Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Encryption for the masses
Kelly Martin, 2006-03-21

File and disk encryption needs to be simple and easy if it's going to be used. This article looks at Apple's FileVault and takes a sneak peak at what's coming in Windows Vista.

Comments Mode:
Encryption for the masses 2006-03-22
Anonymous
Encryption for the masses 2006-03-22
Scott Ramsdell (3 replies)
Windows does have the ability to encrypt your home folder, you simply enable EFS on your home folder. It's that easy.

Encrypting a drive offers no security when someone has physical access to the machine. Why? Because the encryption key itself cannot be encrypted, it has to be on the disk somewhere in clear text.

In a corporate environment, Microsoft has solved this issue by allowing you to export the local encryption key to a 2003 Certificate Server.

On a stand alone machine, Windows or OS X, it is trivial to gain admin access if you have physical access to the machine. Once you have admin access, you can access the encryption key and decrypt whatever you want.

Vista and any other operating system that encrypts an entire volume using a unique key that is embedded on a chip soldered to a mother board is missing a very important point: what happens when the board fries?

Back to the corporate world again, I'll have a clear text backup of the data (which will be encrypted by the backup process). But for the masses of home users, alas, you'll be out of luck.

Encyption is being sold to the masses as something it isn't. It cannot solve the problem of you needed to secure your laptop, and if you are unwilling to secure your laptop, you should not put sensitive information on it.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/393/33360#33360
Re: Encryption for the masses 2006-03-22
William
Re: Encryption for the masses 2006-03-23
Anonymous (2 replies)
Re: Encryption for the masses 2006-03-23
J (1 replies)
Re: Re: Encryption for the masses 2006-03-25
Anonymous
Encryption for the masses 2006-03-24
Anonymous
One problem with EFS 2006-03-28
Anonymous (1 replies)
Re: One problem with EFS 2006-03-28
Anonymous
Encryption for the masses 2006-04-16
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus