Jump to content

Recommended Posts

Posted
Hi, if laptops need encrypting for GDPR, shouldn't they have been encrypted anyway? So if work needs dong in this regard, would I expect our IT suppliers to charge extra, or is this just part of the ongoing maintenance and upkeep?
Posted

Confused by the question but suppliers wouldn't have to encrypt as the devices being supplied don't have any personal data on them at that time. (just os and apps)

They would only have to encrypt if you asked them to as part of a service which they may charge for.

  • Thanks 1
Posted
Hi, if laptops need encrypting for GDPR, shouldn't they have been encrypted anyway?

 

If they have identifiable information on them then yes, you should have been encrypting them before GDPR came along. It's not a suppliers job to enable encryption on a computer, it's a Schools/Businesses responsibility to have a Policy on the matter that the IT Department then adhere to.

  • Thanks 1
Posted
OK. Just asking because our IT would encrypt at the end of the year since the tend to rebuild anyway. I suppose it's the unusual nature of the timing that makes the difference, as it's an unexpected extra job. This is another school in our MAT.
Posted

Most suppliers wouldn't do anything with the device, they would just ship it out. The manufacturer wouldn't know what purpose the device will be used for, so it may not require encryption as it wouldn't with just Windows and the bloatware they install by default. Most companies would also wipe the laptops when they receive them, which would remove the encryption anyway.

 

Unless you have a company that is placing a specific work image onto the laptop before shipping it out, I wouldn't expect it to be encrypted... but also... if they are encrypting it, they may also have the keys to unlocking it.

  • Thanks 1
Posted
Yes this is for a school so the staff laptops are imaged specifically for staff with the software they use. Software is then sometimes remotely deployed, but occasionally the laptops are reimaged. This is all part of the maintenance contract, but I suppose the sudden urge for encryption wasn't anticipated early enough.
Posted
Indeed if by "supplier" you mean the likes of Dell, HP then absolutely no, they would have no reason or interest in encryption prior to supplying products to you, especially as it's highly unlikely many schools run with the supplied operating system; imaging would wipe that all that. If you mean services supplier such as 3rd party IT support who would be responsible for imaging those laptops then yes, they would absolutely need to do that from the get-go and should have been doing anyway.
Posted

If you have right policies in place in active directory you don't need to re-image them you can set it to encrypt using bitlocker and save the recovery key in active directory. You can also get them to encrypt as part of the imaging process.

assuming you have tpm modules on laptops otherwise you have to use usb sticks as a sort of startup key.

Posted
i also personally wouldnt want laptops encrypted off site where bitlocker diddnt automatically back the key up to ad (not to mention other policies for instance that would mean the supplier knowing a pin code if you use one)
  • 2 weeks later...
Posted

Yeah, I think it's still new and slightly buggy, esp since it depends on bios/hardware too.

 

If it's tpm 2 it's pretty easy, but make sure you're fine with having to reimage if it fails, backup computer first. GPO to enable bitlocker stuff seemed to screw up Dell Vostro (wifi and touchpad failed if gpo was enabled), the encryption itself was fine though, so weird.

 

tpm 1.2 you have to enable in bios, so touch each machine or use per manuf. bios config stuff. Couple of HP desktops I did that on failed to boot after encrypting.

 

no tpm = password on boot, which has failed to work and left the computer pretty much unbootable most of the time I've tried it.

 

Overall it's better than anything else as it requires 0 for the user to do.

 

Don't think you can image encrypted, have to image, then encrypt.

 

Also look into SSDs that do OPEL so the SSD itself can encrypt, easier/faster

  • Thanks 1
Posted
Yeah, I think it's still new and slightly buggy, esp since it depends on bios/hardware too.

 

If it's tpm 2 it's pretty easy, but make sure you're fine with having to reimage if it fails, backup computer first. GPO to enable bitlocker stuff seemed to screw up Dell Vostro (wifi and touchpad failed if gpo was enabled), the encryption itself was fine though, so weird.

 

tpm 1.2 you have to enable in bios, so touch each machine or use per manuf. bios config stuff. Couple of HP desktops I did that on failed to boot after encrypting.

 

no tpm = password on boot, which has failed to work and left the computer pretty much unbootable most of the time I've tried it.

 

Overall it's better than anything else as it requires 0 for the user to do.

 

Don't think you can image encrypted, have to image, then encrypt.

 

Also look into SSDs that do OPEL so the SSD itself can encrypt, easier/faster

 

Laptops I am looking at encrypting are TPM 2. I've got a spare one here that I'm gonna experiment with. Just got a test OU and applying the group policies. It does have an SSD.... Kingston jobby... I'll check for OPEL!

Posted (edited)
Also look into SSDs that do OPEL so the SSD itself can encrypt, easier/faster

Do you mean TCG Opal? Opel is the car company. ;)

 

I recently tried enabling hardware-based encryption on a Samsung 960 EVO, but gave up. Windows kept wanting to use software-based encryption despite the PC meeting all of the requirements. The SSD had also been securely erased beforehand. :(

 

https://helgeklein.com/blog/2015/01/how-to-enable-bitlocker-hardware-encryption-with-ssd/

 

Annoyingly Samsung don't provide a tool to revert the PSID so I had to use SEDUtil.

Edited by Arthur
Posted
Yeah, I think it's still new and slightly buggy, esp since it depends on bios/hardware too.

If it's tpm 2 it's pretty easy, but make sure you're fine with having to reimage if it fails, backup computer first. GPO to enable bitlocker stuff seemed to screw up Dell Vostro (wifi and touchpad failed if gpo was enabled), the encryption itself was fine though, so weird.

tpm 1.2 you have to enable in bios, so touch each machine or use per manuf. bios config stuff. Couple of HP desktops I did that on failed to boot after encrypting.

no tpm = password on boot, which has failed to work and left the computer pretty much unbootable most of the time I've tried it.

Overall it's better than anything else as it requires 0 for the user to do.

Don't think you can image encrypted, have to image, then encrypt.

Also look into SSDs that do OPEL so the SSD itself can encrypt, easier/faster

 

not had any of those issues and most of my laptops dont have tpm if you set the policy correctly ive never had it screw up a machine (ive had it fail to encrypt because of conflicting policies but never fail)

if you have a tpm and image with mdt you can install it and as soon as mdt finishes the drive is encrypted

Posted

I have TPM and after encrypting it asked for the long key every time it booted. Just decrypting now. Gonna try again.... policies I have in place are:

 

Store BitLocker recover info in ADDS

Choose drive encryption method and cypher strength

 

Then in OS Drives:

Allow Secure Boot for integrity validation

Configure use of hardware-based encryption for OS drives

Choose how bitlocker OS drives can be recovered

configure TPM platform validation profile for BIOS based firmware configs.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...