Re: An EFS encryption question.

Posted: 10-23-2008, 12:13 AM
Not a good idea.
The first time that you forget to import the PKCS#12 before you attempt to
access a file, a new EFS certificate will be generated
From that point on, all newly encrypted files will use the new default EFS
key
If you want to have the removal of the EFS certificate from software, then I
recommend you move to Vista and use a smart-card based EFS certificate
Brian

"bagassa" <not@available.com> wrote in message
news:e8Eqa9INJHA.5692@TK2MSFTNGP02.phx.gbl...
> Good afternoon everyone,
>
> What I like to do is lock some of my sensitive files using the windows EFS
> encryption so that if someone were to steal my computer and somehow hack
> the password into my account, they still would not be able to read the
> files.
>
> If I were to:
>
> 1. encrypt the files
> 2. then export the "encrypting file system" certificate from the
> certificate manager (in the personal folder) to a thumb drive (and a
> backup drive).
> 3. delete the certificate managers copy
> 4. Every time I want to access the files, I plug the thumb drive in, and
> use it to decrypt the files.
>
> Is this a good way to do it ? Any red flags here ?
>
> Thanks for your time and help
>
> Peter
>

Re: An EFS encryption question.


Responses to "Re: An EFS encryption question."

bagassa
Guest
Posts: n/a
 
An EFS encryption question.
Posted: 10-23-2008, 07:39 PM
Good afternoon everyone,

What I like to do is lock some of my sensitive files using the windows EFS
encryption so that if someone were to steal my computer and somehow hack the
password into my account, they still would not be able to read the files.

If I were to:

1. encrypt the files
2. then export the "encrypting file system" certificate from the certificate
manager (in the personal folder) to a thumb drive (and a backup drive).
3. delete the certificate managers copy
4. Every time I want to access the files, I plug the thumb drive in, and use
it to decrypt the files.

Is this a good way to do it ? Any red flags here ?

Thanks for your time and help

Peter

Brian Komar
Guest
Posts: n/a
 
Re: An EFS encryption question.
Posted: 10-23-2008, 08:38 PM
Inline...
"bagassa" <not@available.com> wrote in message
news:eFmgzvUNJHA.2824@TK2MSFTNGP06.phx.gbl...
> Good afternoon Brian,
>
> You raised a good point. Does this mean that the burglar who stole my
> computer and broke into my account could still read the files, simply
> because Windows will always make a new certificate ?
No. They would need access to the removed certificate's private key to open
previous files
>
> There is no registry change that can stop this automatic generation?
No. You need to read the whitepaper on how EFS works.
You could prevent the creation of self-signed EFS, but the client would
still either request a Basic EFS certificate or autoenroll another
certificate.

>
> About those smart card readers you mentioned. Where can I get a simple
> one at a reasonable price ?
You need three things:
1) Smart card
2) Smart card reader
3) Middleware/mini-driver
Google is your friend. Search for Gemalto


>
> Thanks for your time and input, Brian.
>
> Peter
>
> ========================================
>
>> Not a good idea.
>> The first time that you forget to import the PKCS#12 before you attempt
>> to access a file, a new EFS certificate will be generated
>> From that point on, all newly encrypted files will use the new default
>> EFS key
>> If you want to have the removal of the EFS certificate from software,
>> then I recommend you move to Vista and use a smart-card based EFS
>> certificate
>>
>> Brian
>>
> ========================================
>>>
>>> What I like to do is lock some of my sensitive files using the windows
>>> EFS encryption so that if someone were to steal my computer and somehow
>>> hack the password into my account, they still would not be able to read
>>> the files.
>>>
>>> If I were to:
>>>
>>> 1. encrypt the files
>>> 2. then export the "encrypting file system" certificate from the
>>> certificate manager (in the personal folder) to a thumb drive (and a
>>> backup drive).
>>> 3. delete the certificate managers copy
>>> 4. Every time I want to access the files, I plug the thumb drive in, and
>>> use it to decrypt the files.
>>>
>>> Is this a good way to do it ? Any red flags here ?
>>>
>>> Thanks for your time and help
>>>
>>> Peter
>
bagassa
Guest
Posts: n/a
 
Re: An EFS encryption question.
Posted: 10-24-2008, 06:09 PM
Good afternoon Brian,

You raised a good point. Does this mean that the burglar who stole my
computer and broke into my account could still read the files, simply
because Windows will always make a new certificate ?

There is no registry change that can stop this automatic generation?

About those smart card readers you mentioned. Where can I get a simple one
at a reasonable price ?

Thanks for your time and input, Brian.

Peter

========================================
> Not a good idea.
> The first time that you forget to import the PKCS#12 before you attempt to
> access a file, a new EFS certificate will be generated
> From that point on, all newly encrypted files will use the new default EFS
> key
> If you want to have the removal of the EFS certificate from software, then
> I recommend you move to Vista and use a smart-card based EFS certificate
>
> Brian
>
========================================
>>
>> What I like to do is lock some of my sensitive files using the windows
>> EFS encryption so that if someone were to steal my computer and somehow
>> hack the password into my account, they still would not be able to read
>> the files.
>>
>> If I were to:
>>
>> 1. encrypt the files
>> 2. then export the "encrypting file system" certificate from the
>> certificate manager (in the personal folder) to a thumb drive (and a
>> backup drive).
>> 3. delete the certificate managers copy
>> 4. Every time I want to access the files, I plug the thumb drive in, and
>> use it to decrypt the files.
>>
>> Is this a good way to do it ? Any red flags here ?
>>
>> Thanks for your time and help
>>
>> Peter
bagassa
Guest
Posts: n/a
 
Re: An EFS encryption question.
Posted: 10-26-2008, 06:03 PM
Last question Brian,

The only white paper I found on the MS website talks about security in
general, or about the BitLocker feature which I don't have (I have Vista
Business).

Can I get a link to that EFS white paper that you mentioned ?

Regards,

Peter

==========================
"Brian Komar" <brian.komar@nospam.identit.ca> wrote in message
news:%23Eyk8%23UNJHA.5232@TK2MSFTNGP05.phx.gbl...
> Inline...
>
>> Good afternoon Brian,
>>
>> You raised a good point. Does this mean that the burglar who stole my
>> computer and broke into my account could still read the files, simply
>> because Windows will always make a new certificate ?
> No. They would need access to the removed certificate's private key to
> open previous files
>
>>
>> There is no registry change that can stop this automatic generation?
> No. You need to read the whitepaper on how EFS works.
> You could prevent the creation of self-signed EFS, but the client would
> still either request a Basic EFS certificate or autoenroll another
> certificate.
>
>
>>
>> About those smart card readers you mentioned. Where can I get a simple
>> one at a reasonable price ?
> You need three things:
> 1) Smart card
> 2) Smart card reader
> 3) Middleware/mini-driver
> Google is your friend. Search for Gemalto
>
> Thanks for your time and input, Brian.
>
> Peter
>
GreenieLeBrun
Guest
Posts: n/a
 
Re: An EFS encryption question.
Posted: 10-28-2008, 12:33 AM


bagassa wrote:
> Last question Brian,
>
> The only white paper I found on the MS website talks about security in
> general, or about the BitLocker feature which I don't have (I have
> Vista Business).
>
> Can I get a link to that EFS white paper that you mentioned ?
>
> Regards,
>
> Peter
>
> ==========================
> "Brian Komar" <brian.komar@nospam.identit.ca> wrote in message
> news:%23Eyk8%23UNJHA.5232@TK2MSFTNGP05.phx.gbl...
>> Inline...
>>
>>> Good afternoon Brian,
>>>
>>> You raised a good point. Does this mean that the burglar who stole
>>> my computer and broke into my account could still read the files,
>>> simply because Windows will always make a new certificate ?
>> No. They would need access to the removed certificate's private key
>> to open previous files
>>
>>>
>>> There is no registry change that can stop this automatic generation?
>> No. You need to read the whitepaper on how EFS works.
>> You could prevent the creation of self-signed EFS, but the client
>> would still either request a Basic EFS certificate or autoenroll
>> another certificate.
>>
>>
>>>
>>> About those smart card readers you mentioned. Where can I get a
>>> simple one at a reasonable price ?
>> You need three things:
>> 1) Smart card
>> 2) Smart card reader
>> 3) Middleware/mini-driver
>> Google is your friend. Search for Gemalto
>>
>> Thanks for your time and input, Brian.
>>
>> Peter
These may help:-

The Encrypting File System
http://www.microsoft.com/technet/sec...hyetc/efs.mspx

Best practices for the Encrypting File System
http://support.microsoft.com/kb/223316/en-us


 
LinkBack Thread Tools Display Modes
 


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


Similar Threads
Thread Thread Starter Forum Replies Last Post
encryption/firewall question r.e.s. Windows XP Security & Administration 7 11-24-2003 05:08 AM
xp encryption Windows XP Security & Administration 2 11-15-2003 06:17 PM
XP-Pro encryption Ralph Newton Windows XP Hardware 0 09-09-2003 12:33 AM
WIN XP PRO File Encryption Question Roger Abell Windows XP Security & Administration 1 08-31-2003 07:15 AM
WEP encryption davy van den broeck Windows XP Network & Web 0 07-25-2003 09:04 AM