Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


September 21, 2000

Laptop Security: Be Deliberate

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Laptops are commonplace today and so is their theft. But losing the computer often doesn't matter as much as losing the data it contains.

Case in point: Qualcomm's chairman and CEO recently gave a speech to the Society of American Business Editors and Writers at the Hyatt Regency Hotel in Irvine, California. After his speech, numerous journalists gathered around to ask questions. During that brief time, he was never more than 30 feet from his laptop, yet someone managed to steal it. The laptop contained some of Qualcomm's most valuable trade secrets (reported to be worth millions), which are now in the thief's hands.

News reports indicate the laptop was running a Microsoft OS and required a password to access its files, but the OS had no file encryption in place. In one report, the executive openly commented that he hoped Microsoft's password protection would prevent access to the laptop's data. But certainly you realize someone can access the laptop's files without a password. For example, a person can use an NTFS book disk if the laptop uses that file system, or someone can simply install a new OS, boot it, log on, and access the data.

The need to protect portable computing platforms is obvious in this light. Not only must you guard the device at all times, you should also consider some form of disk encryption to protect against a worst-case theft scenario.

If you prefer the Windows platform, consider adopting Windows 2000 for systems that store sensitive information. The new OS contains an Encrypting File System (EFS) that uses public key technology to guard files. Without the private key, users can access the file system only through an account that has been authorized as a private key recovery agent. Learn about EFS and some best practices by clicking here. You can also find two articles on our Windows 2000 Magazine Network written by Mark Russinovich that explain EFS in detail. Search for "Encrypting File System" to locate the articles quickly.

Also, be aware of a nuance to the EFS utilities, which Windows 2000 Magazine contributing editor Kathy Ivens recently discovered: EFS documentation states that read-only files won't be encrypted. However, Kathy found that in one scenario, read-only files are encrypted. If you use the Properties dialog in Windows Explorer to mark a folder encrypted, a message asks whether you want to encrypt all subfolders and files. If you choose not to do so, all files in the selected directory, including any read-only files, will be encrypted. This does not occur with the command line EFS utility Cipher.exe. We alerted Microsoft about this matter, and the company intends to clarify the nuance in the documentation.

If you prefer not to rely on EFS to protect your data, consider the encryption solutions other security vendors offer. You can find several listed on our Windows 2000 Solutions Shopper site. Search for "encryption" to find related security products.

Also, consider using a laptop cable lock to secure the device when you can't guard it closely. In addition, you might want to install a utility such as Stealth Signal that can "phone home" when connected to the Internet to report a system's IP address, which you can use to help locate a stolen system. Until next time, have a great week.

End of Article



Reader Comments
Correct me if I'm worng, but the software-based "Phone Home" type of security will only work if they:
1) connect to the internet first
2) then attempt to log on.

If they attempt to log on without connecting to the internet, they most likely will reload the operating system to get use of the laptop and you will lose your software-based tracking solution.

Anonymous User December 29, 2004 (Article Rating: )


I know a lot of software companies now have BIOS level software that will reinstall itself, even if the OS is installed. I believe CompuTrace does this with it's security software.

peddietech April 21, 2009 (Article Rating: )


Yes, it does - you can get it at http://www.absolute.com/

rupertmastemynde August 06, 2009 (Article Rating: )


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Getting your iPhone to Sync with Exchange 2003

Follow these steps to use an iPhone with Exchange. ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...


Security Whitepapers Reducing the Costs and Risks of Branch Office Data Protection

Solving Desktop Management Challenges in Healthcare

Solving Desktop Management Challenges in Education

Related Events The Increasing Threat of Financially Motivated Data Theft

Introduction to Identity Lifecycle Manager "2"

SQL Server Security: How to Secure, Monitor & Audit Your Databases

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement