Jump to content

Encryption for Staff Laptops - Any Advice or help please


Recommended Posts

Posted
Are you using the Sophos cloud encryption solution? I was wondering if it works with Windows 7 Pro?

 

if its basically an interface for bitlocker id say no as on win 7 bitlocker is enterprise/ultimate only (but i dont have sophos that supports it to test with)

Posted
Are you using the Sophos cloud encryption solution? I was wondering if it works with Windows 7 Pro?

 

Yes I am using the cloud based sophos central but we are fully windows 10 so not looked into 7

Posted
Im just looking at the Sophos product now on trial, All sophos does is provide a management system for Bitlocker, cost wise on a 3 year deal its about £3 per device per year, not bank breaking but still deciding if its worth it. Next up is MBAM.

 

Over 3000 machines here so Sophos gets pricey quickly. Just had our MS reseller confirm we can use MBAM \ MDOP at no additional cost so decision made for me :)

  • 2 weeks later...
Posted
Do these laptops not have a TPM in them? I have a bunch of ten year old Dells that are Bitlocker enabled with the TPM and keys stored to Active Directory. Usually the TPM has to be enabled and then set to activate in the BIOS.
Posted
You need to test every key and re-encrypt stuff. 25% of the laptops with TPM they tested were flawed.

 

Well, 100% of our laptops work OK with TPM.

Posted (edited)
Am I affected by ROCA?

 

The answer is most likely yes. Even if you aren’t a citizen of Estonia or Slovakia, your personal computer and your workstation may be affected. Microsoft has published an advisory (ADV170012) stating that Windows 8.1, Windows 10, and Windows Server 2012 and 2016 are all affected. BitLocker keys may also need to be regenerated.

 

Estonia is well-aware of the vulnerability affecting 55% of its citizens; the government published an advisory last month, which was followed by an update earlier this week. They stress that the flaw remains theoretical and is difficult to execute, so they have decided not to recall the affected smartcards. Some of their services use the ID smartcard to supplement a username and password, which an attacker would not have.

 

You can test RSA public keys against the ROCA flaw with these tools:

https://keychest.net/roca

https://keytester.cryptosense.com/

Offline: https://github.com/crocs-muni/roca (relevant code is in Java)

 

How do we fix this?

The authors have made it clear that this flaw is embedded into the hardware and firmware of many devices widely used across the globe. This makes it difficult to completely patch, but there are some mitigating controls.

 

If you are using Windows, Microsoft has issued several updates that should address the issue. Google, HP, Lenovo, and Fujitsu have released updates for their software products as well. Estonian citizens can suspend the digital signature services of their smartcards if they choose. A new chip is in development in the meantime.

Source: https://www.synopsys.com/blogs/software-security/roca-cryptographic-flaws/

Edited by DJ-1701
Posted (edited)

The tpm flaw only effects chips from 1 tpm chip supplier and as far as I am aware dell don’t use the tpm chip affected?

 

Re-reading this it’s a separate software issue..

Edited by gaz350b

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...