gshaw Posted February 7, 2011 Posted February 7, 2011 Just wondering if anyone has used BitLocker on staff-issued laptops? We're going to encrypt all of ours and just ordered some cheap USB sticks to hold the encryption key as I somehow doubt they have TPM onboard Would be interested to know how much of a hit it has on performance and if there's any compatibility issues anyone's encountered?
teejay Posted February 7, 2011 Posted February 7, 2011 Works very well apart from staff losing the USB keys:doh: Make sure you keep a copy of the backup key from the usb key and also check that the recovery key is being stored in active directory. You need to have some firm policies in place, such as not keeping the usb key in the laptop bag. Also, when (not if) a memeber of staff loses their usb key you really need to be re-encrypting the hard drive with a new encryption key. If they just break their key then just copy the encryption key onto a new usb stick.
gshaw Posted February 7, 2011 Author Posted February 7, 2011 These laptops aren't part of the domain (issued for home use and never see the network) so we're going to keep records of the keys for each laptop on record (file stored on the network and paper documentation). Yup we'll be making it part of the loan scheme that the USB key is never stored with the laptop, will try and get them to put the USB on their main keys when booking out to make sure
teejay Posted February 7, 2011 Posted February 7, 2011 How are they going to back up any work on them and how are you going to ensure the backup is encrypted?
gshaw Posted February 7, 2011 Author Posted February 7, 2011 Tbh I don't think many have ever been backed up but you make a good point about the use of USB sticks etc. Would be easy enough to control on network managed machines but not so sure about these ones. I think the next stage is encrypted USB sticks but haven't got those yet...
Killer_Bot Posted February 7, 2011 Posted February 7, 2011 Have the laptops already been partitioned accordingly, i.e. with the 1.5Gb system partition? If not then you're going to have to format as you may already know. Also, my understanding of BitLocker is that it will hit the performance but if the laptops aren't used for anything that rely on fast performance I can't see it being an issue. Could be worth looking into EFS for folder encryption if there's only a select few files that really need encrypting. Unless you're worried about the pagefile and whatnot.
gshaw Posted February 7, 2011 Author Posted February 7, 2011 Yup they need to be completely reformatted anyway, the plus point of doing it with BitLocker is that it doesn't rely on people storing files in the right place... anywhere on the HD will be encrypted... can't get much easier than that
Killer_Bot Posted February 7, 2011 Posted February 7, 2011 Yup they need to be completely reformatted anyway, the plus point of doing it with BitLocker is that it doesn't rely on people storing files in the right place... anywhere on the HD will be encrypted... can't get much easier than that That's true but on the other hand they don't have to rely on a USB to do any work at all, if they lose it on a weekend and can't see you for a day or two it's pretty much a brick in the meantime. It's one of those pros vs cons things isn't it. Ideally I'd love to BitLocker all our laptops here but I know without a doubt that USBs would be constantly lost or left with the laptop itself out of convenience. Either way it's a headache we could do without though I appreciate that sometimes you really do need this level of security.
sted Posted February 7, 2011 Posted February 7, 2011 isnt that why when installing win7 it leaves a blank partition so you dont need to do that?
teejay Posted February 7, 2011 Posted February 7, 2011 That's true but on the other hand they don't have to rely on a USB to do any work at all, if they lose it on a weekend and can't see you for a day or two it's pretty much a brick in the meantime. It's one of those pros vs cons things isn't it. Ideally I'd love to BitLocker all our laptops here but I know without a doubt that USBs would be constantly lost or left with the laptop itself out of convenience. Either way it's a headache we could do without though I appreciate that sometimes you really do need this level of security. It's an even bigger headache for the school when a laptop gets stolen and has confidential data in an unencrypted part of the drive, think it's up to a £500k fine now.
Arthur Posted February 7, 2011 Posted February 7, 2011 Isn't that why when installing win7 it leaves a blank partition so you don't need to do that? That's correct. In addition to BitLocker, the 100MB partition is also used for other things (it's not completely blank).
Killer_Bot Posted February 7, 2011 Posted February 7, 2011 It's an even bigger headache for the school when a laptop gets stolen and has confidential data in an unencrypted part of the drive, think it's up to a £500k fine now. Luckily that's not my decision to make, I just do as I'm told by my boss BitLocker is by no means fully secure either, especially if it's set for the USB keys. Granted, it's much more secure than an unencrypted drive but requires far more staff training RE things like storage, social engineering, passwords, etc. Just to be clear I'm not against BitLocker, I just don't think it's something to take on lightly when EFS and training with it can do almost the same thing.
gshaw Posted February 7, 2011 Author Posted February 7, 2011 (edited) That's correct. In addition to BitLocker, the 100MB partition is also used for other things (it's not completely blank). Isn't that 100MB partition hidden anyway? Tbh once we get our 2008 servers in the whole argument becomes moot anyway as it'll all be done via Terminal Services \ VDI so will only need an Internet connection and no files will be moving between locations. In the meantime it's really just a case of providing an additional computing resource with Office etc installed for staff that don't have dedicated PCs at home. As it stands I'd rather have them encrypted and take a few groans than the other option as mentioned above. Just considering if it's worth locking the USB ports as well, although that might push people over the edge Quick qu just thinking about it, if set to encrypt the boot drive am I right in thinking it won't auto encrypt USB sticks by default? Not sure I want it doing that until we've decided on a strategy there... Edited February 7, 2011 by gshaw
Killer_Bot Posted February 7, 2011 Posted February 7, 2011 It's another layer of protection so why not. As you say it's only temporary. Otherwise could a user not "accidentally" copy some contents onto there unencrypted stick? Not sure if it works like EFS where it unencrypts before copying? You could maybe set up BitLocker ToGo though and insist sticks be protected with that?
teejay Posted February 7, 2011 Posted February 7, 2011 Just considering if it's worth locking the USB ports as well, although that might push people over the edge They'll all be broken in a few weeks from having the usb encryption key rammed in the wrong way round anyway
gshaw Posted February 7, 2011 Author Posted February 7, 2011 Well the first few have to go out by Friday so I'll revisit the thread in a few months and report back how long they last Some interesting info comparing the pros and cons of EFS vs BitLocker here... Prevent data theft with Windows Vista's Encrypted File System (EFS) and BitLocker | TechRepublic That 1.5GB partition is only the little 100MB hidden one in 7 so not too worried about that
sted Posted February 7, 2011 Posted February 7, 2011 They'll all be broken in a few weeks from having the usb encryption key rammed in the wrong way round anyway along with the network and hdmi sockets as a minor point you do know bitlocker isnt in pro its only enterprise and ultimate
Killer_Bot Posted February 7, 2011 Posted February 7, 2011 They'll all be broken in a few weeks from having the usb encryption key rammed in the wrong way round anyway Not if they used these; Double USB concept ends your fear of USB plug rejection -- Engadget (Pretending they were actually a product right now and not a concept!)
gshaw Posted February 7, 2011 Author Posted February 7, 2011 along with the network and hdmi sockets as a minor point you do know bitlocker isnt in pro its only enterprise and ultimate Yup no issue here, Enterprise CALs rule all
sted Posted February 7, 2011 Posted February 7, 2011 Yup no issue here, Enterprise CALs rule all lucky you all my win7 is pro oem
gshaw Posted February 7, 2011 Author Posted February 7, 2011 (edited) Indeed, very glad we have Campus license here Would be ideal to use BitLocker to go to secure any transfers but our desktops are all XP so might still be an issue there, won't be for much longer though as I'm planning to move them to 7 in the next year or so. In the meantime a couple of encrypted USB sticks from Integral or suchlike will probably suffice to ease my paranoia along with this GPO... http://blogs.catapultsystems.com/IT/archive/2010/02/07/windows-7-restricting-and-securing-usb-storage-devices.aspx Edited February 7, 2011 by gshaw
Arthur Posted February 7, 2011 Posted February 7, 2011 Isn't that 100MB partition hidden anyway? It is hidden, but it also contains boot files for WinRE too... The 100 MB system partition is used primarily as BitLocker partition for BitLocker encryption. Additionally, it also holds the Windows Recovery Environment (WinRE) and boot files with boot manager for booting up the computer for troubleshooting when there is no Windows 7 installation DVD disc on hand. (Source) By the way, if you turn on BitLocker before joining a computer to your domain, you may want to read the following article to ensure the recovery keys get stored in AD... http://blogs.technet.com/b/askcore/archive/2010/04/06/how-to-backup-recovery-information-in-ad-after-bitlocker-is-turned-on-in-windows-7.aspx
gshaw Posted February 7, 2011 Author Posted February 7, 2011 Thanks for the link, another one saved to the Bookmark list! I'm in two minds about whether to join these machines to the domain as they'll never be connected to it. I guess for the first time sync of policies e.g. BitLocker and maybe USB device restriction it could be handy but apart from that I'm not sure if there's any benefit?
DannyG555 Posted February 10, 2011 Posted February 10, 2011 (edited) I've recently enabled BitLocker on some of our staff laptops. I thought this could only be enabled on machines that have TPM? I attempted enabling it on non-TPM laptops, and didn't get anywhere with it. What I found during going through the BitLocker setup wizard is that it creates the necessary partioning and information required. We're not currently implementing storing the recovery information in AD, so I simply stored the recovery key to a file on a protected network share. I'd be interested to know if you get anywhere enabling without the need for TPM We have added ours to the domain so they do get a policy. It was necessary for us to allow control over turning proxy settings on/off (the default for our workstations is that settings are locked) and adding a logon information box after the ctrl + alt + del screen to inform them of how to logon locally. Edited February 10, 2011 by DannyG555
teejay Posted February 10, 2011 Posted February 10, 2011 I've recently enabled BitLocker on some of our staff laptops. I thought this could only be enabled on machines that have TPM? I attempted enabling it on non-TPM laptops, and didn't get anywhere with it. What I found during going through the BitLocker setup wizard is that it creates the necessary partioning and information required. We're not currently implementing storing the recovery information in AD, so I simply stored the recovery key to a file on a protected network share. I'd be interested to know if you get anywhere enabling without the need for TPM You can disable the requirement for TPM through group policy.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now