flyinghaggis Posted December 10, 2016 Posted December 10, 2016 (edited) Just wanted to ask whether anyone knows if you enable offline files in Chrome (on Microsoft Windows) for Google Docs/Drive whether they're stored encrypted or secured anyway within the browser cache or can this be read by anyone with access to the file system? I'm guessing they aren't encrypted, since it mentions not enabling this facility on shared/public computers, but wondered whether anyone could confirm for sure as I can't find anything describing the actual process of how it works? Edited December 11, 2016 by flyinghaggis
mavhc Posted December 11, 2016 Posted December 11, 2016 don't think they are. You could enabled NTFS encryption for that folder/the whole home dir
mjk Posted December 11, 2016 Posted December 11, 2016 I think it's up to the operating system; ChromeOS is encrypted by default, android you can select whether to disable offline file encryption (it's in drive settings on android). On windows the files are in C:\Users\\AppData\Local\Google\Chrome\User Data\Default\File System Unfortunately I don't have a windows PC at hand to check
flyinghaggis Posted December 11, 2016 Author Posted December 11, 2016 (edited) Thanks for the replies guys. I guess the angle I'm approaching this from is the point of view of how secure these files are on personal devices and whether it's safe leaving offline files enabled. My main worry is what happens if staff are caching copies of files to their own laptops/tablets/phones/etc and any of these devices end up being lost/stolen what's potentially recoverable from them. Most Google sites and companies generally seem to suggest disabling offline files due to the potential loss of control of company/school data but I know some of our staff use the functionality so it's probably something we need to run past SLT first and let them make the call. Do you allow staff to make copies of offline files at your school? Edited December 11, 2016 by flyinghaggis
southhamster Posted December 11, 2016 Posted December 11, 2016 Using gsuite for education you can enrol android and apple phones into management with remote locking or erasing which may be handy. Doesn't solve the problem of laptops though.
flyinghaggis Posted December 11, 2016 Author Posted December 11, 2016 (edited) Using gsuite for education you can enrol android and apple phones into management with remote locking or erasing which may be handy. Doesn't solve the problem of laptops though. I did suggest this but the feedback from SLT was they didn't feel it was appropriate for the school to manage staff personal devices like phones. At the moment we're allowing both offline files and staff to sync data to personal devices without any form of control which I feel leaves the school over-exposed. I'll put it to SLT again and see what their thoughts are given this potentially leaves any sync'd school data readily accessible in the event personal devices are lost or stolen. Edited December 11, 2016 by flyinghaggis
yoasties Posted December 16, 2016 Posted December 16, 2016 Would full-disk-encryption on Linux (LUKS), MAC-OS (FileVault) or Windows (Bitlocker) not be sufficient to limit those risks for laptops?
flyinghaggis Posted December 16, 2016 Author Posted December 16, 2016 (edited) Would full-disk-encryption on Linux (LUKS), MAC-OS (FileVault) or Windows (Bitlocker) not be sufficient to limit those risks for laptops? Yeah, I'd be OK with it if the devices were encrypted but the problem is they'll often be staff's own personal devices so we have no way to confirm they've actually encrypted them before offlining files! Plus Bitlocker is only available on Pro versions of Windows so most people's laptops and computers won't even give them the option. Edited December 16, 2016 by flyinghaggis
mavhc Posted December 16, 2016 Posted December 16, 2016 Yeah, they won't be, but their passwords are all simple anyway, so it's not as if stealing a laptop is the enemy's first choice.
yoasties Posted December 16, 2016 Posted December 16, 2016 Well, both Chromebooks and Cloudready devices are encrypted, though the quality does not match LUKS, probably. Implementing Filevault is easy enough to ask MAC users, LUKS or Veracrypt or other good encryption can be asked from most Linux users. Sounds to me that the Windows users are the main problem. Offering help, having policies and asking them to click on "I agree that I have encryppted this environment" etc. may raise concerns about whether the users actually do: but it could be enough. Synchronization would reduce the (sometimes enormous) amounts of information being copied by users that have poor connections and want to work at home.
flyinghaggis Posted December 16, 2016 Author Posted December 16, 2016 (edited) There are limitations as to what we can realistically force and do when it comes to staff personal devices. I don't think there are any technical solutions to the issue so it's basically a case of creating a policy and asking staff to follow it. It's back to SLT really to make the call as to whether they're comfortable with that or want us to restrict offline files! Edited December 16, 2016 by flyinghaggis
yoasties Posted December 17, 2016 Posted December 17, 2016 Good Luck with that. In the current dropbox, Onedrive, Gdrive and 128 Gb USB-drives costing peanuts etc. world one may wonder if the choice should not be formulated between a. Sync'd with some monitoring and control or b/ poorly syncd with lots of manual errors outside our control. :-) It is not known as "Shadow IT" anymore, the register has re-branded it to "Self Starter IT". We'll see.
mavhc Posted December 17, 2016 Posted December 17, 2016 If you really want to control your documents you'll need DRM
yoasties Posted December 18, 2016 Posted December 18, 2016 Doesn't DRM make them read-only (i.e. make collaboration impossible)?
Alis_Klar Posted January 6, 2017 Posted January 6, 2017 If you are really wanting to avoid data leakage you could stop using Google Apps and setup VDI or Citrix to allow logging into a remote desktop session from home that way the document never leaves your premises. There is still the analogue hole of screenshoting a document but I don't think we have to sign the official secrets act in schools yet!
Areku Posted January 9, 2017 Posted January 9, 2017 If you are really wanting to avoid data leakage you could stop using Google Apps and setup VDI or Citrix to allow logging into a remote desktop session from home that way the document never leaves your premises. There is still the analogue hole of screenshoting a document but I don't think we have to sign the official secrets act in schools yet! This is what we did, all drive/file etc forwarding from thehost is also disabled. next phase was to start issuing laptops/desktops with USB ports disabled. (or "removable device" blocked in some cases)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now