Jump to content

Recommended Posts

Posted

What are people's opinion on this situation.

 

We have staff laptops in our inventory that have no TPM chip running Windows 7 ent. Really Really old. Personally nowadays I really do not know how much staff use them and whether they use them for "work" purposes.

 

Recent laptops that I have bought with a TPM chip integrated are already encrypted so not an issue as far as GDPR goes

 

However the no TPM chip laptops, I am planning on recalling all laptops to ensure that all laptops have Bitlocker enabled and force staff to boot with USB and Pin. This is something that I know how to facilitate but concerned that teachers will see the extra step as a burden and no longer use the laptops as an asset. Also slightly concerned about the impact it will have on my support when they inevitably break/lose the usb device. Again I know how to support if the case happens but being on my own just concerned of the impact it will cause on an already stretched IT support, implementing bitlocker on all Non compatible TPM devices and then supporting it when it goes wrong.

 

What have you all done? am I over thinking it? do I need to do it? or should I be recalling all laptops without TPM?

Posted
You're doing the right thing but ignore the USB thing, just set them up to boot with a password. Have the password set to something that's not overly difficult, easy to remember or find out, and different per machine. Serial numbers, asset tags etc are some good resources to get those passwords from to help them avoid sticking a post it with the encryption password on it.
  • Thanks 1
Posted
As to the right thing to do it's up to the school. However, we are in a similar situation and our local IT support have suggested that they will not support us with implementing bitlocker on them as they feel it is not enough. (Although they offer no solution), We are instead looking at Veracrypt on them and replacing with laptops containing TPM as and when we get chance to replace.
  • Thanks 1
Posted

We have staff laptops in our inventory that have no TPM chip running Windows 7 ent. Really Really old. Personally nowadays I really do not know how much staff use them and whether they use them for "work" purposes.

 

Just to clarify. School issued laptops off the domain that staff use at home for personal/work use.

Posted
You're doing the right thing but ignore the USB thing, just set them up to boot with a password. Have the password set to something that's not overly difficult, easy to remember or find out, and different per machine. Serial numbers, asset tags etc are some good resources to get those passwords from to help them avoid sticking a post it with the encryption password on it.

 

Whilst testing I have no other option but to use a usb. the pin option is grey out.

 

the USB acts as the TPM chip and is required for devices with No TPM chip on the motherboard.

 

I know I can set a HDD password but that is not encrypting the drive.

Posted
Wouldn't a laptop with no tpm but offline file cache encrypted suffice. As long as people cannot save files outside their user area should you lose the laptop the files are secure
  • Thanks 1
Posted
As to the right thing to do it's up to the school. However, we are in a similar situation and our local IT support have suggested that they will not support us with implementing bitlocker on them as they feel it is not enough. (Although they offer no solution), We are instead looking at Veracrypt on them and replacing with laptops containing TPM as and when we get chance to replace.

 

I can understand their reluctance to advise as really the method is an option that would create a lot of work for something which is not directly supported. I can understand the easiest and more secure solution would be to recall and replace with TPM chipped laptops. something which schools do not have the budget to do.

  • Thanks 1
Posted
Wouldn't a laptop with no tpm but offline file cache encrypted suffice. As long as people cannot save files outside their user area should you lose the laptop the files are secure

 

the laptops are not domain joined. they were bought years ago (10years ago maybe) solely for the purpose to aid teachers who didn't have the facility to work on a computer at home were given a staff laptop. so happened that once they new they could get one they suddenly all wanted one

Posted
I can understand their reluctance to advise as really the method is an option that would create a lot of work for something which is not directly supported. I can understand the easiest and more secure solution would be to recall and replace with TPM chipped laptops. something which schools do not have the budget to do.

 

Yes, completely understandable, but not very helpful. We certainly don't have the budget to replace them all, which I why we are looking at Veracrypt. It's free and can encrypt the entire hard drive.

  • Thanks 1
Posted
As you've noticed, Windows 7 doesn't support Bitlocker with PIN alone when there's no TPM. That functionality came with Windows 8. For Windows 7, Veracrypt is probably the best solution.
  • Thanks 1
Posted
Yes, completely understandable, but not very helpful. We certainly don't have the budget to replace them all, which I why we are looking at Veracrypt. It's free and can encrypt the entire hard drive.
What Windows licensing model are you on? If you have EES/OVS you could try Windows 10 which would allow you run Bitlocker without TPM.
  • Thanks 1
Posted
What Windows licensing model are you on? If you have EES/OVS you could try Windows 10 which would allow you run Bitlocker without TPM.

 

Lol did I mention how old they were. Something a know I didn’t mention however is they are Samsung and another (whose name escapes me right now) netbooks. Some only have 1gb ram in. 7 barely functions on them. On the other named netbooks windows 7 does not activate automatically. Something to do with the hardware and the volume license not being compatible if my memory serves me right. My boss at the time thought cheap cheap bought them from pc world and dumped 30 of them on my desk saying hand them out. Of course After putting a lite image on them all I notice none were activated and therefore had to call ms activation for each one. I was young and naive to think that things wouldn’t be that easy. This was the only method that worked. That was as I recall the Worst day of my life

TBF I did try win 10 (on one this time) as I too thought why not try with very little confidence that they would function and I was right. The unnamed didn’t even install and the Samsung bsod with no drivers available to use. I wasn’t prepared to waste any more time and resorted to this post for alternative suggestions [emoji23][emoji848]

Posted

not sure how this is a GDPR question as such. There's no mention of access to personal data or even the school network.

 

"I really do not know how much staff use them and whether they use them for "work" purposes. " ?? Surely this needs to be known and risk assessed before thinking about any actions.

Posted
not sure how this is a GDPR question as such. There's no mention of access to personal data or even the school network.

 

"I really do not know how much staff use them and whether they use them for "work" purposes. " ?? Surely this needs to be known and risk assessed before thinking about any actions.

 

the risk assessment is somewhat detailed or can be derived from my original post. Let recap what we know so far

 

1- The school bought the laptops so we are responsible and liable.

2- They were given to staff. It is highly likely that staff will use the laptops for work related material

3- it is likely that the work related material would contain sensitive information

 

Therefore it is a valid GDPR query

Posted (edited)
You can use a password on bitlocker without a TPM, I would strongly, massively advise against using USB; we need to be moving away from that entirely rather than going back to it.

https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/

I've set up hoards of machines in this way.

 

Yeah iv done all that but when I come to turn on bitlocker it only offers the option of startup key

I agree I would very much like not to use usb if I can help it

 

The other two options are greyed out

IMG_1515747282.331150.jpg

Edited by dapaulio
Posted

Argh, I may have to retract that after remoting in to the relevant schools and realising they were all either windows 8 or 10... my apologies! :(

 

We do use Veracrypt in another school of ours as we used Truecrypt prior to it going belly up.

  • Thanks 1
Posted

Yeah that was my understanding from 8 onwards you can use a pin.

I was hoping I was wrong.

Looks like a USB key it is or veracrypt

Never mind thanks for looking

Posted
The advent 4211c just remembered.

 

I've put W8.1 on these successfully. Student use, so didn't Bitlocker them - but I can't imagine it wouldn't work as long as you've set the appropriate Group Policy. I'd test, but kinda busy today.

 

They don't run fast, but IIRC 8.1 was better than 7. Of course, if you could afford extra RAM/SSDs it would help.

  • Thanks 1
Posted

A lot of our staff laptops do not have TPM chips.

 

We dont user a PIN or a USB stick.

 

We encrypt them with BitLocker and use a password - you have to set a security policy (if I remember correctly) to enable this option and each Teacher that doesnt have a TPM chip in their laptop uses this method. So far no problems! As we integrate it with AD when we have had to remove a HDD from a laptop to recover data etc. we just put in the recovery key and then we can access it!

 

All good so far.

  • Thanks 1
Posted (edited)

Just started setting this up. Not sure what the best approach for setting the passwords is?

 

Do you let the teacher set it the same as thier login so its easier for them to remember? (would this leave the encryption vulnerable in any way?)

Or do you require them to learn an additional password?

 

Obviously the most secure approach is, unique complex password for each laptop, what are your experiences?

 

Edit: Is the AD intergration just for recovering the key, or can you set it up to use the users domain password?

Edited by ollyyllo
Posted

As a left field alternative, I've been testing the Porteus Linux distro. It's designed as a kiosk mode and boots to either Chrome or Firefox. There are a few config options on first boot. On some old Samsung netbooks I had it power on to Chrome homepage in 8 seconds! OS is less than 80MB and once booted the whole thing runs in RAM. Default setting is no saving to local or USB storage. Complete system reset on power off or sleep.

 

Get them to use a school Google Suite or O365 account to save work if they need to.

 

http://www.porteus.org

Posted
As a left field alternative, I've been testing the Porteus Linux distro. It's designed as a kiosk mode and boots to either Chrome or Firefox. There are a few config options on first boot. On some old Samsung netbooks I had it power on to Chrome homepage in 8 seconds! OS is less than 80MB and once booted the whole thing runs in RAM. Default setting is no saving to local or USB storage. Complete system reset on power off or sleep.

 

Get them to use a school Google Suite or O365 account to save work if they need to.

 

Home - Porteus - Portable Linux

 

I tried to get one of my schools to use that as it was pretty easy to set up. No takers :(. Might mention it again now they are using Google more.

Posted
the risk assessment is somewhat detailed or can be derived from my original post. Let recap what we know so far

 

1- The school bought the laptops so we are responsible and liable.

2- They were given to staff. It is highly likely that staff will use the laptops for work related material

3- it is likely that the work related material would contain sensitive information

 

Therefore it is a valid GDPR query

 

The push for encryption on systems with personal data is not something new with GDPR.

 

Is it likely/high likely that the school might have been operating in breach of the Data Protection Act?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...