Showing posts with label Encryption. Show all posts
Showing posts with label Encryption. Show all posts

Tuesday, May 22, 2012

bench3

Prevent Accidental Printing Copying Or Forwarding Confidential Documents

Often, users need to share confidential documents to collaborate efficiently. For example, a user might e-mail a document to another user for review. However, when the document is copied from your protected shared folder or intranet, you lose control of the document. Users might accidentally copy, forward, or print the document, where it can be found by a user who shouldn’t have access.

There’s no perfect solution to protect electronic documents from copying. However, the Windows Rights Management Services (RMS) client, built into Windows Vista and Windows 7, enables computers to open RMS-encrypted documents and enforce the restrictions applied to the document. With an RMS infrastructure and an application that supports RMS, such as Microsoft Office, you can:
  • Allow a user to view a document but not save a copy of it, print it, or forward it.
  • Restrict users from copying and pasting text within a document.
  • Make it very difficult to open the document using a client that does not enforce RMS protection.
Windows 7 provides built-in support for using RMS to protect XML Paper Specification (XPS) documents. To use RMS, you need an RMS infrastructure and supported applications in addition to Windows Vista or Windows 7.
Read More

Wednesday, April 6, 2011

bench3

Encrypting USB Thumb Drive Using BitLocker

BitLocker Drive Encryption is a new feature that provides protection for operating hard drives, external drives, and removable data drives in case they are lost or stolen. BitLocker is a way of encrypting the data on drives and requiring authentication to access the information.

BitLocker encrypts your drives so others cannot access them without a password. BitLocker comes in two flavors in Windows 7 which are BitLocker and BitLock To Go.

You can also force the PC to book from an encryption key on a USB flash drive. You can insert the USB flash drive into the computer during startup to allow it to boot. The USB flash drive is used to unlock the computer.

When enabling BitLocker on a hard drive or removable drives, BitLocker can use the following unlock methods:

Password: You can use a password to unlock your BitLocker encrypted data drives and Group Policy settings can be used to set minimum password lengths.

Smart card: BitLocker allows you to use a compatible certificate on your smart card. By default, BitLocker will choose the certificate unless you have multiple compatible certificates, in which case you must choose the certificate to use.

BitLocker To Go was specially created to encrypt the data on your portable media. With an increasing number of key drives being used, the loss of sensitive data is becoming more of a threat.

Steps Involved In Encrypting Thumb Drive:

To encrypt your thumb drive, do the following:

You should plug your thumb drive into a USB port,

Click the Start button, type BitLocker, and click on BitLocker Drive Encryption.

Encrypting USB Or Flash Thumb Drive 1

Next to your drive letter of your thumb drive, click Turn on BitLocker as shown in figure above.

Encrypting USB Or Flash Thumb Drive 2

Choose a password and click Continue as shown in figure above.

You will be given the option to save your recovery key (used if you forget your password) or print it. If you save the file, ensure the file is stored somewhere safe and then click Next as shown in figure below

Encrypting USB Or Flash Thumb Drive 3

You will then need to confirm your chosen settings, the password and click
Start Encrypting as shown in figure below.

Encrypting USB Or Flash Thumb Drive 4

After you click Start Encrypting you will see the screen in figure below.

Encrypting USB Or Flash Thumb Drive 5

Please notice the figure above where it warns that large drives may take quite a while.

Now that I am done, I am going to try and access the drive I just encrypted.

Encrypting USB Or Flash Thumb Drive 6

As soon as I try a new screen appears asking me to enter a password before I can access the drive as shown in figure above.

Read More

Tuesday, April 5, 2011

bench3

Storing More Than One BitLocker Recovery Keys In Single USB

Scenario: I have enabled BitLocker on both my internal HDDs, all seems to be well. I was wondering if I could consolidate all the recovery keys on to a single USB drive. From what I can see the file names are all different, but would the OS pickup the correct files if I need run recovery?

Solution: The USB stick will become a single point of failure in this scenario. Windows is made to pickup the correct files even when you have more than one recovery key. However, Perhaps storing the BitLocker and TPM recovery information in Active Directory is a better choice?

If you are using a stand-alone machine and if you are not concerned about TPM nor when you are not having access to an Active Directory.

If you were considering storing the recovery keys on a single USB stick. Windows will get to the correct files in a recovery situation if the recovery keys for multiple disks were stored together on the same USB stick.

Read More

Sunday, January 23, 2011

bench3

Use Of AppLocker | File Security And Encryption In Windows 7

Windows 7 is full of ways to protect yourself when you are using your computer. There are so many threats out there that it is important to be proactive and educated on possible threats to your computer and do what you can to detect and prevent them.

AppLocker

AppLocker as shown in Screen Shot below, it is a new application control feature available in Microsoft Windows 7 that helps eliminate unwanted and unknown applications within an organization’s network  to providing a much more productive and secure environment.

Use Of AppLocker  File Security And Encryption In Windows 7  1

AppLocker answers the need for application control with a simple and flexible application that allows administrators to specify exactly what is allowed to run
on the computer in their network environment. There are many benefits to using AppLocker in your network such as:

  • Stop unlicensed software from being installed or run in your environment.
  • Preventing vulnerable, unauthorized applications from being installed or run in your environment.
  • Prevent user from running applications which waste time.
  • Stopping users from running applications that needlessly consume network bandwidth.
  • Preventing users from running applications that possible contain viruses or malware.
  • Allow users to install and run software and updates based upon their business needs
  • Ensure compliance of corporate policies and industry regulations for PCI DSS, Sarbanes-Oxley, HIPAA, Basel II, and state identity theft protection acts.
  • Reduce the cost of repair for users who install software which causes their PC to have issues or infects other devices in the network.

AppLocker provides a powerful solution using three rule types: allow, deny, and exception. Allow rules limit execution of applications to a "good list" of programs and applications. Deny rules take the opposite approach and disallow all programs and applications on the “bad list”. Exception rules allow you to exclude files from an allow/deny rule that would normally be included such as a rule to “allow everything in the Windows Operating System to run, except the built-in games.”

Use Of AppLocker  File Security And Encryption In Windows 7  2

AppLocker is configured in the Group Policy Editor in Local Computer Policy, Security Settings, Application Control Policies, and then AppLocker as shown in screenshot above. In the below screenshot you will see the options that you can configure for AppLocker.

Use Of AppLocker  File Security And Encryption In Windows 7 3

Read More

Monday, January 17, 2011

bench3

What Are The Improvements Of Windows 7 Over Vista

The prospect of migrating an entire company to a new operating system is almost always a daunting venture. You'll need to make sure you get a return on the significant investment that you'll make in the product itself. The staff, time and resources needed to install it and work out the inevitable kinks.

Windows 7 has changed the name, look, feel, features, speed, and even the logo’s to part ways with Vista because of the bad vibes that still resonate. Windows Vista met with almost immediate critical disapproval when it was released in January 2007.

To be fair, Vista had many improvements over the XP operating system, including better security, file sharing, and search capabilities. But those were largely overshadowed by its shortcomings: constant security pop ups, excessive use of RAM, an overly aggressive User Account Control (UAC) feature, hardware incompatibility, and more.

Now comes Windows 7 and if the early reviews are any gauge including my review, Microsoft appears to have ironed out many of the issues that haunted Vista. In fact, some reviewers including myself feel it is the best Microsoft Operating System ever produced.
Windows 7 Improvements Over VistaImproved security 
Security is always a big issue with Windows. Witness the flurry of activity and tension that surrounds the typical Patch Tuesday. Windows 7 addresses the issue with a number of security upgrades. Microsoft has added the BitLocker full-volume encryption feature that came out with Vista. The Windows 7 version still uses a 128-bit or 256-bit AES encryption algorithm, but is now more flexible and simplifies drive encryption by automatically creating hidden boot partitions.

The result, users no longer need to repartition their drives after installation. And where Vista users required a unique recovery key for each protected volume, Windows 7 users only need a single encryption key. A new feature called “BitLocker To Go” lets users encrypt removable storage devices with a password or a digital certificate. 

New improvements for IT administrators
A plethora of new options that make life easier for IT professionals as shown below:
  • AppLocker: This new feature is a control policy that allows administrators to precisely spell out what applications users can run on their desktops. It  can also be used to block unauthorized or unlicensed software and pplications.
  • Multiple Active Firewall Policies: This feature provides a big improvement over Vista, which automatically set firewall policies depending on the type of network connection you chose such as home, public, or work. Remote Vista users couldn’t connect to multiple networks while on the road, or if someone working from home used a VPN, he or she couldn't apply settings to connect to the corporate network. Windows 7's Multiple Active Firewall Policies allows IT professionals to create multiple sets of rules for remote and desktop employees. 

  • DirectAccess: A feature provides a secure way to manage and update individual PCs remotely. It uses IPv6 and IPSec protocols to create a secure, two-way connection from a remote user's PC to the corporate network. Users benefit by not having to manually set up VPN connections and IT professionals enjoy the ease of distributing patches and updates whenever remote workers are connected to the network. 

  • Improved Windows Search: Is a new feature which allows for faster more thorough searches, and also provides IT administrators with better per-user policy oversight and the ability to manage resource utilization by controlling how desktop search accesses network resources. Additional improvements were the seek-and-find capabilities with Federated Search, which combines desktop, SharePoint, and Internet search methods and allows users to scan external hard drives, networked PCs, and even remote data sources. Another new feature enables the user to search for identical copies of files on drives.

  • Upgraded Windows Recovery Environment: A feature Microsoft introduced in Vista and was a replacement of the Recovery Console in Windows XP. The new upgrade allows users to perform a range of system and data recovery functions, including checking for defective memory, repairing boot-level startup issues, returning the system to earlier configurations.
AeroSnap Desktop Feature
This is a new feature of Windows desktop. If you pull a window to either edge of the desktop, it automatically makes each screen half the screen and compares the two windows side by side. 

AeroPeek Desktop Feature
This is another new feature of Windows desktop. In XP and Vista you had a button to minimize all the windows and see the desktop. The problem was that all the windows you had minimized you then had to maximize one by one. The new button to the right of the clock makes all the windows invisible when  pushed. You can even click on desktop items and open them. Press the button again and all your open windows come back the way they were before you pressed the button. 

Improved Backup Utility
This improved backup utility now gives users control over which folders they want to back up which was a restriction in Vista, which allowed backups on a per-volume basis only.

Windows XP Mode and Windows Virtual PC
These two new features address issues of incompatibility for applications designed to run older XP applications. This shows Microsoft is intent on retiring XP as a supported product in the near future.
Read More

Saturday, January 15, 2011

bench3

Encrypt And Decrypt From The Shortcut Menu In Windows

As you know, one of the perks of using Windows 7 (Professional, Enterprise, or Ultimate) is that you can encrypt files and folders, protecting them from people who try to open them from across the network or using a different account. If you use this feature quite a bit, however, you’ll quickly grow tired of opening the Properties box every time you want to encrypt something. Wouldn’t it be much more convenient if the Encrypt and Decrypt commands were right there in the shortcut menu that appears when you right-click an icon? Of course it would. To make it so, do this:

Warning: before you try to modify windows registry, learn how to backup windows registry. Also try to have a backup of your registry at this stage before you proceed. Read More On How To Backup Windows Registry.

  • Navigate to: HKEY_CURRENT_USER->Software->Microsoft->Windows->CurrentVersion->Explorer->Advanced.

Now, for this trick, you’re going to need a key that doesn’t actually exist yet. Fortunately, it’s very easy to create a new key.  In this case,

  1. Just right-click the Advanced “folder,” and then,
  2. From the shortcut menu, choose New->DWORD (32-bit) Value. You see “New Value #1” appear in the right side of the window, ready to be renamed;
  3. Type EncryptionContextMenu, and then press Enter.

The birth of a new Registry entry is a good opportunity to name it, but you can rename any value or key at any time, just the way you’d rename a file icon. That is, you can open the renaming rectangle by right-clicking or by pressing F2.

  • Double-click this value on the right side: EncryptionContextMenu.
  • Make this change: In the “Value data” box, type 1.
  • Wrap up: Click OK and quit regedit.

When you right-click any file or folder icon, you’ll see the new Encrypt command in the shortcut menu. (Or, if it’s already encrypted, you’ll see a Decrypt command.)

Read More