How To Secure A Hard Drive

The ONLY viable solution to protect your HD is to encrypt entire content of the HDD with secure encryption and use preboot authentication so that nobody can tamper it. ALL other options WILL fail, since there is always possibility to either tam...




Topic Options
#121479 - 02/27/03 08:59 AM How To Secure A Hard Drive
KhaineBOT Offline
stranger

Registered: 02/03/03
Posts: 18
The ONLY viable solution to protect your HD is to encrypt entire content of the HDD with secure encryption and use preboot authentication so that nobody can tamper it. ALL other options WILL fail, since there is always possibility to either tamper the settings, take out the HDD to read the contents of it or plant trojan horse into it.

Couple examples of such (not-so-free) products are
- "Drivercrypt plus" http://www.drivecrypt.com/dcplus.html
- "Safeboot solo" http://www.controlbreak.net/products/sbsolo41.html

After that, all you have to worry about is hardware keyloggers...

Top
Advertisement
#121716 - 03/03/03 09:03 PM Re: How To Secure A Hard Drive
duhmez Offline
addict

Registered: 04/27/02
Posts: 583
Loc: Canada, West siiiiiiiiiide!
Problem I see with windows native encryption, all someone has to do after stealing your HD, is crack the user account passwords, then they can read it all anyways.

Tying encryption to user accounts a really weak security wise IMO.

Unless there is somehting I am missing....
\

Top
#121742 - 03/04/03 04:31 AM Re: How To Secure A Hard Drive
Xiven Offline
addict

Registered: 05/21/00
Posts: 690
Cracking the user account passwords isn't as easy as it seems. The most common way of breaking into a Windows 2000/XP machine is to delete the file containing the passwords. However, if you do this you'll never gain access to those encrypted files ever again. Since that's not an option, you'll have to try things the hard way (dictionary cracker etc) which puts it on the same level as any other kind of encryption.

Top
#121762 - 03/04/03 08:29 AM Re: How To Secure A Hard Drive
KhaineBOT Offline
stranger

Registered: 02/03/03
Posts: 18
Well in windows 2000 EFS can apparently by bypassed 3rd party software :

http://www.elcomsoft.com/aefsdr.html

"Advanced EFS Data Recovery (or simply AEFSDR) is a program to recover (decrypt) files encrypted on NTFS (EFS) partitions created in Windows 2000. Files are being decrypted even in a case when the system is not bootable and so you cannot log on, and/or some encryption keys (private or master) have been tampered. Besides, decryption is possible even when Windows is protected using SYSKEY. AEFSDR effectively (and instantly) decrypts the files protected under all versions of Windows 2000 (including Service Packs 1, 2 and 3)."

So I would prefer to using something alittle more secure smile

Second Both of these products encrypt the whole HD, so they can't use a boot disk to delete the SAM account, which is a big bonus smile

Top
#121805 - 03/04/03 09:31 PM Re: How To Secure A Hard Drive
duhmez Offline
addict

Registered: 04/27/02
Posts: 583
Loc: Canada, West siiiiiiiiiide!
CRacking the password is easy if you have the hard drive. Reset the admin password (no probleem i can do it in 2 seconds), then login and reset every other password using users and passwords applet.

not that mS security options like this are bad in themselves, the problem is every cracker out there works to crack it. It would seem to me that using obscure third party tools would make anything that much more secure.

Top
#121822 - 03/05/03 01:36 AM Re: How To Secure A Hard Drive
Xiven Offline
addict

Registered: 05/21/00
Posts: 690
Quote:
CRacking the password is easy if you have the hard drive. Reset the admin password (no probleem i can do it in 2 seconds), then login and reset every other password using users and passwords applet.


In Windows XP, if you try to change another user's password (ie. using User Management) it will warn you that if you do so, they will no longer be able to access their secure files. Like this:



Now I'm not sure if this applies to Win2k and the warning is just not there or not. But resetting the account password should not work.

Quote:
Well in windows 2000 EFS can apparently by bypassed 3rd party software


Hmm, I was led to believe it was more secure than that. Ah well.

Top
#121847 - 03/05/03 08:14 AM Re: How To Secure A Hard Drive
KhaineBOT Offline
stranger

Registered: 02/03/03
Posts: 18
I believe that EFS itself is secure, but the way Microsoft implemented it is flawed and thus not secure.

About that program APK, I honestly don't know if it works over lan's or not, as I haven't used it.

Top
#121894 - 03/05/03 10:31 PM Re: How To Secure A Hard Drive
duhmez Offline
addict

Registered: 04/27/02
Posts: 583
Loc: Canada, West siiiiiiiiiide!
That's interesting, about chaning the password. what does this mean then? How can a user change his password safely???

Top
#126812 - 05/30/03 05:39 PM Re: How To Secure A Hard Drive
insaNity Offline
member

Registered: 11/09/01
Posts: 155
is it tied specifically just to your password? because I thought there was some sort of 'certificiate' deal.... if it is tied to your password... can't changing the password back to the original let you access the encrypted files again?
This is kinda important, cause I'm wondering what will happen to the encrypted files on my D partition if I decide to kill my C partition.. (inevitable that I will install windows again and some point)

Top
#126833 - 05/31/03 01:27 AM Re: How To Secure A Hard Drive
clutch Offline
Carpal Tunnel

Registered: 03/29/00
Posts: 3859
From what I remember, EFS uses "keys" to access the files, and you need those keys to get to them. Now, most people leave the keys on the same drive as the encrypted files and never backup or remove them. I wonder if this software relies on that flaw in usage by the user.

Top
#126855 - 05/31/03 01:45 PM Re: How To Secure A Hard Drive
insaNity Offline
member

Registered: 11/09/01
Posts: 155
so these keys are stored hidden on the partition? So in my case it shouldn't be a problem? how do I back them up in case?

Top
#126860 - 05/31/03 08:01 PM Re: How To Secure A Hard Drive
clutch Offline
Carpal Tunnel

Registered: 03/29/00
Posts: 3859
Read the whitepaper here for a better understanding of EFS:

http://www.microsoft.com/windows2000/techinfo/howitworks/security/encrypt.asp

Check out the word doc link.

Top
#131427 - 09/21/03 03:16 PM Re: How To Secure A Hard Drive
trilliansucks Offline
newbie

Registered: 09/21/03
Posts: 26
how is a 3rd party app any less vulnerable to a dictionary attack? wink

Top
#131432 - 09/21/03 04:12 PM Re: How To Secure A Hard Drive
felix Offline
addict

Registered: 10/28/99
Posts: 691
Loc: Hobart, Australia
That error message 5 posts above only seems to occur when changing the password in "Manage>>Local Users & Groups". If you use the "users" applet on the control panel (as suggested) you don't seem to have this problem.
Perhaps MS used the local system account to add a quiet decrypt key to the data so when you change the password, the data is decrypted using the local system account rather than the user account.
This then points to the usual idea advocated by APK, Clutch and the like that once someone has physical access to your system, you can put your head between your knees.

Top


Forums
Windows Support Forums
Everything New Technology
Legacy OS
Hardware
Software
Games
Networking
Customization & Tweaking
Security

Linux Support Forums
Everything Linux
Linux Hardware
Linux Software
Linux Games
Linux Networking
Linux Customization & Tweaking
Linux Security

Apple Support Forums
Everything Apple
Recent Topics
For sale brand new Apple iPhone 3GS 32GB- $210,Bla
by MOBILE3
5 seconds ago
x86 OS, RAM, & Virtual Machines
by Myke
Yesterday at 08:16 PM
Ram Question
by JohnnyAshes
12/21/09 09:50 PM
NEWBIE needs help with REALTEK
by SerryJW
12/21/09 06:09 AM
What version of Linux is this?
by DxxLinux
12/15/09 07:59 PM
Who's Online
2 Registered (danleff, MOBILE3), 180 Guests and 38 Spiders online.
Key: Admin, Global Mod, Mod
Forum Stats
91371 Members
24 Forums
59176 Topics
189698 Posts

Max Online: 1079 @ 03/12/08 01:36 PM

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22