Re: Windows Encryption - All too easy workaround?

From: Carey Frisch [MVP] (cnfrisch_at_nospamgmail.com)
Date: 03/11/05


Date: Fri, 11 Mar 2005 15:06:10 -0600

If someone were to changed the account password, the encrypted files
would remain encrypted and inaccessible. Windows XP creates a randomly
generated file encryption key (FEK) and then transparently encrypts the data,
using this FEK, as it is being written to disk. The FEK, and therefore the data
it encrypts, can be decrypted only with your certificate and its associated private key,
which are only available when you log on with your correct user name and password.
Other users who attempt to use your encrypted files receive an "access denied" message.
Even other administrators who have permission to take ownership of files are unable to
open your encrypted files.

Third-party tools could gain access to your computer, but not the encrypted files.

Best practices for the Encrypting File System
http://support.microsoft.com/kb/223316/EN-US/

You could also set a BIOS password that would prevent someone
from making a change to the boot order. Always set your hard drive
as the first bootable device, and not the CD Drive or floppy drive.
Therefore no one could boot into your system using a CD or floppy
disk.

-- 
Carey Frisch
Microsoft MVP
Windows XP - Shell/User
Microsoft Newsgroups
Be Smart! Protect Your PC!
http://www.microsoft.com/athome/security/protect/default.mspx 
------------------------------------------------------------------------------
"AberTech" wrote:
| I have recently been looking into using the encryption tool in WinXP Pro for
| added privacy/security.  Then someone at work told me about a bootable CD
| from winternals.com(?) called Super Acronis or Locksmith which allows you to
| change the password for any user on that machine.  A reboot later and you
| can log on to that account - including Administrator with the new password.
| As it is the account that your files were encrypted with, anyone who did
| this would automatically be granted access to the encrypted files.  They
| even give you a 5 day working demo available for free!
| 
| On looking at this NG I can see recent posts 'Forgotton Logon password'
| which also cover this.
| 
| If this is so easy to do, it made wonder if there is much point in using
| Windows' encryption?  Is the purchase of 3rd party software necessary to
| ensure that files can be made secure/private?


Relevant Pages

  • Re: EFS Encryption
    ... was left with quite a number of encryption keys in various locations. ... and am unable to decrypt the encrypted files ... Advanced EFS Recovery doesn't do the trick, ... then installed windows xp onto his system again (it already ...
    (microsoft.public.windowsxp.security_admin)
  • RE: cannot decrypt encrypted files
    ... Reinstalling Windows WIPES OUT ... Windows will create a completely NEW random encryption key for that NEW user. ... Note that although you could take ownership of the encrypted files (with an ...
    (microsoft.public.platformsdk.security)
  • Unable to recover encrypted files Help!
    ... I used Microsoft windows Xp proffessional in my computer. ... (No relation with the encryption done) ... installation took place i encountered problems in opening ... Please tell me a way of recovering these encrypted files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: EFS Encryption
    ... If you failed to make copies of your certificate (and no recovery agent certificates exist), ... Remove File Encryption in Windows XP ... Without a backup of the original Encryption Certificate Key, encrypted files ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Encryption Issues
    ... If you didn't make a copy of your certificates, ... Remove File Encryption in Windows XP ... Without a backup of the original Encryption Certificate Key, encrypted files ...
    (microsoft.public.windowsxp.security_admin)