Jump to content

Recommended Posts

Posted

Hi All

 

Right, I'm looking to get a new stock of USB Pen Drives in school (as I've run out of spare ones now) and I know that encrypted is probably the best way to go, given you can tell staff members not to store pupil data on non-secure devices, but they still will, so I thought, encrypted drives then they have to.

 

Now, preferably looking at Hardward Encrypted Drives, but the problem (as we all know) is passwords, therefore I'm wondering what thoughts are for and against encrypted drives, and whether people know of any decent managed systems for encrypted drives, which obviously have their perks.

 

Personally, I have nothing against saying:

 

Here is your new pen drive, it is encrypted to protect any student data you may carry on it. Ensure you only use it for school use. I have set you password as being ..... and will keep a note of this. Should you change this password and then forget it, the only way to make the stick useable again is to format it, meaning you will lose any data on this drive.

 

Sign here to accept ...

 

(obviously with a bit better wording in there, but you get the jist).

 

Anyway, thoughts, ideas, suggestions are all welcome.

 

No, where did I put my liquid sun protector.. :rain:

Posted
Check the Mac-compatibility of them - that's the sticking point we keep finding here. Otherwise, probably a good idea as it takes all the hassle out of encrypting the drives, so staff don't even realise they're doing it.
  • Thanks 1
Posted

truecrypt or jcrypt are possible options but then you have to set the usb memory devices ( sticks ) up with the said encryption software and I think truecrypt can have the option of making a recovery disk or recovery option of some description so if they do lose there originally set password then you can recover from that but not sure how password changes would be done or dealt with as far as recovery options go

 

you could how ever put a thing in the sign here bit to state that they ensure that they keep a copy of there work in there home area so if it does for whatever reason vanish from the memory stick ie

 

forgot password, memory stick dies or w/e then they at least have something to fall back on

  • Thanks 1
Posted (edited)

We have encrypted sticks here, 2 class teachers tried to swap data, plugged both sticks in and managed to lose all data on both the sticks... I have had people forget there passwords so have made a word document with passwords on (with teachers permission) and stored it on my encrypted stick.

We looked at trucrypt and freeware but went for preinstalled 0 footprint 256 aes encryption blah blah...

 

Other than the mishap with plugging 2 sticks in no complaints work well and data is safe. :)

 

http://www.misco.co.uk/applications/SearchTools/item-details.asp?EdpNo=363418&CatId=3327

 

also note these are not mac compatible, I havnt tested the outcomes myself nor have I checked them with linux but if people want me to test I can do... :)

Edited by neon
  • Thanks 1
Guest theeldergeek
Posted (edited)

Anyway, thoughts, ideas, suggestions are all welcome.

 

ROHOS is the simplest encryption software I have come across. Also allows the drive to have an unencrypted partition as well as a hidden, encrypted partition. The latter is of course password protected.

 

I store things like WEP keys, software licence keys etc in the encrypted partition, and then everyday stuff I might use is visible in the open partition.

 

This might confuse some, but for anyone with some savvy, it is dead easy to use. The only problem I could see happening, is that it requires a little .exe to be held on the USB drive so the hidden data can be accessed on a PC not running ROHOS. If the .exe is deleted, it will obviously cause problems!

 

And it's freeware - http://www.rohos.com/

Edited by theeldergeek
added URL
Posted
ROHOS is the simplest encryption software I have come across. Also allows the drive to have an unencrypted partition as well as a hidden, encrypted partition. The latter is of course password protected.

 

And it's freeware - Rohos Featured product

 

Free is always good, but I'm also warey of self encryption, but I'll take a look .. I think if I go for it then it will have to be AES and then the staff don't have the option of not encrypting, it's just the management of it and ensuring that I have copies of passwords and the like.

Posted
Why do you need to ensure you have copies of everyone's passwords? Surely the responsibility should lie with the teacher to ensure they have backup copies of any files on their pen drives anyway in case they lose or break the drive.
Posted
Why do you need to ensure you have copies of everyone's passwords? Surely the responsibility should lie with the teacher to ensure they have backup copies of any files on their pen drives anyway in case they lose or break the drive.

 

It does, but I like to be nice occasionally .. and it would be a sticking point if I was to simply say 'forget your password you lose your stuff' though, I guess they'd only do it once.

 

But, this is why I'm interested in the managed options out there, as then I wouldn't have to know their passwords, but (from my understanding) could reset their password if they brought the drive to me, instead of just resetting the drive.

 

:cool:

Posted

Windows 7 Enterprise and Ultimate both contain BitLocker2Go which can be managed via Active Directory.

 

If the drive is used on a non-7 box it is read only (after entering the password) but I'm not 100% on Mac/*nix compatibility.

Posted
As you say, Bitlocker2Go is read-only on non-7 computers, putting it up there with the inflatable dart board...

 

It depends on your use of the device. If all your staff have a Windows 7 laptop, they will all be able to write to the devices (of course the device is less necessary but that's a different story). It is of course a 'con' for the solution. The 'pro' being that AD manages it all for you. The OP asked for pros and cons.

 

Personally, I think USB storage devices are evil and allow far too much, potentially sensitive, data to be moved around too easily. There's plenty of solutions that negate their use nowadays.

Posted

If all my staff had and used their own laptops, I would question the need for USB drives at all?!

 

I wonder how many of us are in schools with sufficient money for all staff to have Win7 laptops too.

Posted
What about biometric drives

 

£165 for a 256MB pen drive?! Not a chance!

 

Staff would not be able to fit everything on the drive, so would also use their own unencrypted one, and would likely soon enough get sick of using two, so would keep everything - sensitive or otherwise - on the one drive, and the school would have wasted thousands of pounds.

Posted

BitLocker would be nice, if we could afford Windows 7 machines - I'm struggling to get the money to get some new ram for older laptops to stop the staff winging inbetween upgrade programs. lol.

 

BioMetric - Trust Me, some staff would manage to not work that here ..

 

I'm thinking that I might go down the AES route with a "this is your password - keep it safe, if you change it, keep that safe, if you don't all I can do is reset your drive and you will lose anything you haven't backed up" and get them to sign an agreement on it.

 

:cool:

Posted
I'm thinking that I might go down the AES route with a "this is your password - keep it safe, if you change it, keep that safe, if you don't all I can do is reset your drive and you will lose anything you haven't backed up" and get them to sign an agreement on it.

Approval from On High permitting, I think that is going to be my response, too...

Posted
Approval from On High permitting, I think that is going to be my response, too...

 

Well, up high seem to approve of and trust me here, so I'm sure with a bit of explaining they will allow it! for me!

 

:cool:

Posted
Well, up high seem to approve of and trust me here, so I'm sure with a bit of explaining they will allow it! for me!

 

Similar here. I have concerns, which they will no doubt share, about insisting people use a solution which we then won't support, but the price difference between that and a managed solution might just tip the balance.

 

One could potentially argue that we don't force people to use pen drives, merely insist that they encrypt them if they do. Not sure that would fly though!

Posted
Any reason the software on those Integral drives can't be used on any drive? I would, if at all possible, like to avoid having to buy every staff member a pen drive...
Posted

Has anyone come accross this Safestick encrypted usb stick (SafeStick Encrypted USB Stick) apparently it has the option to use a web based console (SafeStick Management console SafeConsole) for management that can also be linked to active directory.

 

I am just starting to research encrypted memory sticks, my main issue with the software based systems is that you can't use them on computers that have been locked down. They may be alright for use in house where the software has already been preinstalled, but take them to another school that haven't and you are out of luck.

 

What I haven't found out yet is if the hardware encrypted sticks require software to be installed aswell or is it just a case of an executable file on the drive being run each time the drive is used. If the latter I assume it will also have problems being used on computers that have had autorun disabled and restricted to stop exe files being run from unauthorised locations such as removable drives.

Posted

Yeah, I'm looking at the Intergral Crypto Drives.

 

And HT in a meeting, I always seem to go up at the wrong time, or she has a sensor that says "Andy wants to spend some money .. I'll just ignore him" lol ..

Posted
Any reason the software on those Integral drives can't be used on any drive? I would, if at all possible, like to avoid having to buy every staff member a pen drive...

 

Hardware encrytion is built into the device. The software is just a means to access it and wouldn't be supported on regular sticks.

Posted
What I haven't found out yet is if the hardware encrypted sticks require software to be installed aswell or is it just a case of an executable file on the drive being run each time the drive is used. If the latter I assume it will also have problems being used on computers that have had autorun disabled and restricted to stop exe files being run from unauthorised locations such as removable drives.

 

They usually mount a virtual CD drive. If autorun is disable you can still navigate to the drive to run the required software provided you haven't set other policies.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...