Utimaco Safeguard Easy vulnerability



Hello guys,

At this moment our company looks for a software to encrypt the whole
disk drives on laptops.


I see that many companies and government institutions use Utimaco
Safeguard Easy.


First, we looked at this software as well.


However, it seems that the tool that is supposed to make laptops more
secure has some serious problems related to password and key
distribution.


For deployement in big companies, Utimaco recommend to implement
centralized management.
The management is done via CFG-files that are pushed via SMS, Active
Directory or otherwise.


These CFG files contain encryption keys for hard disks and floppy, as
well as user passwords and backup passwords for recovery.


The content of the file is supposedly "encrypted" as Utimaco's manual
says. However, it seems that the encryption keys are hardcoded directly

in the EXE file. So, they are easily recoverable and all these CFG
files can be easily compromised.


I am just wondering whether it has been discussed here and someone else

has seen this problem before?


I know that many government and bank institutions use this product, am
I the only person to see this security whole?


Thank you


boom

.



Relevant Pages

  • Utimaco Safeguard Easy vulnerability
    ... At this moment our company looks for a software to encrypt the whole disk drives on laptops. ... I see that many companies and government institutions use Utimaco Safeguard Easy. ... it seems that the tool that is supposed to make laptops more secure has some serious problems related to password and key distribution. ... Utimaco recommend to implement centralized management. ...
    (Bugtraq)
  • Utimaco Safeguard Easy vulnerability
    ... I see that many companies and government institutions use Utimaco ... it seems that the tool that is supposed to make laptops more ... These CFG files contain encryption keys for hard disks and floppy, ...
    (sci.crypt)
  • Utimaco Safeguard Easy breach
    ... I see that many companies and government institutions use Utimaco ... it seems that the tool that is supposed to make laptops more ... These CFG files contain encryption keys for hard disks and floppy, ...
    (alt.computer.security)
  • Re: The ugly side of using disk encryption
    ... That is good info about DriveCrypt. ... because compusec only supports 128 bit AES encryption. ... My forensic laptops are all DriveCrypted, I have let at least 50 different ... > EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ...
    (Security-Basics)
  • RE: Whole disk encryption
    ... We use SafeBoot on all our laptops and even on a bunch of dekstops. ... For specific data you can also use the content encryption future to ... WHY would you choose to NOT do full disk? ...
    (Focus-Microsoft)