Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • PC Hardware

    Can Microsofts Bitlocker Save Us from Ourselves?

    Written by

    John G. Spooner
    Published May 30, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Microsoft is making it much more difficult to access and steal a businesss vital data from one of its PCs.

      The giant software maker will deliver Bitlocker, a hard drive encryption tool, as part of its forthcoming Windows Vista operating system, which is now in its second beta and is due to large businesses in November. Bitlocker, which will come with Windows Vista Enterprise and Ultimate editions, can be used to encrypt an entire hard drive, making it more difficult for someone to access the computers data if it is lost or stolen.

      Microsoft believes that Bitlocker will help companies guard against accidental loss—where a PC, as well as a server in many cases, is lost or possibly disposed of without its drive being wiped—inappropriate access by company employees and even theft from individuals interested in a PC for its data. Despite the fact that hard drive encryption tools already exist, the act of including Bitlocker with Windows Vista—and integrating the tool with its Active Directory for things like automatically storing backup encryption keys—could get more businesses thinking about encrypting their PC hard drives, due to security concerns, industry watchers said.

      Indeed, “One of my most favorite [new features] now in Windows Vista is Bitlocker Drive Encryption. Why is that? Its going to secure the information on a hard disk, whether its in a laptop or a desktop PC, and if [a PC] is stolen nobody can get the data off of it,” said Will Poole, senior vice president of Microsofts Market Expansion Group, during a WinHEC keynote address on May 23 in Seattle. “I personally burned the better part of a perfectly nice Saturday just a few weeks ago, after being informed by a financial services company in New York that a PC had been stolen from their office that had my name, account information and Social Security number on it.”

      The availability of Bitlocker would have had made it harder for someone to access the data resident on the stolen machine, Poole said.

      Although Bitlocker has not yet been tested widely given that Vista is still in beta, security industry watchers agreed that, at a minimum, the wider availability of hard drive encryption tools is a good step for companies looking to beef up their data security.

      But security expert Bruce Schneier, chief technology officer at Mountain View, Calif.-based Counterpane Internet Security, warned that Bitlocker is not a panacea, but just one of several steps needed to keep data secure.

      “In security, the devil is in the details,” Schneier said. Still, “at the level Ive read, [Bitlocker] seems well-designed.”

      /zimages/2/28571.gifIs Windows Vista soup yet? Click here to read what beta testers have to say.

      Just like with any other software product, flaws are likely to crop up from time to time and require fixing, he said.

      Bitlocker, Microsoft officials said, is capable of working either with or without a TPM (Trusted Platform Module) security chip. But they said they consider the encryption tool to be at its best when it can take advantage of the combination of a TPM 1.2-specification chip and a secure BIOS.

      With a TPM present, Bitlocker uses the chip to generate cryptographic keys based on scans of core system files—things like the master boot record—in addition to a key for the hard drive itself. The drives entire volume, including the operating system, page file, temporary files, hibernation volume, user data and blank space, are all encrypted by Bitlocker, said Shon Eizenhoefer, a Microsoft program manager, during a May 24 presentation at WinHEC.

      Later, if one of the core files is discovered to have been changed or replaced—an indication that a machine may have been tampered with or its hard drive removed in an effort to access its data—Bitlocker will not release any of the keys in preboot and thus the data stays encrypted, Eizenhoefer said.

      /zimages/2/135889.jpg

      “After the first time, every time you turn on machine, it makes sure that current measurements match, so that if someone tries to hack with a BIOS or an [external] drive … the TPM can detect it and wont release the keys to the rest of the OS.”

      Setting up Bitlocker requires a few clicks into Vistas security control panel and then a few more to set up the feature. Bitlocker allows users to log in and access their machines in several ways, including placing a log-in key on a USB (Universal Serial Bus) drive, creating a PIN (personal identification number) or using only a TPM.

      Using a TPM with a USB key is the most secure method—assuming a person doesnt carry that key in the same case as his or her laptop—but presents the possibility of lost or stolen USB keys. PINs can also be lost or stolen. Meanwhile, simply using a TPM is most convenient, but more defeatable in that it only takes cracking a systems password to gain access to its data.

      “TPM-only provides a clear advantage in that its transparent to the user,” Eizenhoefer said. “They dont even need to know its there … and, at the very least, that TPM protection provides a very significant layer of protection to help protect that data.”

      /zimages/2/28571.gifMicrosoft has a lot more security credibility these days than it had a few years ago. Click here to read more.

      To deal with lost or forgotten PINs, Bitlocker offers a recovery key, which can be saved to a file, printed, or stored on the Web or in an Active Directly server for domain-joined business machines.

      But, despite the advantages of hard drive encryption, there are still some concerns among security experts about Bitlocker and how it may be used.

      “The fear is this is an entry into a very restrictive DRM [digital rights management] system,” Schneier said. “Thats down the road. We have to watch and make sure Microsoft cant abuse this technology.”

      Others are concerned that Bitlocker might not follow industry-standard specifications.

      “My hackles are up just slightly when the industry goes in multiple directions at the same time,” said Roger Kay, president of EndPoint Technologies Associates in Wayland, Mass. “Microsoft is particularly well-known for doing that. They sort of show up to every standards group, but when it comes to productization, they do it their own way.”

      The one-time adoption of a single method by the PC industry would be more favorable.

      However, there is something to be said for quicker time-to-market, Kay said.

      “Theyre not entirely wrong. They put out functionality, they can get it out quickly,” he added. “The TCG [Trusted Computing Group] is still sort of fiddling around” with an effort to create a hard drive encryption standard of its own.

      /zimages/2/28571.gifCheck out eWEEK.coms for Microsoft and Windows news, views and analysis.

      John G. Spooner
      John G. Spooner
      John G. Spooner, a senior writer for eWeek, chronicles the PC industry, in addition to covering semiconductors and, on occasion, automotive technology. Prior to joining eWeek in 2005, Mr. Spooner spent more than four years as a staff writer for CNET News.com, where he covered computer hardware. He has also worked as a staff writer for ZDNET News.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×