Re: file security

From: Torgeir Bakken (Torgeir.Bakken-spam@hydro.com)
Date: 09/07/02


From: Torgeir Bakken <Torgeir.Bakken-spam@hydro.com>
Date: Sat, 07 Sep 2002 03:23:29 +0200


"Robert Gu [MS]" wrote:

> What do you mean loose data sooner or later? If you export your EFS
> certificate+keys, you can reinstall your OS 100 times and you still have
> your files as good as it was written.

Hi

Well, that is the problem, people doesn't do this backup, or they think they do
it, but they do it incorrectly, or they do it correctly, but misplaces the
backup.

When enabling EFS on a computer, NO warning is given. The documentation is
"hidden" and unclear. The combinations of EFS, local computers and novice users
is a disaster waiting to happen. Why do you think Kent W. England (MVP) calls
EFS the "delayed Recycle Bin"? Several times a week there are posts in the
Windows XP groups asking "I can't access my encrypted files. They are very
important to me. What can I do?". Do you think they have backup of the keys? No,
they haven't.

Even if you do backup your keys, you can get into trouble, it seems like:

From: Earl Lewis (brassono_spam@mybizz.net)
Subject: Again with the Encryption!
Newsgroups: microsoft.public.windowsxp.help_and_support
Date: 2002-09-04 12:16:06 PST
http://groups.google.com/groups?selm=cgjcnuc9i2tj8vf0vd9rbdj40g54lr1iqb%404ax.com

For the documentation part, take a look at this extract from a previous thread
"Help with XP Encryption" in newsgroup
microsoft.public.windowsxp.help_and_support:

Message-ID: <q3e4nucj199iqh0hp16pe3mp75ojpcickv@4ax.com>
Date: Sun, 01 Sep 2002 16:59:36 +0100
From: Alex Nichol <Alexn.mvp@btinternet.delete.com>

<qoute>
larry samuels MS-MVP (XP) wrote:
>Copying saved certificates will not work--you have to export and import
>certificates.
>If you did not do this or create a recovery disk before the system
>crashed,the files are history--there is no way to recover them.

I find it extraordinary how *bad* Help and Support is in this area. I
just went looking - out of curiosity - to see, and I can find nothing
the usual enquirer might find by looking under a search on Encryption.
And no cross references into Certificates, nor anything to cause the
casual enquirer about encryption to look there

--
Alex Nichol MVP (DTS)
Bournemouth, U.K.  Alex.Nichol@mvps.org
</qoute>
Message-ID: <5jq4nuc4j41oh3joa0leoleg3gaoela9cl@4ax.com>
Date: Sun, 01 Sep 2002 19:33:58 GMT
From: Earl Lewis <brassono_spam@mybizz.net>
<qoute>
On Sun, 01 Sep 2002 16:59:36 +0100, Alex Nichol
<Alexn.mvp@btinternet.delete.com> wrote:
>I find it extraordinary how *bad* Help and Support is in this area.  I
>just went looking - out of curiosity - to see, and I can find nothing
>the usual enquirer might find by looking under a search on Encryption.
>And no cross references into Certificates, nor anything to cause the
>casual enquirer about encryption to   look there
I can't believe how *incomplete*
http://www.microsoft.com/WINDOWSXP/pro/techinfo/administration/recovery/default.asp
(the .doc)
is. Actually it's a very nice document, with pictures even. It just,
maddeningly, leaves out some details. I kinda wondered if Microsoft
was being reticent because they didn't want those Linux tech-heads
cracking their encryption any time soon. It's sort of like waving a
red flag in front of their noses to shout that it can't be cracked.
Earl
</qoute>
Message-ID: <#EOTBytUCHA.2652@tkmsftngp12>
Date: Mon, 2 Sep 2002 16:44:23 -0700
From: "Kent W. England [MVP]" <kwe@mvps.org>
<qoute>
Alex,
It is a serious omission. Our concerns about this issue have been raised
with Microsoft. Doubt that SP1 will include a fix, but at least MS knows
that we XP MVPs consider this a serious problem.
--
Kent W. England, MS MVP for Windows XP
(Please respond only in the newsgroup)
Alex Nichol <Alexn.mvp@btinternet.delete.com> wrote:
> larry samuels MS-MVP (XP) wrote:
>
>> Copying saved certificates will not work--you have to export and
>> import certificates.
>> If you did not do this or create a recovery disk before the system
>> crashed,the files are history--there is no way to recover them.
>
> I find it extraordinary how *bad* Help and Support is in this area.  I
> just went looking - out of curiosity - to see, and I can find nothing
> the usual enquirer might find by looking under a search on Encryption.
> And no cross references into Certificates, nor anything to cause the
> casual enquirer about encryption to look there
</qoute>
--
torgeir


Relevant Pages