Protecting the Operating System



Hello,
I have just come to the conclusion that the only way to protect the machine
with free physical access to anauthorized personnel is... to encrypt it.
Unfortunately it seems that this can be done only the lonely by DriveCrypt
software which costs a lot. It's wonderful stuff indeed allowing to encrypt
the drive with authentication feature at the pre-boot level! The encryption
seems excellent AES-256 algotithm. It's only drawback (except for the price)
is that it doesn't see Linux partitions (not to mention that it doesn't run
on Linux)which makes them liable to potential attack. It looks like for now
only Windows operationg system may be securely locked unless you run Linux
as a VMware guest system on the DriveCrypted Windows host. I wonder what are
your experiences with respect to securing the stand alone box with
uncontrolled physical access, like at the University (my case).
P.S. Have just noticed free stuff called CompuSec PC Security Suite which
seems both Windows and Linux compatible though as compared to DriveCrypt it
uses weaker encrypting algorithm AES-128 and looks like is much slower. I
cannot wait to hear your comments.
Kindest regards,
--
Ricardo


.



Relevant Pages

  • Protecting the Operating System
    ... with free physical access to anauthorized personnel is... ... It's wonderful stuff indeed allowing to encrypt ... only Windows operationg system may be securely locked unless you run Linux ... uncontrolled physical access, like at the University. ...
    (alt.computer.security)
  • Re: Linux, BSD, and Unix are fundamentally insecure.
    ... what you are saying is that someone with physical access to a machine ... > the option to encrypt the hard drive, you won't get at the data. ... The *only* thing file system encryption buys you is the ability secure the ... hardware if it is accessed outside the installed operating system. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Linux, BSD, and Unix are fundamentally insecure.
    ... what you are saying is that someone with physical access to a machine ... > the option to encrypt the hard drive, you won't get at the data. ... The *only* thing file system encryption buys you is the ability secure the ... hardware if it is accessed outside the installed operating system. ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Password Security
    ... > 'the bad guys' have physical access to your box, ... stealing it and breaking in at their convenience. ... Is it possible to encrypt mySQL database ...
    (freebsd-questions)
  • Re: File encryption: bdes or gpg
    ... > to encrypt a file and store it on my filesystem. ... > access or physical access to my computer. ... > merits of these approaches or pointers to better options if available. ... To unsubscribe, ...
    (freebsd-questions)