-
March 8th, 2005, 01:53 PM
#1
Registered User
Securing files on a computer
My boss wants to have some sort of setup in place on his new WinXP laptop where he can put files in a location and have them encrypted. Company secrets and the like.
He does not want to secure the entire laptop. Other people may need to use the laptop with admin privileges while he is out of the office. So we cannot use WinXP user permissions or a boot password.
Free or cheap is good, too. Any suggestions on how to go about this?
Thank you!
-
March 8th, 2005, 02:33 PM
#2
Registered User
Is an encypted thumb drive an option.You know the ones with finger print scanners?
Whichever route choosen hes going to have problems with the risk of secure data being accesed via the temp files if others use the system.
The other option that comes to mind is an encrypted drive like that provided by PGP.
-
March 8th, 2005, 03:08 PM
#3
Chat Operator
Originally Posted by MacGyver
My boss wants to have some sort of setup in place on his new WinXP laptop where he can put files in a location and have them encrypted. Company secrets and the like.
He does not want to secure the entire laptop. Other people may need to use the laptop with admin privileges while he is out of the office. So we cannot use WinXP user permissions or a boot password.
Free or cheap is good, too. Any suggestions on how to go about this?
Thank you!
Use the XP encryption. Will lock it to his user account, regardless of permissions.
I guess if someone where to use admin access, reset his password then logon.. but if they don't know that, it's ok. The other option is to use a zip file with password option, should keep people out.
<Ferrit> Take 1 live chicken, cut the head off, dance around doing the hokey pokey and chanting: GO AWAY BAD VIRUS, GO AWAY BAD VIRUS
-----------------------
Windows 7 Pro x64
Asus P5QL Deluxe
Intel Q6600
nVidia 8800 GTS 320
6 gigs of Ram
2x60 gig OCZ Vertex SSD (raid 0)
WD Black 750 gig
Antec Tri power 750 Watt PSU
Lots of fans
-
March 8th, 2005, 03:42 PM
#4
Registered User
If the files are so important maybe they shouldn't be stored on the PC in the first place... Set a network share with permissions for him only. If they are so important they have to be backed up anyway.
Protected by Glock. Don't mess with me!
-
March 9th, 2005, 07:36 AM
#5
Registered User
Network share won't suffice because he wants to guarantee only he can see the files (I'm the network admin and I can see everything) and he also wants to take the files with him.
I'll consider the WinXP encryption, but I think the encrypted USB drive is going to be the best option.
-
March 9th, 2005, 08:13 AM
#6
Banned
Originally Posted by MacGyver
Network share won't suffice because he wants to guarantee only he can see the files (I'm the network admin and I can see everything) and he also wants to take the files with him.
I'll consider the WinXP encryption, but I think the encrypted USB drive is going to be the best option.
I've tried the XP encryption before; it tends to lock up the computer when you try to access file within an encrypted folder, this happened on several different PC’s. Hell, the suggestion to zip up with Password protect was actually what we started doing around here. The cool thing there is it can be backed up from network shares no sweat. I don't know what sort of hack proof that solution is, but it worked for what we were trying to do...
-
March 9th, 2005, 08:25 AM
#7
Registered User
Originally Posted by MacGyver
Network share won't suffice because he wants to guarantee only he can see the files (I'm the network admin and I can see everything) and he also wants to take the files with him.
I'll consider the WinXP encryption, but I think the encrypted USB drive is going to be the best option.
*NOTHING* can "secure" files from an admin - not even EFS. The admin can define a recovery policy (even should do it) and easily recover encrypted files. That is one option. The second one is to access the files with that user's account. Getting user's password is a matter of 8 hours for a secure password (10-15 minutes if you already have rainbow tables).
The only "admin-proof" way of storing files is keeping them on removable media and never insert that media in the computer.
What Ya_Know suggested - password-prottected zip with a long password is a viable solution, but again there are temp files...
Protected by Glock. Don't mess with me!
-
March 9th, 2005, 09:19 AM
#8
Registered User
I was thinking something along these lines:
PGP Disk
PGP Disk transparently creates volumes whose contents are encrypted when not in use, preventing unauthorized access. PGP Disk includes options that enable it to automatically unmount a disk after a specified period of inactivity, even with files open, or when a computer goes into Sleep Mode. PGP Disk is especially critical for laptop computers, which are vulnerable to being lost or stolen.
PGP Workgroup Desktop
-
March 9th, 2005, 09:24 AM
#9
Registered User
Pgp
I think I would choose a PGP type solution. I'm using the free open source Winpt (windows privacy tray http://www.winpt.org ) which is an open source PGP compatible prodcut (they call it GPG - gnu privacy guard). It has a feature to encrypt files using a drag and drop interface. It is an manual process but no more so that pkzip IMHO and with pkzip there is still the possibilty the password can be guessed via brute force. At least with PGP the attacker would need the private key (something you have) and the password (something you know). I prefer the free version but even the commercial PGP software isn't that expensive.
If you're a "script monkey" you could probably automate the PGP/encrypting decrypting/clean up for your boss quite easily.
-
March 9th, 2005, 10:13 AM
#10
Similar Threads
-
By DrewJoh in forum Windows XP
Replies: 5
Last Post: September 22nd, 2002, 07:08 PM
-
By Ron Prestenback in forum Windows XP
Replies: 13
Last Post: November 12th, 2001, 02:48 PM
-
By dr-diggs in forum Windows 95/98/98SE/ME
Replies: 8
Last Post: September 25th, 2001, 03:00 PM
-
By Spawn_X in forum Networking
Replies: 7
Last Post: May 10th, 2001, 08:57 PM
-
By Smokey702a in forum BIOS/Motherboard Drivers
Replies: 9
Last Post: April 30th, 2001, 03:14 AM
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|
Bookmarks