dapaulio Posted January 11, 2018 Posted January 11, 2018 What are people's opinion on this situation. We have staff laptops in our inventory that have no TPM chip running Windows 7 ent. Really Really old. Personally nowadays I really do not know how much staff use them and whether they use them for "work" purposes. Recent laptops that I have bought with a TPM chip integrated are already encrypted so not an issue as far as GDPR goes However the no TPM chip laptops, I am planning on recalling all laptops to ensure that all laptops have Bitlocker enabled and force staff to boot with USB and Pin. This is something that I know how to facilitate but concerned that teachers will see the extra step as a burden and no longer use the laptops as an asset. Also slightly concerned about the impact it will have on my support when they inevitably break/lose the usb device. Again I know how to support if the case happens but being on my own just concerned of the impact it will cause on an already stretched IT support, implementing bitlocker on all Non compatible TPM devices and then supporting it when it goes wrong. What have you all done? am I over thinking it? do I need to do it? or should I be recalling all laptops without TPM?
synaesthesia Posted January 11, 2018 Posted January 11, 2018 You're doing the right thing but ignore the USB thing, just set them up to boot with a password. Have the password set to something that's not overly difficult, easy to remember or find out, and different per machine. Serial numbers, asset tags etc are some good resources to get those passwords from to help them avoid sticking a post it with the encryption password on it. 1
Ogdos Posted January 11, 2018 Posted January 11, 2018 As to the right thing to do it's up to the school. However, we are in a similar situation and our local IT support have suggested that they will not support us with implementing bitlocker on them as they feel it is not enough. (Although they offer no solution), We are instead looking at Veracrypt on them and replacing with laptops containing TPM as and when we get chance to replace. 1
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 We have staff laptops in our inventory that have no TPM chip running Windows 7 ent. Really Really old. Personally nowadays I really do not know how much staff use them and whether they use them for "work" purposes. Just to clarify. School issued laptops off the domain that staff use at home for personal/work use.
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 You're doing the right thing but ignore the USB thing, just set them up to boot with a password. Have the password set to something that's not overly difficult, easy to remember or find out, and different per machine. Serial numbers, asset tags etc are some good resources to get those passwords from to help them avoid sticking a post it with the encryption password on it. Whilst testing I have no other option but to use a usb. the pin option is grey out. the USB acts as the TPM chip and is required for devices with No TPM chip on the motherboard. I know I can set a HDD password but that is not encrypting the drive.
markwilfan Posted January 11, 2018 Posted January 11, 2018 Wouldn't a laptop with no tpm but offline file cache encrypted suffice. As long as people cannot save files outside their user area should you lose the laptop the files are secure 1
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 As to the right thing to do it's up to the school. However, we are in a similar situation and our local IT support have suggested that they will not support us with implementing bitlocker on them as they feel it is not enough. (Although they offer no solution), We are instead looking at Veracrypt on them and replacing with laptops containing TPM as and when we get chance to replace. I can understand their reluctance to advise as really the method is an option that would create a lot of work for something which is not directly supported. I can understand the easiest and more secure solution would be to recall and replace with TPM chipped laptops. something which schools do not have the budget to do. 1
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 Wouldn't a laptop with no tpm but offline file cache encrypted suffice. As long as people cannot save files outside their user area should you lose the laptop the files are secure the laptops are not domain joined. they were bought years ago (10years ago maybe) solely for the purpose to aid teachers who didn't have the facility to work on a computer at home were given a staff laptop. so happened that once they new they could get one they suddenly all wanted one
Ogdos Posted January 11, 2018 Posted January 11, 2018 I can understand their reluctance to advise as really the method is an option that would create a lot of work for something which is not directly supported. I can understand the easiest and more secure solution would be to recall and replace with TPM chipped laptops. something which schools do not have the budget to do. Yes, completely understandable, but not very helpful. We certainly don't have the budget to replace them all, which I why we are looking at Veracrypt. It's free and can encrypt the entire hard drive. 1
3s-gtech Posted January 11, 2018 Posted January 11, 2018 As you've noticed, Windows 7 doesn't support Bitlocker with PIN alone when there's no TPM. That functionality came with Windows 8. For Windows 7, Veracrypt is probably the best solution. 1
jmak Posted January 11, 2018 Posted January 11, 2018 Yes, completely understandable, but not very helpful. We certainly don't have the budget to replace them all, which I why we are looking at Veracrypt. It's free and can encrypt the entire hard drive.What Windows licensing model are you on? If you have EES/OVS you could try Windows 10 which would allow you run Bitlocker without TPM. 1
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 What Windows licensing model are you on? If you have EES/OVS you could try Windows 10 which would allow you run Bitlocker without TPM. Lol did I mention how old they were. Something a know I didn’t mention however is they are Samsung and another (whose name escapes me right now) netbooks. Some only have 1gb ram in. 7 barely functions on them. On the other named netbooks windows 7 does not activate automatically. Something to do with the hardware and the volume license not being compatible if my memory serves me right. My boss at the time thought cheap cheap bought them from pc world and dumped 30 of them on my desk saying hand them out. Of course After putting a lite image on them all I notice none were activated and therefore had to call ms activation for each one. I was young and naive to think that things wouldn’t be that easy. This was the only method that worked. That was as I recall the Worst day of my life TBF I did try win 10 (on one this time) as I too thought why not try with very little confidence that they would function and I was right. The unnamed didn’t even install and the Samsung bsod with no drivers available to use. I wasn’t prepared to waste any more time and resorted to this post for alternative suggestions [emoji23][emoji848]
dapaulio Posted January 11, 2018 Author Posted January 11, 2018 The advent 4211c just remembered. The head of it bought them for like £150 each. Are they still classed as a bargain if they were sh!t [emoji57]
jdoyle Posted January 11, 2018 Posted January 11, 2018 not sure how this is a GDPR question as such. There's no mention of access to personal data or even the school network. "I really do not know how much staff use them and whether they use them for "work" purposes. " ?? Surely this needs to be known and risk assessed before thinking about any actions.
dapaulio Posted January 12, 2018 Author Posted January 12, 2018 not sure how this is a GDPR question as such. There's no mention of access to personal data or even the school network. "I really do not know how much staff use them and whether they use them for "work" purposes. " ?? Surely this needs to be known and risk assessed before thinking about any actions. the risk assessment is somewhat detailed or can be derived from my original post. Let recap what we know so far 1- The school bought the laptops so we are responsible and liable. 2- They were given to staff. It is highly likely that staff will use the laptops for work related material 3- it is likely that the work related material would contain sensitive information Therefore it is a valid GDPR query
synaesthesia Posted January 12, 2018 Posted January 12, 2018 You can use a password on bitlocker without a TPM, I would strongly, massively advise against using USB; we need to be moving away from that entirely rather than going back to it. https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/ I've set up hoards of machines in this way. 2
dapaulio Posted January 12, 2018 Author Posted January 12, 2018 (edited) You can use a password on bitlocker without a TPM, I would strongly, massively advise against using USB; we need to be moving away from that entirely rather than going back to it. https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/ I've set up hoards of machines in this way. Yeah iv done all that but when I come to turn on bitlocker it only offers the option of startup key I agree I would very much like not to use usb if I can help it The other two options are greyed out Edited January 12, 2018 by dapaulio
synaesthesia Posted January 12, 2018 Posted January 12, 2018 Argh, I may have to retract that after remoting in to the relevant schools and realising they were all either windows 8 or 10... my apologies! We do use Veracrypt in another school of ours as we used Truecrypt prior to it going belly up. 1
dapaulio Posted January 12, 2018 Author Posted January 12, 2018 Yeah that was my understanding from 8 onwards you can use a pin. I was hoping I was wrong. Looks like a USB key it is or veracrypt Never mind thanks for looking
LeMarchand Posted January 12, 2018 Posted January 12, 2018 The advent 4211c just remembered. I've put W8.1 on these successfully. Student use, so didn't Bitlocker them - but I can't imagine it wouldn't work as long as you've set the appropriate Group Policy. I'd test, but kinda busy today. They don't run fast, but IIRC 8.1 was better than 7. Of course, if you could afford extra RAM/SSDs it would help. 1
Fazza Posted January 12, 2018 Posted January 12, 2018 A lot of our staff laptops do not have TPM chips. We dont user a PIN or a USB stick. We encrypt them with BitLocker and use a password - you have to set a security policy (if I remember correctly) to enable this option and each Teacher that doesnt have a TPM chip in their laptop uses this method. So far no problems! As we integrate it with AD when we have had to remove a HDD from a laptop to recover data etc. we just put in the recovery key and then we can access it! All good so far. 1
ollyyllo Posted January 12, 2018 Posted January 12, 2018 (edited) Just started setting this up. Not sure what the best approach for setting the passwords is? Do you let the teacher set it the same as thier login so its easier for them to remember? (would this leave the encryption vulnerable in any way?) Or do you require them to learn an additional password? Obviously the most secure approach is, unique complex password for each laptop, what are your experiences? Edit: Is the AD intergration just for recovering the key, or can you set it up to use the users domain password? Edited January 12, 2018 by ollyyllo
jmak Posted January 12, 2018 Posted January 12, 2018 As a left field alternative, I've been testing the Porteus Linux distro. It's designed as a kiosk mode and boots to either Chrome or Firefox. There are a few config options on first boot. On some old Samsung netbooks I had it power on to Chrome homepage in 8 seconds! OS is less than 80MB and once booted the whole thing runs in RAM. Default setting is no saving to local or USB storage. Complete system reset on power off or sleep. Get them to use a school Google Suite or O365 account to save work if they need to. http://www.porteus.org
LeMarchand Posted January 12, 2018 Posted January 12, 2018 As a left field alternative, I've been testing the Porteus Linux distro. It's designed as a kiosk mode and boots to either Chrome or Firefox. There are a few config options on first boot. On some old Samsung netbooks I had it power on to Chrome homepage in 8 seconds! OS is less than 80MB and once booted the whole thing runs in RAM. Default setting is no saving to local or USB storage. Complete system reset on power off or sleep. Get them to use a school Google Suite or O365 account to save work if they need to. Home - Porteus - Portable Linux I tried to get one of my schools to use that as it was pretty easy to set up. No takers . Might mention it again now they are using Google more.
jdoyle Posted January 13, 2018 Posted January 13, 2018 the risk assessment is somewhat detailed or can be derived from my original post. Let recap what we know so far 1- The school bought the laptops so we are responsible and liable. 2- They were given to staff. It is highly likely that staff will use the laptops for work related material 3- it is likely that the work related material would contain sensitive information Therefore it is a valid GDPR query The push for encryption on systems with personal data is not something new with GDPR. Is it likely/high likely that the school might have been operating in breach of the Data Protection Act?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now