Windows Encryption - All too easy workaround?

From: AberTech (abertech_at_hotmail.com)
Date: 03/11/05


Date: Fri, 11 Mar 2005 20:19:10 -0000

I have recently been looking into using the encryption tool in WinXP Pro for
added privacy/security. Then someone at work told me about a bootable CD
from winternals.com(?) called Super Acronis or Locksmith which allows you to
change the password for any user on that machine. A reboot later and you
can log on to that account - including Administrator with the new password.
As it is the account that your files were encrypted with, anyone who did
this would automatically be granted access to the encrypted files. They
even give you a 5 day working demo available for free!

On looking at this NG I can see recent posts 'Forgotton Logon password'
which also cover this.

If this is so easy to do, it made wonder if there is much point in using
Windows' encryption? Is the purchase of 3rd party software necessary to
ensure that files can be made secure/private?



Relevant Pages

  • Re: X.509 and ssh
    ... encryption which may be illegal in some jurisdictions, ... supposedly hiding an account number. ... authorty industry embellishing the role of digital certificate as the ... the issue with LDAP isn't so much that real-time, ...
    (comp.security.ssh)
  • Re: How to securely store a password on a PC
    ... password - so locking the data to ONE account will not solve that problem. ... Full disk encryption can protect against EXTERNAL attackers (who ... full encryption - not only Vista's BitLocker but any 3rd party solution. ... Security is not about the secrecy of the algorithm. ...
    (microsoft.public.platformsdk.security)
  • Re: decrypt help...
    ... > i've tried re-establishing a user account with the same name as when i ... then importing the cert/key combo into that account ... You would need a backup of the user profile and machine system state as well ... >> a slippery slope that most stay as far away from encryption as possible. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: EFS Certificates and Keys when Changing Password
    ... What that meant is that changing the password of the account only ... this case that the system will upon an encryption attempt generate a new ... Then I exported the certificate/key pfx file to a floppy disk. ... Then I encrypted more data files. ...
    (microsoft.public.windowsxp.security_admin)
  • File Encryption
    ... I wasn't logged into Administrator ... account appears to be the only account whose security ... my certificate and security information is intact (the ... related files, encryption keys, etc). ...
    (microsoft.public.windowsxp.security_admin)