Re: FAQ - READ BEFORE POSTING

From: Karl Levinson [x y] mvp (levinson_k@excite.com)
Date: 12/04/02


From: "Karl Levinson [x y] mvp" <levinson_k@excite.com>
Date: Wed, 4 Dec 2002 16:28:31 -0500


"Drew Cooper [MS]" <dcoop@online.microsoft.com> wrote in message
news:eEjZRb9mCHA.2208@TK2MSFTNGP09...
> In a word: Wow!

Thanks for the kind words.

> On Windows 2000, this is only true if SYSKEY is not used in offline mode.
> Granted, that this is the most common scenario. Who wants to remember yet
> another password or carry around a floppy just to log on?
> On WindowsXP (and soon .Net Server) it's only true for files encrypted in
> machine context and only true if SYSKEY is not used in offline mode. EFS
> sorta breaks one of the "immutable" laws of security.

Yes, you're right, maybe I should have included that fact in the FAQ.
Assuming that most people are like me, when I wrote this I was imagining
people leaving the syskey floppy in the floppy drive 30% of the time, and
losing the floppy [or the password] and thus lose all access to their
computer's hard drive another 20% of the time, thus leaving their computer
still physically vulnerable.

> I very much enjoyed your FAQ. I'll forward it to some of the other
security
> geeks to see if they have feedback for you, too.

Thanks, I do look forward to hearing other feedback.



Relevant Pages

  • Re: FAQ - READ BEFORE POSTING
    ... > On Windows 2000, this is only true if SYSKEY is not used in offline mode. ... > another password or carry around a floppy just to log on? ...
    (microsoft.public.windowsxp.security_admin)
  • Re: FAQ - READ BEFORE POSTING
    ... > On Windows 2000, this is only true if SYSKEY is not used in offline mode. ... > another password or carry around a floppy just to log on? ...
    (microsoft.public.win2000.security)
  • Re: FAQ - READ BEFORE POSTING
    ... > On Windows 2000, this is only true if SYSKEY is not used in offline mode. ... > another password or carry around a floppy just to log on? ...
    (microsoft.public.inetserver.iis.security)
  • Re: NTFS encrypted folders in WindowsXP
    ... >If I encrypt all my folders using NTFS and store the keys safely would this ... In W2K it is possible to inject an arbitrary password by booting to a floppy ... An additional feature of W2K is syskey. ... However the EFS files cannot be accessed. ...
    (comp.security.misc)
  • Re: Passfilt.dll and Syskey
    ... I searched on our database and did not find ... any issues about syskey after upgrading DC to 2000 AD. ... | What are the procedures for upgrading to Windows 2000 from ... I am about to upgrade to ...
    (microsoft.public.win2000.security)