home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers



Security
R E V I E W  
Gone in 6.0 Seconds

  September 30, 2002
  By Mike DeMaria


>> continued from previous page

Disk-Encryption Software
TOC Issue TOC
Printer Print full article
Printer Print this page
Printer Download as PDF
E-Mail E-Mail this URL
flame author Flame the author
 
  In this article
arrow
Introduction
arrow
The Eighth Commandment
arrow
Disk-Encryption Software
arrow
Report Card: Disk Encryption Software
arrow
Lockdown Devices
arrow
Report Card: Lockdown Devices
arrow
Recovery Services
arrow
Report Card: Recovery Services
arrow
Executive Summary
arrow
File-Encryption Products

Products Reviewed: WinMagic SecureDoc 3.1 | Pointsec Mobile Technologies Pointsec PC 4.0 | PC Guardian Encryption Plus Hard Disk

You can encrypt files individually, either file by file or whole folders, or encrypt an entire drive. Each method had advantages: When you encrypt individual files with third-party software, you can send them across a network knowing that the files won't be accessible to anyone who does not have the password and the encryption software loaded. Whole-drive encryption, on the other hand, prevents data theft if a computer is stolen. We looked at a trio of disk-encryption offerings: PC Guardian's Encryption Plus Hard Disk, Pointsec Mobile Technologies' Pointsec PC 4.0 and WinMagic's SecureDoc 3.1.

File-level encryption is a well-understood process. Commonly used encryption schemes include AES (Advanced Encryption Standard), Blowfish and 3DES with keys varying from 56 to 256 bits in length, and all sorts of single-file and folder-encryption products are available, including some shareware and freeware. Some encryption products require you to decrypt the data with the same computer (or key) with which it was encrypted. Other products let you encrypt/decrypt with a password. The user's needs should determine which method you use.

A huge number of file- and folder-encryption programs are on the market, with little differentiation, so we decided to take a look at two: Microsoft EFS because it's built into Windows 2000 and up, and PC Guardian's Encryption Plus File. You'll find our evaluation of these products here.


Web Links
"Control the Keys to the Kingdom" (Network Computing, Sept. 2, 2002)

"Aventail Delivers SSL-based VPN Appliance" (InternetWeek, Aug. 27, 2002)

"Enterprise Firewall Line Extended to Laptops" (InternetWeek, July 18, 2002)

To protect temporary files, swap files and printer spools, you need to encrypt the entire drive. Because the entire file system is encrypted, including the OS, drive-encryption software must load before the OS. Normally, after you power on a computer and it goes through its memory test, the boot loader will load the OS. When you install drive encryption software, it modifies the boot loader to run instead of Windows on boot. The encryption software then authenticates the user, and, on success, loads Windows. This is a much more complicated procedure than simple file or folder encryption--the point of these products is to protect the data from a thief who gets his or her hands on the hard drive, not to secure the data when copied or transmitted.

The three drive-encryption products we evaluated load on bootup, request a user name/password login or token, and then perform on-the-fly decryption and load the OS. Because the OS is encrypted, users must enter the decryption key (password or token) to boot the system. If they forget the password, an administrator can override the user's password.

Files remain encrypted on the drive. However, they are in the clear when sent over the network or copied to a removable disk or unencrypted partition/drive. When we analyzed the disk after encryption, the entire drive was encrypted except for some bootstrap code. Some features to look for are multiuser support, recovery keys, administrator overrides, centralized management and integration with PKI (public key infrastructure) and tokens, in addition to user name/password authentication.

Also, there is a difference between full-drive encryption and virtual-drive encryption. Software that performs virtual-drive encryption creates a single large encrypted file on a disk, and is presented to Microsoft Windows as a logical mountable drive. It acts like a container.

Emulation software (such as VirtualPC on the Apple Macintosh) and disk-image files have been doing this sort of thing for years. However, these virtual drives offer the same level of protection as folder-level encryption--in other words, the swap file and temporary files are unencrypted. Be careful: Sometimes the product marketing won't make this distinction clear.

Winmagic secureDoc 3.1



SecureDoc encrypts drives with DES, 3DES and AES. It also lets you encrypt individual floppy disks with the same encryption key or a key shared among a few people. We were able to encrypt two floppy disks with two different keys. The advantage here is you can protect and hide data from multiple departments within your organization. This is a unique feature--none of the other vendors supports removable drive encryption--and is enough to make SecureDoc our Editor's Choice.

Disks can be encrypted and shared among a group, which is a common activity, or reserved for the lone user. In addition, you can store the encryption key on the floppy disk instead of the hard drive, thus requiring the floppy in addition to user name/password and acting as a token. Another feature supported is locking down the removable drives. We were able to prevent the user from accessing the floppy drive, though the efficacy of this feature comes into question when you consider that the files can be uploaded easily off the computer via HTTP or FTP.

SecureDoc 3.1 Disk Encryption Software, $159 (individual license). WinMagic, (905) 502-7000, (888) 879-5879. http://www.winmagic.com

Pointsec Mobile Technologies Pointsec PC 4.0



Pointsec has fewer features than SecureDoc, but still offers a lot of options. Encryption is done via Blowfish or CAST, and the product lets you create multiple users and groups, and offers smartcard integration. Like all the products we evaluated, there is support for the administrator to generate a one-time login password in case the user forgets his or her password and needs to change it.

Users can be granted or denied access to individual partitions. And Pointsec PC can't encrypt removable media. The initial encryption process (after installing the product) runs in the background while Windows is loaded. This means users can continue to work as a drive is being converted to an encrypted format. SecureDoc offers this capability; PC Guardian's product does not. Seeing as it took us several hours to encrypt a 9-GB drive, this is a useful capability.

Pointsec PC 4.0, $42,580. Pointsec Mobile Technologies, (925) 256-2500, (800) 579-3363. http://www.pointsec.com

PC Guardian Encryption Plus Hard Disk



This product was the simplest to use and administer, but it is less feature-rich than its competitors. The program is limited to one user login/password per machine. There is no support for tokens or PKI integration, and the product will encrypt only the primary hard drive. It does, however, offer master password capabilities, custom installer-package creation and one-time password overrides. This product seems best suited for individuals and smaller departments, especially those that want an easy-to-configure package. For large installations that require good key management, multiple users and PKI, the other products would be a better choice.

Encryption Plus Hard Disk, $99.95 per seat (50 seat minimum). PC Guardian, (415) 459-0190, (800) 288-8126. http://www.pcguardian.com


start top  The Eighth Commandment Report Card: Disk Encryption Software 





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Aneesh Chopra is looking to other CIOs to advise him on fleshing out a more detailed agenda to best serve the president's IT agenda.

IT spending is expected to decline by 3.8 percent in 2009 according to Gartner.










2009 IT Salary Survey: Meager Raises, Solid Prospects
Though raises are notably smaller than a year ago, and job security’s shrinking, IT careers are looking safer than many others in this economic downturn. Get all the findings in InformationWeek's 2009 IT Salary Survey. Available FREE for a limited time.
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



Techweb
Informationweek Business Technology Network
InformationweekInformationweek 500Informationweek 500 ConferenceInformationweek AnalyticsInformationweek Events
Informationweek MagazineGlobal CIOIWK Government ITbMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingPlug Into The CloudDr. DobbsContentinople
space
TechWeb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0Mobile Business ExpoNoJitter
Black HatGTECEnergy CampCloud ConnectGov 2.0 ExpoGov 2.0 Summit
space
Light Reading Communications Network
Light ReadingLight Reading AsiaUnstrungCable Digital NewsInternet EvolutionPyramid Research
Heavy ReadingLight Reading LiveLight Reading InsiderEthrnet ExpoTelco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems and TechnologyInsurance and TechnologyWall Street and TechnologyAccelerating WallstreetBST SummitBuyside Trading SummitIT Summit
space
Microsoft Technology Network
MSDNTechNetTotal IT ProTotal Dev ProNET Total Dev Pro CommunitySQL Total Dev Pro Community
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service