Thoughts on full disk encryption?

Skeeedunt

Platinum Member
Oct 7, 2005
2,777
3
76
I'm debating whether I want to pony up the extra bucks for Vista Ultimate to get BitLocker. What little sensitive data I have (password files mostly) is already encrypted, usually with KeePass or TrueCrypt.

I realize I'm not a high priority target, and that if my laptop does get lost/stolen it's unlikely to undergo a rigorous offline attack, but I'm curious to hear if anyone has any insight into the matter. The biggest concern seems to be that any random chunk of memory could get paged out to disk and left there for someone else to recover. Is this a legitimate concern, or only for the hyper-paranoid? Any way to mitigate or eliminate the risk?

===

I was bored over the weekend, so I went for it. I haven't seen much written about Bitlocker, so I figured I'd share a few thoughts:

Overall, the process was fairly painless. Having to repartition from the command line before you install is a bit annoying, but went smoothly.

After that it's all pretty straightforward. Install Ultimate to the big partition. Go to the Bitlocker control panel page and and hit the On button (this initialized the TPM and encrypts the drive, which took a few hours). Reboot and there you go.

The amazing thing is that the HD Tune benchmarks I got were pretty much identical to this guy's, with slightly higher CPU usage (~6%). All in all, not bad.
 

commOdog

Golden Member
Oct 9, 1999
1,687
0
0
I deploy POINTSEC (now called checkpoint i think) full disk encryption on all our laptops at work. About 600 so far. Use full 256bit AES on them.

We will be switching to Bitlocker when we deploy Vista next year, simply because it is included in our license agreement.

I do know this, you can't get to data without the recovery files if windows borks up, and even then, its a 50/50 chance and a 6-8 hour decryption process
 

Skeeedunt

Platinum Member
Oct 7, 2005
2,777
3
76
Thanks for the responses guys, sorry to take a while getting back.

Originally posted by: commOdog
I do know this, you can't get to data without the recovery files if windows borks up, and even then, its a 50/50 chance and a 6-8 hour decryption process

That's good to know. I've read that physical drive failures could be more catastrophic vs. an unencrypted disk as well. I "plan" to get a good backup strategy going, so hopefully that wouldn't be any more than an inconvenience.

Originally posted by: kamper
According to this, bitlocker will encrypt swap for you, which is good.

That's what I was hoping for. It sounds like FDE is your only option if you're worried about data being paged to disk.
 

stash

Diamond Member
Jun 22, 2000
5,468
0
0
FYI, if you're using Ultimate, you don't need to set up the partitions with diskpart beforehand. There is a Bitlocker prep tool available as an Ultimate extra that does this for you.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |