Jump to content

Recommended Posts

Posted

Were going down the route of encryption and looking to use Bitlocker.

 

Most of our laptops don't have a TPM chip so I will need to use a USB startup key.

 

Rather than a USB key I thinking about using a SD card as all the laptops have SD card readers built-in. This would mean that the staff could leave the SD card in the laptop without needed to remove and eventually loose the USB drive.

 

So from what I understand, doing it this way is the same as using the TPM on board. If the laptop is stolen the SD key is taken with it as it is in the laptop already. But this would be the same with a laptop that had an onboard TPM.

 

Can anyone see any problems with this?

 

From what I have read the data is still encrypted and a thief would need to know the windows credentials to get access to the machine. If their tried to boot from a Linux CD or reset the windows password then they wouldn't be able too as the data would still be encrypted..

Posted (edited)

I can see the logic. If they were to remove the HDD and mount in another machine it would be encrypted. But if they have the key also would they not be able to decrypt the HDD within another windows install? I doubt the TPM chip can be simply read as the SD card would be..

 

We went for USB sticks, they can remove them as soon as it starts to boot so not had any damaged as of yet.

Edited by burgemaster
Posted
Isn't that the same as stealing the laptop with the TPM attached?

The TPM is significantly more secure than an SD card or USB flash drive. Unless the thief works for the NSA/GCHQ, I don't think you would have to worry about the decryption keys being extracted.

 

If you left the SD card in the laptop and it was stolen, someone could extract the keys from RAM relatively easily after it has been booted up. For this reason, you may want to consider preventing the installation of Firewire and Thunderbolt drivers through Group Policy.

 

Blocking the SBP-2 driver and Thunderbolt controllers to reduce 1394 DMA and Thunderbolt DMA threats to BitLocker

Posted (edited)
But if someone steals the laptop the sd card will be left in. It makes encryption a bit pointless.

 

Isnt that the same as stealing the laptop with the TPM attached ?

 

The thing is, both situations still result in a laptop that is inaccessible to the thief - unless they have the user's password - in which case all bets are off. They can't log in, so can't access data. They can't remove the HDD and access data. They can't boot off an OS disc and access data.

 

Not to mention, you can make it 2 factor auth quite easily - by enabling the need for a PIN to be entered. So now you have to know something as well as know something.

Edited by localzuk
Posted (edited)

Can't do PIN without TPM in BitLocker and I'm fairly sure the Bitlocker key file that will be on SD card could be used to unlock the laptop hdd by connecting it to another computer with Bitlocker available or by running WinPE and using the bde-manage commands.

 

I agree with Arthur and the smaller usb drives on a keyring is possibly the way to go or look at Windows 8 which I believe you can set a password on boot rather than using usb drives to unlock drive on boot for laptops without TPM.

Edited by Ashm
Posted
I'm fairly sure the Bitlocker key file that will be on SD card could be used to unlock the laptop hdd by connecting it to another computer with Bitlocker available or by running WinPE and using the bde-manage commands.

The recovery key doesn't have to be stored on the SD card, just the startup key.

 

or look at Windows 8 which I believe you can set a password on boot rather than using usb drives to unlock drive on boot for laptops without TPM.

Good idea! :)

Posted
AFAIK, the use of an SD card is the same as using a USB key. In which case, you can have both key + PIN by using the manage-bde command to enable Bitlocker.
  • 5 weeks later...
Posted (edited)

Hi everyone,

 

Depending on your security requirements, there is a SD card with built in smart card and TPM. It's marketed for mobile devices and tablets but might work on laptops which have no onboard TPM. I have not checked to see if it has driver support for Windows 8.1. See:http://www.safenet-inc.com/multi-factor-authentication/authenticators/pki-smart-cards/government-mobile-security/. If you are really paranoid, you could get an SSD hd which is edrive compliant in order to offload the crypto to the hardware and use the SD TPM to sure up key security. It might be cheaper to buy a new laptop with a built in TPM and edrive compliant SSD, as opposed to upgrading an existing laptop. Crucial have edrive compliant drives with very fast crypto read/write speeds: http://www.crucial.com/products/m550.aspx

HIDDN also make a nice encrypted SSD drive which has onboard two factor, but the write speeds are much slower than Crucial: http://hiddn.no/laptop/

 

I was passing by the forum and found this discussion. Ive had a similar issue with a client who has 1000's of corporate laptops with no TPM. Cheers, njoy

Edited by njoy

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...