Re: In light of what has happened with the theft of the VA laptop, what are the "best practices" for securing laptops?



One thing I do for added security, is enable an extra password to
access syskey (required before msgina.dll is loaded). Go to start >
run > syskey.exe [enter]

Make sure encryption is enabled, then press "update".

You can choose to use a system generated password, or set your own.

If you use a system generated startup key, you can choose to place it
on a floppy disk or usb key; the system wont boot to Windows without
it inserted it/plugged in.

Also of course I set up a bios password that is required at boot, and
enable the password on resume from screensaver.

I've been using truecrypt for a while now, and I have to say I love
it. More important than truecrypt itself, are the extensions tcgina
and tctemp which can be found here:
http://www.truecrypt.org/third-party-projects/

tcgina puts the entire user profile (My documents etc) into a
encrypted virtual drive that is mounted at login, this process is
almost transparent to the user.

tctemp encrypts the entire page file, which, is clearly a good idea.

Thats all I can think of for now...

In my case, I use different passwords for each step of the boot up
process, but in a real life business enviroment, getting a vp or ceo
to follow by this is near impossible.

Daniel Hückmann



Relevant Pages

  • Re: Retrieving Encrypted Directories
    ... if there's any chance that you still have the old "user profile" stored ... encryption system. ... 1991 Floppies are almost certainly drink coasters by now. ... disks might be completely unusable by now anyway. ...
    (microsoft.public.windowsxp.security_admin)
  • RE: [Full-Disclosure] harddisk encryption
    ... > boot process and may be broken by anything that changes the system boot ... In the event of disk crash or emergency, unless a tool is provided to ... > i'm evaluating a software that performs harddisk encryption for deploying ...
    (Full-Disclosure)
  • Re: New laptop - resize win partition?
    ... Torfinn> Only one small snag - the disk is encrypted (with ... which means that I'll have to boot ... having both the encrypted Windows volume and an unencrypted FreeBSD ... talk the client CISO into letting me install the disk encryption ...
    (comp.unix.bsd.freebsd.misc)
  • Re: REQ: Computer Security Software Help
    ... >boot into my computer from a cd-rom or floppy disk? ... physical access to your computer is encryption, ... compromise (e.g., a hardware keylogger like keyghost, video, ... tamper-proof seals aren't :-) Although they're enough to ...
    (alt.computer.security)
  • Crypto implementation for public use (was: RE[2]: Storing an encryption key in CMOS)
    ... VBK> passwords and unencrypted sensetive data. ... Your security always depends on security expert ... VBK> If you really wanna use strong filesystem encryption, ... the system boot is locked by a BIOS password. ...
    (Security-Basics)