Home > Enterprise Desktop Tips > > Questions about using BitLocker Drive Encryption
Enterprise Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


Questions about using BitLocker Drive Encryption


Serdar Yegulalp, Contributor
12.06.2006
Rating: -4.50- (out of 5)


Advice for securing Windows
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


This is the second part of Serdar's two-part series on Windows Vista's BitLocker.


BitLocker Drive Encryption, the security feature touted in Windows Vista, is sparking controversy. Some of the furor is predicated on misinformation about what BitLocker really is or how it is to be used, or how it might be possible to perform an end-run around it.

    BitLocker has no key escrow system. "Key escrow," a controversial provision in some encryption systems, allows a third party such as a government body to hold a set of universal keys that would allow any data encrypted by the system to be unlocked with one of those keys. When asked if BitLocker would have any such "back door" provisions, Niels Ferguson, one of the Microsoft developers responsible for BitLocker, responded as bluntly as possible: "Over my dead body. … In the unlikely situation we're forced to [add key escrow] by law, we'll either announce it publicly or withdraw the entire feature."

    You can't gain access to a BitLocker volume by simply installing a parallel copy of Vista or moving the hard drive to another computer. BitLocker uses multiple key structures to ensure that a system volume cannot be decrypted by using another parallel install of Vista or some other extra operating system (OS) mechanism. Only the OS, encrypted by a given combination of keys, can access the key required to read the boot volume.

BitLocker in competition

Another widely asked question about BitLocker is how it compares to existing encryption products, both commercial and free. WinMagic Inc.'s SecureDoc is one example of a Windows product that supports full-system encryption, including the OS partition, and that also supports other verification mechanisms such as smart cards. SecureDoc is used extensively. More than 500,000 licenses have been sold worldwide, according to the company. Administrators may want to balance the per-license cost of SecureDoc ($150 per seat, with volume discounts) against the cost of upgrading to Vista. If Vista upgrades are planned and they work out to be cheaper overall, BitLocker may be the better deal. People looking to encrypt specific systems now, however, can benefit from SecureDoc.

Encryption for desktops
  • TrueCrypt: Free encryption utility

  • Encryption made simple: LockNote
  • Another product that is popular is TrueCrypt. I've worked with TrueCrypt a fair amount, and it has one feature that distinguishes it heavily from BitLocker: Full volumes encrypted with it are indistinguishable from random data, and there is no volume signature on an unencrypted volume. By contrast, BitLocker volumes can be easily detected, as they have a distinct signature. To that end, TrueCrypt is more useful for encrypting non-system data, such as auxiliary or external drives.

    One possible way to use TrueCrypt (or another file-and-partition product) for creating an encrypted OS partition would be to create a system volume for a virtual PC on an encrypted drive and use that. This is perfectly feasible (in fact, I've done it myself), but it requires the presence of virtual machine software in the first place.

    Because BitLocker is a Vista-exclusive product designed to meet a very specific need — full-disk encryption for the Windows OS partition — the odds of it displacing existing general-purpose or full-disk encryption solutions are pretty low. But as Vista becomes the version of Windows over the next several years, BitLocker ought to become more attractive as a standard-issue way to secure laptops and desktops -- either with or without the additional expense of TPM hardware.

    Read the first half of this tip, End-to-end encryption for Windows Vista systems: BitLocker.

    About the author:Serdar Yegulalp is editor of the Windows Power Users Newsletter. Check it out for the latest advice and musings on the world of Windows network administrators -- and please share your thoughts as well!

    Rate this Tip
    To rate tips, you must be a member of SearchEnterpriseDesktop.com.
    Register now to start rating these tips. Log in if you are already a member.


    Submit a Tip




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Microsoft Windows Vista operating system
    Windows 7 launches, offers salvation from Vista
    An intro to Windows 7's Deployment Image Servicing and Management tool
    Guide to converting from Windows XP to Windows 7
    Choosing the best way to install images
    Has Microsoft corrected Vista annoyances in Windows 7?
    Microsoft's August patches run the gamut
    Your questions answered: The Windows 7 upgrade quandary
    Windows Vista users get little pricing relief on Windows 7
    Combining folder redirection with roaming profiles
    IPv6 protocol, Windows Vista features simplify peer ad-hoc networking

    Patches, alerts and critical updates
    Structuring patch management in seven steps
    Underlying causes of inconsistent patch management
    Microsoft's Online Desktop Manager caters to small IT shops
    Microsoft's Patch Tuesday brings a bumper crop of security fixes
    Act fast with five critical September patches
    Microsoft's August patches run the gamut
    Patching third-party browsers adds more work in Windows shops
    Troubleshooting Microsoft WSUS connectivity issues
    Windows security tools for the busy desktop administrator
    The state of enterprise security and emerging threats in 2009

    Windows desktop security tips
    Structuring patch management in seven steps
    Underlying causes of inconsistent patch management
    Monitoring user activity with network analyzers
    Microsoft's Patch Tuesday brings a bumper crop of security fixes
    Using third-party technologies with Microsoft's NAP
    Understanding Microsoft's NAP's internal and external components
    Microsoft's NAP can ensure security compliance
    Top 5 registry keys for Windows XP
    Secure Windows XP before a Windows 7 upgrade
    Nine common password oversights to avoid

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    desktop management  (SearchEnterpriseDesktop.com)
    Vista  (SearchEnterpriseDesktop.com)
    Vista glossary  (SearchEnterpriseDesktop.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



    Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
    HomeTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogs
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts