ayoward Posted January 21, 2010 Posted January 21, 2010 Hello Folks, I am wondering whether data encryption has appeared on any of your radars yet? I am aware that disk and data encryption are starting to become a requirement for local authorities and schools, but I am wondering just how much thought is being given to it. We have been asked by the members of the YHGfL Network Group to get an indicative price from Sophos for their encryption software SafeGuard Device Encryption coupled with Safeguard Management Centre and Safeguard Data Exchange to see if we can get a deal similar to the one we got for the Sophos AV stuff. I am curious however as to how many of our regions schools would be interested in such a deal. There is no point in us buying a load of licenses, even if it is at a fantastic deal if then none of the schools are bothered aboout buying it. Let me know if there is any appetite in your school. We are probably talking around £20 per license (perpetual) with £5 maintenance per annum for updates. Obviously the more schools that sign up, the cheaper this could get. Regards, Andrew
dhicks Posted January 21, 2010 Posted January 21, 2010 SafeGuard Device Encryption coupled with Safeguard Management Centre and Safeguard Data Exchange What does that do that, say, TruCrypt doesn't? -- David Hicks
AyatollahPies Posted January 21, 2010 Posted January 21, 2010 Hello Folks, I am wondering whether data encryption has appeared on any of your radars yet? I am aware that disk and data encryption are starting to become a requirement for local authorities and schools, but I am wondering just how much thought is being given to it. We have been asked by the members of the YHGfL Network Group to get an indicative price from Sophos for their encryption software SafeGuard Device Encryption coupled with Safeguard Management Centre and Safeguard Data Exchange to see if we can get a deal similar to the one we got for the Sophos AV stuff. I am curious however as to how many of our regions schools would be interested in such a deal. There is no point in us buying a load of licenses, even if it is at a fantastic deal if then none of the schools are bothered aboout buying it. Let me know if there is any appetite in your school. We are probably talking around £20 per license (perpetual) with £5 maintenance per annum for updates. Obviously the more schools that sign up, the cheaper this could get. Regards, Andrew Have you tested the product to see if it's usable in a school environment or are you just trying to get a feel for interest?
ayoward Posted January 21, 2010 Author Posted January 21, 2010 What does that do that, say, TruCrypt doesn't? -- David Hicks I have no idea. I'm not familiar with what the TruCrypt product does or doesn't do. I have seen the Sophos product in action however. It is purely because we have an existing bulk purchase arrangement with Sophos that we have been asked to approach them to get a similar cheap deal. The AV deal was ridiculously cheap, so we've been given a pretty good deal on this as well I think. Andrew
ayoward Posted January 21, 2010 Author Posted January 21, 2010 Have you tested the product to see if it's usable in a school environment or are you just trying to get a feel for interest? I have seen a demo of the product and I don't see a reason why it wouldn't work in a school environemnt. You would need to make a decision I feel in terms of which machines you would want to protect with this kind of thing. Would you purely protect laptops and any removable data or media, would you encrypt the disks of all your computers in school, or just the admin machines? But in answer to the second part of your question, I am trying to get a feel for interest. We have a deal from Sophos that lasts until end of March, after that it almost doubles in price, so if we wanted it at these prices, we would have to act fast, but I wouldn't want spend the money, no matter how good a deal it is if no one wants it. Andrew
dblight Posted January 21, 2010 Posted January 21, 2010 We are using Windows Bitlocker now on all laptops. It works great. We purchased a load of USB keys and customised them with the school logo etc etc and now all the laptops have been rebuilt and encrypted. The member of staff just simply inserts the USB key on boot and then removes it and the laptop boots. We had to change the local group policy to allow bitlocker to use a USB key rather than look for a TPM chip each time but if a laptop has TPM obviously we use that. You can only use Bitlocker on Windows Vista Enterprise/Ultimate and Windows 7 Enterprise/Ultimate. We have a large Microsoft Schools Agreement so we could have Enterprise Editions. Hope this helps Darren
john Posted January 21, 2010 Posted January 21, 2010 I wouldn't trust Sophos with my data encryption, it seems in my experience to be missing viruses again at work or being slow on detection, so would be concerned about having that, plus its more eggs in one basket. I am using and rolling out Truecrypt to all my staff Laptops, nearly done them all now, and its working great.
evil-tom Posted January 21, 2010 Posted January 21, 2010 Encryption is certainly on my radar. I've had to implement it on around 100 laptops, both PCs and Macs. A Government agency paid. Trucrypt was a no-go for them - as it wasn't on "the list" of approved products. Only PGP Enterprise fitted our cross platform needs that met with their requirements. Having a central keyserver with the ability to issue recovery tokens for when they forget them is cool! Integrates with a AD, eDir, LDAP too. T
dhicks Posted January 21, 2010 Posted January 21, 2010 (edited) I have no idea. I'm not familiar with what the TruCrypt product does or doesn't do. It encrypts whole volumes (harddrives). It, and other similar systems, are free: TrueCrypt - Free Open-Source On-The-Fly Disk Encryption Software for Windows 7/Vista/XP, Mac OS X and Linux TrueCrypt's Wikipedia page is good for a quick summary, and the "see also" section is probably a good place to start looking for other similar systems (both free and paid-for, like PGP as mentioned above) for comparison: [ame=http://en.wikipedia.org/wiki/TrueCrypt]TrueCrypt - Wikipedia, the free encyclopedia[/ame] -- David Hicks Edited January 22, 2010 by dhicks
PiqueABoo Posted January 21, 2010 Posted January 21, 2010 What does that do that, say, TruCrypt doesn't? Well it used the word: "Management". With TrueCrypt you have to be very organised e.g. keep initial recovery ISOs to ensure IT folk can get access to some encrypted drive after the user has changed the password to suit themselves etc. One assumes these products help with that side of things.
evil-tom Posted January 22, 2010 Posted January 22, 2010 Management was the big issue for us. Having a multi-platform solution where the same individual users' credentials can be used for multiple machines - including a hardware token that I can use to gain access to locked drives. It's really the way to doing the job properly when you can't trust people to remember the same number of different passwords that you do. It has already saved our bacon when a laptop was left at an airport.
evil-tom Posted January 22, 2010 Posted January 22, 2010 Feel free to contact me about the issues with data encryption in a mixed platform environment. I don't run a standard ship (no Windows servers for example), and management gave us 8 days to implement a solution. Tom
Marci Posted January 25, 2010 Posted January 25, 2010 Let me know if there is any appetite in your school. We are probably talking around £20 per license (perpetual) with £5 maintenance per annum for updates. Obviously the more schools that sign up, the cheaper this could get. Licensed per site, or per client?
steve Posted January 26, 2010 Posted January 26, 2010 Might be interested for our laptops - we already encrypt them but I'm not overwhelmed by the software we use.
russdev Posted January 26, 2010 Posted January 26, 2010 Yes has been for about 12 months (I am on the LA working party). Few things True Crypt is good for whole disk backup such as laptops. As a memory stick solution I think it is very complicated and staff would not use them. Hence why for memory sticks we are looking for better solution (hardware based encryption was idea until someone broke it so need to look into it bit more). But key issue here is finding a solution that works both on MACS and Windows. But anyway feel free to give me a buzz if want to discuss it more. Russ
MatthewL Posted January 26, 2010 Posted January 26, 2010 We currently use McAffee Endpoint Encryption (Safeboot) if anyone has any queries, we were forced to use this (NHS agreement). It's good at its job and most of the problems have been solved. I would be interested in TrueCrypt (am I right in believing this is the free download one) for use on my netbook possibly.
dhicks Posted January 26, 2010 Posted January 26, 2010 As a memory stick solution I think it is very complicated and staff would not use them. I think that's the area to spend money in - getting rid of the need for teachers and other staff to carry around external storage devices and laptops with locally-kept copies of files in the first place. -- David Hicks
john Posted January 26, 2010 Posted January 26, 2010 I would be interested in TrueCrypt (am I right in believing this is the free download one) for use on my netbook possibly. Yes it is the free one, I use it with good success
enjay Posted January 27, 2010 Posted January 27, 2010 I think that's the area to spend money in - getting rid of the need for teachers and other staff to carry around external storage devices and laptops with locally-kept copies of files in the first place. I've wondered about that, when it was suggested that we should buy all teachers hardware-encrypted drives - I thought, hmm, a decent remote access system would be cheaper... I suspect that people are now so engrained in the use of pen drives that it would be an impossible battle to win, however sensible it is.
ayoward Posted January 27, 2010 Author Posted January 27, 2010 I've wondered about that, when it was suggested that we should buy all teachers hardware-encrypted drives - I thought, hmm, a decent remote access system would be cheaper... I suspect that people are now so engrained in the use of pen drives that it would be an impossible battle to win, however sensible it is. Now it's interesting that you should say that. I have been having the exact same thoughts, and to that end, we are now going to be developing a low cost VPN solution that uses Cisco IPSEC VPN tunnelling secured by two factor authentication with a one time password. We already have a solution in place which is used by IT Technicians really and a few teachers which is secured by CRYPTOCard 2FA tokens, but when the tokens are £30 a pop, they will never be rolled out to the whole teaching staff in a school as you would be looking at a £3K outlay. So we are looking at SMS one time passwords, your mobile phone then becomes one facter and your memeorised PIN becomes the other factor in 2FA. My logic is if you have a secure tunnel into the school, the data will never need to leave school and you don't have to worry about encryption. If we get the security right, it could be rolled out to parents and even students for access to various bit of reporting and RDP to desktop for use of specialised software. Watch this space.
PiqueABoo Posted January 27, 2010 Posted January 27, 2010 the data will never need to leave school I'd still fully encrypt laptops, but that approach definitely has my sympathy and also because it helps with another risk i.e. the data might get backed up if it's still at the school. I work like that a lot and the issues for me (which may depend on how you configure it): * I'm exclusively on the Cisco VPN network i.e. it messes with the local routing tables so I can't send something to a printer on my local network. * Similarly I can't fire up a local browser to go check someting on the net (unless I'm RDPd into a box). For me this turns out to be quite a pain, so I often have Laptop-on-VPN and home PC-not-on-VPN going at the same time. * RDP works fine then just freezes sometimes... could be anything between me on contended 10Mb ISP link typically talking to a target on 100Mb. As ever, you do have to think about bandwidth and bottlenecks at various times and places.
ayoward Posted January 27, 2010 Author Posted January 27, 2010 I work like that a lot and the issues for me (which may depend on how you configure it): * I'm exclusively on the Cisco VPN network i.e. it messes with the local routing tables so I can't send something to a printer on my local network. * Similarly I can't fire up a local browser to go check someting on the net (unless I'm RDPd into a box). For me this turns out to be quite a pain, so I often have Laptop-on-VPN and home PC-not-on-VPN going at the same time. What you need is split tunnelling. If you get it right, you should be able to do what ever you like on your local network and only the stuff that needs to will go down the VPN. What you would need to be careful of in that situation though is that you need to be sure that your local network is clean and patched so you can't inroduce something inadvertently to your VPN network. You will have the "Tunnel Everything" switched on on your VPN concentrator. Let me know if you need any pointers as to what you will need to change if you don't already know.
SpuffMonkey Posted January 27, 2010 Posted January 27, 2010 I think that's the area to spend money in - getting rid of the need for teachers and other staff to carry around external storage devices and laptops with locally-kept copies of files in the first place. -- David Hicks Yeah - we put in an outward facing Citrix solution - so that staff can work from home pretty much as if they were at their PC in school - which seems to work well - as they can do their reports etc when they feel like it and there are no problems with backups/incompatible software etc - the only probs are with people out in the sticks who can't get a relatively decent bb connection
Marci Posted February 5, 2010 Posted February 5, 2010 Last time I looked at truecrypt, it required users to have administrative access to be able to work with encrypted content... has this changed of late? We've been using AxCrypt where required, which allows stuff to be encrypted using a key file which we host on internal server shares which are restricted departmentally. All staff then use either a central or departmental keyfile, to prevent "forgotten my key..." issues.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now