Jump to content

Recommended Posts

Posted

Evening folks,

 

I have started a new post at a school... Been here about 4 months...

 

Now we use Trucrypt for desktop and laptop encryption...

 

Now instant reply was BITLOCKER... Then i cried when I found out that a total of 0% of the hardware on site has TPM chips installed....

 

So now I am looking at possible alternatives...

 

What does anyone know about a centrally managed preferably cheap solution for Drive encryption.

 

I need something that preferably I can just leave and it encrypts the machines on its own.

 

Hope someones got something for me.

 

Matt

Posted
Well it's free so you could push it out using sccm. However there is no management. If you want that you probably need to spend some money on an enterprise solution.
Posted

Now instant reply was BITLOCKER... Then i cried when I found out that a total of 0% of the hardware on site has TPM chips installed....

 

0% Seriously?!

 

DiskCryptor, albeit not quite as rounded as Truecrypt.

 

Shame about BitLocker... As free780 has already said, an enterprise solutions is also a possibility.

Posted

Windows 7 pro although I'm slowly moving to enterprise.

 

Yup a nice 0%

 

The network manager has been buying zoo storm machines. Which are pretty basic so say the least.

 

I have said however for future purchases that we make sure they have Tpm modules. So we will see what happens.

 

To be honest I think if we want to save money it's going to be a case of just replacing old true crypt machines with new ones that have Tom modules.

 

Or I'm going to need to spend some money...

 

If I was to spend money on this do we have any suggestions to put out there?

 

Matt

Posted
Windows 7 pro although I'm slowly moving to enterprise.

Any scope for moving to win 8.1 Pro? Bitlocker can be used with just a password a la Truecrypt. Our Win 8.1 Pro laptops use this and its great (recovery keys are stored in AD which is a boon).

I looked at sophos solution. Seemed OK. Targeted at 1 user per laptop. Do you want to encrypt every desktop and laptop?

Our Win 7 laptops use Sophos which is...ok. It works by you specifying users that are allowed to unlock the machine at boot time so not really suitable for multi-user machines unless you have a significant amount of time on your hands to setup and maintain.

Also, every so often, we have a spate of corrupted boot loaders that need fixing which is a PITA.

Posted
We are using Sophos Safeguard Easy. It's not central managed but is does what we need. We have a similar issue as you in that 99% of our laptops don't have TPM. That's fine as most use Windows 7 with Sophos POA but ran into the same issue as you with Bitlocker when using Windows 8. Because there was no TPM we had to use USB to access the laptop.
Posted

You can use Windows 7 enterprise and use a usb stick with bitlocker if you have no tpm module.

The machine will need the usb stick inserted to allow it to boot so this also acts as another form of security.

Recovery passwords are then stored in active directory.

Posted
but ran into the same issue as you with Bitlocker when using Windows 8. Because there was no TPM we had to use USB to access the laptop.

Not sure if I read that right but with Win 8 there is no need to use USB if you have no TPM, you can just use a password, that's what we do here.

Posted
I looked at sophos solution. Seemed OK. Targeted at 1 user per laptop. Do you want to encrypt every desktop and laptop?
We used this at one school I was at and it is a pain. It frequently locked users out of their laptops; to overcome this there is a challenge/response screen. The challenge generates an impossibly long string, which we then had to read out to the LEA, who had the software to generate the appropriate response, which we then had to enter into the machine to unlock it. Often this failed, and we then had to talk to the only sophos expert in the LEA. He was never available (no doubt fixing sophos problems for other schools). One day, the principals laptop was locked and naturally I couldn't get any sense out of the LEA. I phoned sophos direct and they helped me out after quoting licence codes at them,.
Posted
Not sure if I read that right but with Win 8 there is no need to use USB if you have no TPM, you can just use a password, that's what we do here.

 

Using Safeguard Easy?

Posted
No, if you are using Windows 8 Pro and have no TPM you can use Bitlocker with just a password, no TPM required.

 

How do you recover if the user forgets password or if you need to work on laptop without knowing password. We very often have a user drop their laptop in for use to work on which is why we use Sophos POA to gain access.

 

I would prefer to use your solution if i can gain access to the laptop without knowing the users password.

Posted
How do you recover if the user forgets password or if you need to work on laptop without knowing password. We very often have a user drop their laptop in for use to work on which is why we use Sophos POA to gain access.

 

I would prefer to use your solution if i can gain access to the laptop without knowing the users password.

Recovery keys are stored in AD, just look at the properties of the machine and the key is listed. You can use this to log onto the machine :)

  • Thanks 1
Posted
We've just started deploying BeCrypt to any machines that won't run TrueCrypt. It's not free, but it is reasonably priced, has a central management option, and is straightforward and reliable to use
Posted

I thought a good deal of doubt had been cast over that announcement? (Depending on the size of your tin foil hat).

 

My personal feeling is that it's probably a good idea to move away from TC where possible, but I'm not rushing to dump it ASAP.

Posted
I thought a good deal of doubt had been cast over that announcement? (Depending on the size of your tin foil hat).

 

My personal feeling is that it's probably a good idea to move away from TC where possible, but I'm not rushing to dump it ASAP.

 

When it comes to security, I tend to try and err on the side of caution. Wouldn't want to be caught out!

Posted
But with Truecrypt, I know they stopped development because they refused to plant NSA backdoors - at least by using it I know the US Gov can't hack it.

 

You *know*? No-one else knows this, so how do you know?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...