovery CD is only used to unlock the encrypted drive in the event of hardware failure and needing to slave the drive to recover the data, but the password is still required? You should do two things: 1) make a record of the encryption password 2) make a copy of the recovery disk . . and both of these should be stored centrally and securely, not by the user. You can use the recovery disk in the event that the TrueCrypt password gets changed and the user forgets the new password - you still need the password associated with the initial encryption run. When slaving the drive the easiest option is to have TrueCrypt installed on the PC, and then mount the slaved drive through it. Having encrypted USB sticks just gives you a different set of problems. If they forget the password, the data is still locked away. Though this is all academic as your users back up all their data, don't they ;-)
clockend25 Posted June 26, 2013 Posted June 26, 2013 We use Truecrypt on about 80 or so staff laptops. Passwords are unique but formulaic, and are stored centrally by IT, as are the recovery disk ISOs.
pete Posted June 26, 2013 Posted June 26, 2013 When you build the laptop, you create the rescue disk .iso and you keep it and the password you use in a secure place. As part of the end-user setup, you reset the header password from within the Truecrypt GUI to a password the end-user chooses. That way you have a means of accessing the encrypted device independently of the end-user, should they forget their password / leave the school. ==== In short, encrypt the laptops. If your end-users have to make a conscious decision on whether a document needs encrypting or not, you're doomed to failure. By encrypting the laptop, stuff is secure by default.
edutech4schools Posted June 26, 2013 Posted June 26, 2013 Why not use a vpn and give staff access to the data on the server from home, that way they never need to carry school data on a laptop.
cogrady84 Posted June 26, 2013 Posted June 26, 2013 Why not use a vpn and give staff access to the data on the server from home, that way they never need to carry school data on a laptop. That's not really a bulletproof solution, and wouldn't be a credible workaround to the ICO, as you are not enforcing a policy of no mobile data unless it is encrypted.
theriver Posted June 26, 2013 Posted June 26, 2013 That's not really a bulletproof solution, and wouldn't be a credible workaround to the ICO, as you are not enforcing a policy of no mobile data unless it is encrypted. This ties up nicely with the http://www.edugeek.net/forums/hardware/116470-laptops-staff-implications.html thread. A school nearby no longer purchases laptops for teachers - this trend started at a time when home PC's were fewer and further between after all - and instead each classroom has a desktop and home access to data is via VPN and Terminal Server, so in theory no data leaves the site. Staff work on lessons at home and bring them on memory sticks.
edutech4schools Posted June 26, 2013 Posted June 26, 2013 That's not really a bulletproof solution, and wouldn't be a credible workaround to the ICO, as you are not enforcing a policy of no mobile data unless it is encrypted. Are you saying that the way banks ,businesses, universities etc using vpn to access a server is not bulletproof or have I misunderstood. You get the staff to sign a policy that says they will only work on network drives and not save work to the desktop etc. They then connect to the server using 2 form authentication + encryption. Why would the ICO have an issue with this?
cogrady84 Posted June 26, 2013 Posted June 26, 2013 (edited) Are you saying that the way banks ,businesses, universities etc using vpn to access a server is not bulletproof or have I misunderstood. You get the staff to sign a policy that says they will only work on network drives and not save work to the desktop etc. They then connect to the server using 2 form authentication + encryption. Why would the ICO have an issue with this? Sorry, i don't mean that there is anything wrong with that method of access, I just mean, just by providing that solution, you are not enforcing them to ONLY use that, they still have an option of carrying around unencrypted devices and storing data on them. I think the best solution would be to provide VPN, but also have access control on stored data, so that it cannot be transferred to external devices unless either the data or the device is encrypted. This is a policy option with Sophos, for example. Paperwork in place or not, people will still do things they are asked not to, so data control is necessary. Edited June 26, 2013 by cogrady84
kaphc Posted June 26, 2013 Author Posted June 26, 2013 As it happens, our LA doesn't allow VPN access from home, which leads most teachers down the line to the hard drive / USB storage solution as it's quick and easy. I appreciate the need for data to be encrypted when it's off-site to minimise risk. But also I'm looking at the fact this has been recommended by an audit at one school but nothing's been mentioned in the audits of the other three who do exactly the same thing! Is is a case of encryption is best practice or mandatory or just "nice to have" in your professional opinions? Are there any standards or minimum requirements stated anywhere that I can quote for the need to do this?
edutech4schools Posted June 26, 2013 Posted June 26, 2013 As it happens, our LA doesn't allow VPN access from home Ou LA once told our schools they were required by law to use Sims Gateway. Pinch of salt with anything LA says. You will probably find they control the ports or some other part of the IT system and like to keep things standardised as it is easier for them to manage, but at the end of the day it is up to the school to run itself. I can not tell you how much simpler and better our systems have been since installing RDS (remote desktop services) for the staff to access from home. Why would the LA want to stop you doing this?
cogrady84 Posted June 27, 2013 Posted June 27, 2013 (edited) As it happens, our LA doesn't allow VPN access from home, which leads most teachers down the line to the hard drive / USB storage solution as it's quick and easy. I appreciate the need for data to be encrypted when it's off-site to minimise risk. But also I'm looking at the fact this has been recommended by an audit at one school but nothing's been mentioned in the audits of the other three who do exactly the same thing! Is is a case of encryption is best practice or mandatory or just "nice to have" in your professional opinions? Are there any standards or minimum requirements stated anywhere that I can quote for the need to do this? I'm not sure about it being mandatory, although your LA would usually have a policy that if you are connected to their network, you have rules to follow as a responsible party. Encryption of data that is leaving your system I would say is definately classified as "best practice", my point of view is, if one of my staff takes a laptop offsite, with sensitive information on it, leaves it in the back of their car and it is stolen... How long before that data either ends up in the wrong hands or in the public domain? It is your responsibility as a network administrator to ensure safe and secure storage of data. If you hold student/parent contact information in your MIS, and that is portable, it must be protected, surely? This is just my opinion, i'm not sure about what each LA or the law requires? It is too easy to reset the user/password registry hive in Windows 7 with UBCD for example, and gain complete control of the device and the data it holds, encryption prevents that. Edited June 27, 2013 by cogrady84
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now