RE: The VA Stolen Laptop - Lessons Learned



If the laptop is stolen, and off the network when you disable the
account, how the heck do you think the fact the account has been
disabled reaches the laptop?

"encrypt it as the roaming profile"? The roaming profile is very
specific files. If you're talking about using EFS, you have other
concerns as well.

If you encrypt a user's profile with EFS, the key would have to be on
the machine or the user couldn't get to their profile off the network.

If the key is left on the machine, then anyone with physical access to
the machine can reset the admin password, login as the admin, and grab
the user's key and get to the files.

The encryption used should be something other than EFS, and should be on
a directory outside the profile (so copies aren't flung onto the user's
network share).

Basically, the users should be trained, and the plan should be created
by someone who knows what they are doing, and people should stop
pointing fingers when something goes wrong, and instead address the
issues.

Good slam on the Prez, BTW, both pertinent and relevant, and about as
thoughtfully consistent as the rest of your rant.

-Scott Ramsdell

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Isaac Van Name
Sent: Thursday, September 14, 2006 8:18 AM
To: 'evb'; security-basics@xxxxxxxxxxxxxxxxx
Subject: RE: The VA Stolen Laptop - Lessons Learned

Bush hasn't defined "data"... he can't define anything because he's a
moron.

Does data include OS files, log files, cab files, drivers, etc.?
IMO, no. None of it. Screw the OS and its files; those things don't
count
as "sensitive data". Okay, so there's the argument that "these things
can
be used for a compromise". Really, I don't see why someone can't just
use a
roaming profile and a VPN connection on the laptop to connect to their
workplace and, anytime sensitive data like that is put on a laptop,
encrypt
it as the roaming profile and set the file rights to only allow that
roaming
profile to access it. That way, when the laptop is stolen, just disable
the
roaming account... that should protect the encrypted files for long
enough
for the laptop to be recovered. True, this is more work, but then,
isn't
proper security just making your everyday tasks take longer?

Of course, this is all said with a cup of coffee in one head and my
hungover
head in the other, so please feel free to correct me. As it seems to
me,
though, I think you have to plan out system security before you
implement
file security... otherwise, you're just playing smoke and mirrors.


Isaac Van Name
Network Assistant / Programmer
Southerland, inc.
ivanname@xxxxxxxxxxxxxxxxxxxx

-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On
Behalf Of evb
Sent: Wednesday, September 13, 2006 3:47 PM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: RE: The VA Stolen Laptop - Lessons Learned


:1. Encrypt all data on mobile computers/devices which carry
:agency data unless the data is determined to be non-sensitive,
:in writing, by your Deputy Secretary or an individual he/she
:may designate in writing
:

And does "data" include operating system files, log files, cab files,
drivers, etc., or does it only include eg xls, doc, pdf and wpd files,
etc.?
How has Bush defined "data"?

Thx,

Eric


------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic
Excellence
in Information Security. Our program offers unparalleled Infosec
management
education and the case study affords you unmatched consulting
experience.
Using interactive e-Learning technology, you can earn this esteemed
degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---




------------------------------------------------------------------------
---
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic
Excellence
in Information Security. Our program offers unparalleled Infosec
management
education and the case study affords you unmatched consulting
experience.
Using interactive e-Learning technology, you can earn this esteemed
degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
------------------------------------------------------------------------
---


---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: Roaming Profile still tries to load off network
    ... laptop and remote workers going crazy. ... When you logon, the computer knows ... load a roaming profile if it already knows it is working from the cache. ... Try logging in with the network cable unplugged. ...
    (microsoft.public.windowsxp.general)
  • Re: Roaming Profiles , Laptops with Outlook Cached mode Offline fi
    ... The Local Settings location is ok but you can move it to another location if you want as long as it is local to the computer and not within a folder that is in your roaming profile or does some other logon/logoff synchronisation. ... Outlook FAQ, HowTo, Downloads, Add-Ins and more ... should i just disable cached exchange mode on the old laptop so it saves ...
    (microsoft.public.outlook.installation)
  • Re: roaming profile for user with two computers
    ... > in mind that the user will not be getting any roaming profile settings. ... > separately on the laptop. ... >> user has a desktop computer with all software installed on it. ...
    (microsoft.public.win2000.networking)
  • RE: Roaming profile problem
    ... when you logged into the laptop - and when you logged out of the laptop it ... was that version that was sent back to the server. ... logged onto my laptop and the roaming profile loaded fine with my ... > previous changes from step 5 (deleted icons from desktop did not delete). ...
    (microsoft.public.windowsxp.general)
  • Re: roaming profile for user with two computers
    ... a user either has a roaming profile or he doesn't. ... You should then be able to configure the laptop profile as desired, ... in mind that the user will not be getting any roaming profile settings. ... > user has a desktop computer with all software installed on it. ...
    (microsoft.public.win2000.networking)