dapaulio Posted January 15, 2018 Author Posted January 15, 2018 The push for encryption on systems with personal data is not something new with GDPR. Is it likely/high likely that the school might have been operating in breach of the Data Protection Act? Thanks for your input but Your not exactly contributing to this thread effectively. How about offering a suggestion rather than highlighting everything that is wrong. Let me know if you have any of your own ideas Thanks
dapaulio Posted January 15, 2018 Author Posted January 15, 2018 I've put W8.1 on these successfully. Student use, so didn't Bitlocker them - but I can't imagine it wouldn't work as long as you've set the appropriate Group Policy. I'd test, but kinda busy today. They don't run fast, but IIRC 8.1 was better than 7. Of course, if you could afford extra RAM/SSDs it would help. What license agreement do you have ? Did you have problems with activation on your models?
klop Posted January 15, 2018 Posted January 15, 2018 We use Bitlocker (though there may be some laptops still running truecrypt which we used before it ceased) We use an individual password for each laptop that the teacher chooses. Password must be min of 10 characters and contain lower & upper case, symbol and number(s) This password is different from their AD login. Staff have a little grumble at first, but I often help them come up with something memorable and it seems to have worked so far. I keep a log of all encryption passwords in case I need to use them. Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out! 2
LeMarchand Posted January 15, 2018 Posted January 15, 2018 What license agreement do you have ? Did you have problems with activation on your models? Open Value Sub *prays he hasn't been norty by upgrading* and no problems with activation. Like I said, not tried Bitlocker on them, but can't imagine it would be a problem. There tomorrow and will take a look if time. 1
LeMarchand Posted January 15, 2018 Posted January 15, 2018 Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out! Something like this:
Blue_Cookeh Posted January 15, 2018 Posted January 15, 2018 Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out! I hope they: 1. subsidise the cost of the laptop 2. don't expect staff or work at home 3. realise the cost of data getting exposed! 1
LeMarchand Posted January 16, 2018 Posted January 16, 2018 What license agreement do you have ? Did you have problems with activation on your models? Tested one a random 4211C on wireless but plugged in (batteries duff + losing will to get the stopwatch out again). Before BL: Off to Logon Screen 24s Logon Screen to Desktop, Student profile 22s Logon Screen to Desktop, My profile 50s After BL: Off to BL Password Screen 12s BL Password Screen to Logon Screen 24s Logon Screen to Desktop, Student profile 30s Logon Screen to Desktop, My profile 75s Logon Screen to Desktop seemed to vary a bit, put most common time. Obviously will also vary according to what's happening to your user profiles at logon. It *looks* like BL adds +14 seconds (in total) on that machine to get to the Logon Screen + a variable amount to the logon. Usage doesn't seem any different.
klop Posted January 16, 2018 Posted January 16, 2018 I hope they: 1. subsidise the cost of the laptop 2. don't expect staff or work at home 3. realise the cost of data getting exposed! 1. It appears not 2. It appears yes 3. No idea!
jdoyle Posted January 16, 2018 Posted January 16, 2018 Thanks for your input but Your not exactly contributing to this thread effectively. How about offering a suggestion rather than highlighting everything that is wrong. Let me know if you have any of your own ideas Thanks My suggestion would be to do a proper GDPR data audit etc (or drop the GDPR reference from the thread title; rephrase it as "Another Encryption question - ") You've had these systems out in the field for nigh on 10years without encryption and without any idea what was held on them. After the long overdue encryption is finally put in place, it sounds like you will still have no idea what personal data (if any) is on the systems. Good luck with the rest of your "GDPR" activities.
MrWrighty Posted January 19, 2018 Posted January 19, 2018 Have you considered DesLock from Eset. You do not need the TPM chip for this to work. You can encrypt at Disc/Folder/File level and even encrypt emails on an individual basis. Admin console is used to manage access on a per user basis.
MrWrighty Posted January 19, 2018 Posted January 19, 2018 (edited) We use Bitlocker (though there may be some laptops still running truecrypt which we used before it ceased) We use an individual password for each laptop that the teacher chooses. Password must be min of 10 characters and contain lower & upper case, symbol and number(s) This password is different from their AD login. Staff have a little grumble at first, but I often help them come up with something memorable and it seems to have worked so far. I keep a log of all encryption passwords in case I need to use them. Our new sponsors to be will not allow allow laptops to be taken from school - teachers must provide their own devices to work on anything at home. Waiting to see how that pans out! That is a huge security risk as you will have no call on how or what is on this laptops. Under GDPR you need better control of everything that could potentially carry sensitive data including Laptops/Mobiles/Tablets and USB/SD cards. The cost of not providing laptops might pale in to insignificance if you suffer a data breach. The same applies if you expect teachers to use their home computers, you cannot control what is saved to them, too risky by far. Edited January 19, 2018 by MrWrighty
ITGURU Posted June 21, 2018 Posted June 21, 2018 When using Passwords with bitlocker without TPM module, how do you choose a password. Do you set it for the user, or let the user choose their own? However, if a staff member uses their own password and they bring the laptop in for repair/updates, you would have to ask the user for their own password rather than there being ad admin over-ride or how would you get around this without the user needing to share their password?
Farloch Posted June 21, 2018 Posted June 21, 2018 the laptops are not domain joined. they were bought years ago (10years ago maybe) solely for the purpose to aid teachers who didn't have the facility to work on a computer at home were given a staff laptop. so happened that once they new they could get one they suddenly all wanted one Sounds like after 10 years they should be put out to pasture anyway. I'd recall them all, secure wipe them and dispose of the lot. If teachers don't have their own computer then they need to get their hands in their pockets and buy one. Its not the taxpayers responsibility to provide teachers with the basic tools to effectively work in their chosen profession. Every other trade has to buy their own tools, I've never understood why teachers think they are any different. At the end of the day teachers own personal devices are not your concern so I wouldn't lose any sleep over it.
dapaulio Posted June 24, 2018 Author Posted June 24, 2018 Sounds like after 10 years they should be put out to pasture anyway. I'd recall them all, secure wipe them and dispose of the lot. If teachers don't have their own computer then they need to get their hands in their pockets and buy one. Its not the taxpayers responsibility to provide teachers with the basic tools to effectively work in their chosen profession. Every other trade has to buy their own tools, I've never understood why teachers think they are any different. At the end of the day teachers own personal devices are not your concern so I wouldn't lose any sleep over it. Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12] I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds.
Blue_Cookeh Posted June 25, 2018 Posted June 25, 2018 Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12] I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds. You force SLT's hand by putting a rolling replacement plan in your policies so you don't have to deal with that crap
Farloch Posted June 25, 2018 Posted June 25, 2018 Have you ever worked in a school??? A school expects only to buy once and never have to renew ever. All equipment must live as long as the person it has been handed to. [emoji12][emoji12][emoji12] I have sent an email to all staff it concerns explaining that they can keep the laptop for what ever purposes they see fit but they aren’t allowed to have any school data on it. If they want to use it for school they must use rds. Yep 13 years in primary and secondary schools. (I should be up for parole soon ) Just explain that they are no longer serviceable and stop supporting them. If staff want to continue using them for personal use at home then let them. It gets them off your hands and saves you the hassle of having to properly dispose of them. You can't be responsible for what data staff decide to copy onto these (or any other) devices. Its beyond your control and staff have to take responsibility for the data they carry around and where they save it. You will never be able to police this whilst the use of portable storage devices is still permitted. Encryption of pen drives is a step in the right direction but it falls short of what is actually required to ensure data is secured.
JATSO Posted June 25, 2018 Posted June 25, 2018 Were running some Dell D530s 10 years old now, put in some SSD drives so they boot pretty quick, no TPM, use Bitlocker without TPM as per this article https://www.howtogeek.com/howto/6229/how-to-use-bitlocker-on-drives-without-tpm/ they require a password to boot. They run fine and its a easy step just putting a password in.
MrWrighty Posted July 2, 2018 Posted July 2, 2018 Eset Endpoint Encryption does not require a TPM chip to function. Will Encrypt, files/folders/laptops/emails etc.
sigma Posted July 2, 2018 Posted July 2, 2018 1. It appears not 2. It appears yes 3. No idea! Maybe this should be brought to the attention of the DPO?
leegcvcc Posted July 2, 2018 Posted July 2, 2018 Do you have a RDS server that they can use for work purposes? Can be all contained within there. Just a thought
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now