Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista - Bitlocker swap file

Reply
 
Old 12-11-2006   #1 (permalink)
lvjobhunt


 
 

Bitlocker swap file

Does bitlocker ecrypt the swap file? Is there anything on a bitlocker driver
that can be recovered?

How does this compare to freeware like compusec.

My System SpecsSystem Spec
Old 12-11-2006   #2 (permalink)


 
 

BitLocker Encrypts (almost) all sectors on the whole volume, including the swap file, hibernation file and unallocated/free space.

It is the newest and best encryption software. Very sound cryptographically. Very good for a domain beacuse it can escrow the computer key into the Active Directory.
It is very well made.

Nik
My System SpecsSystem Spec
Old 12-11-2006   #3 (permalink)
Jamie Hunter [MS]


 
 

Re: Bitlocker swap file

BitLocker encrypts the page file (swap file), and even encrypts crash-dump
files and hibernation files (things often overlooked). Only the boot files
and portions of metadata are in clear text, none of which provide any
sensitive information.

Because BitLocker was designed in conjunction with Vista, these special
files are handled seamlessly, allowing all the OS functionality you would
expect... securely without requiring special workarounds.

When BitLocker is enabled, it encrypts the volume carefully to ensure that
no data is left unencrypted, and to ensure that if the computer crashes in
the middle of conversion of the volume, it is recoverable.

As I've never installed CompuSec, I can't give you a comparison, but why not
try both out and see which meets your needs better?

Things to consider when comparing products, for example, is if you use a
user-remembered password for boot authentication, how easy is it to crack?
When using TPM+PIN, then the TPM hardware helps mitigate brute-force
attacks, making an easily remembered PIN harder to crack than many password
solutions. The TPM also detects tampering of pre-boot files.

-
Jamie Hunter [MS]

"lvjobhunt" <lvjobhunt@discussions.microsoft.com> wrote in message
news3186967-544F-4776-9FFA-8A123A438E28@microsoft.com...
> Does bitlocker ecrypt the swap file? Is there anything on a bitlocker
> driver
> that can be recovered?
>
> How does this compare to freeware like compusec.


My System SpecsSystem Spec
Old 12-12-2006   #4 (permalink)
Roof Fiddler


 
 

Re: Bitlocker swap file

"Jamie Hunter [MS]" <jamiehun@nospam.microsoft.com> wrote in message
news:E830023B-789D-4F6C-ACF5-B9D6D55B02F3@microsoft.com...
> portions of metadata are in clear text

Which portions exactly?

My System SpecsSystem Spec
Old 12-12-2006   #5 (permalink)


 
 

The three .fve blob in system volume information. when you read those under a live system they are filled with \x00.
The $Boot file is also not encrypted. There are probably other boot files.
How does BitLocker know which files are encrypted and which are not?
My System SpecsSystem Spec
Old 12-12-2006   #6 (permalink)
Jamie Hunter [MS]


 
 

Re: Bitlocker swap file

Specifically $BOOT is the first 8K of the disk, and contains information
such as file-system size; unused boot code; and some "snapshot" information.
It also points to the first copy of BitLocker metadata (see
http://blogs.msdn.com/si_team/archiv...itlocker.aspx).
Each copy of metadata (shadowed by the three .fve files in system volume
information) point to each other. The primary structure is decrypted, but
contains encrypted components. The entire structure has a MAC (Message
Authenticity Check).
The final piece of decrypted data is the backup boot sector at the end of
the volume immediately after the file-system. That's 5 decrypted and easily
identifiable regions in total. None of which contain sensitive information.

An example of decrypted data in the metadata is a label that helps identify
the volume and key labels to help find the recovery key.
An example of encrypted data in the metadata is the VMK (Volume Master Key)
encrypted by an externally provided (or TPM provided) key; and the FVEK
(Full Volume Encryption Key) encrypted by the VMK.

Hope this helps?
-
Jamie Hunter [MS]

"niknik" <niknik.2ipsca@no-mx.vista64.net> wrote in message
news:niknik.2ipsca@no-mx.vista64.net...
>
> The three .fve blob in system volume information. when you read those
> under a live system they are filled with \x00.
> The $Boot file is also not encrypted. There are probably other boot
> files.
> How does BitLocker know which files are encrypted and which are not?
>
>
> --
> niknik
> ------------------------------------------------------------------------
> niknik's Profile: http://vista64.net/forums/member.php?userid=637
> View this thread: http://vista64.net/forums/showthread.php?t=29093
>


My System SpecsSystem Spec
Old 12-12-2006   #7 (permalink)


 
 

Yes - this completely answers my last question.

I guess since BitLocker is a Full Volume Encryption (hence the .FVE extension) it only encrypts the OS volume and not the BCD partition needed for the booting or any other partitions.

Does BitLocker support external volumes yet?


Thank you.
My System SpecsSystem Spec
Old 12-12-2006   #8 (permalink)
Josh


 
 

Re: Bitlocker swap file

you can encrypt other volumes if you use the managebde script. Tread
lightly however is my best advice as you really need to understand what you
are doing here to do it correctly. Be sure to escrow that key.

--
Josh
http://windowsconnected.com

"niknik" <niknik.2iqeln@no-mx.vista64.net> wrote in message
news:niknik.2iqeln@no-mx.vista64.net...
>
> Yes - this completely answers my last question.
>
> I guess since BitLocker is a Full Volume Encryption (hence the .FVE
> extension) it only encrypts the OS volume and not the BCD partition
> needed for the booting or any other partitions.
>
> Does BitLocker support external volumes yet?
>
>
> Thank you.
>
>
> --
> niknik
> ------------------------------------------------------------------------
> niknik's Profile: http://vista64.net/forums/member.php?userid=637
> View this thread: http://vista64.net/forums/showthread.php?t=29093
>


My System SpecsSystem Spec
Old 12-13-2006   #9 (permalink)


 
 

Thank you!
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Using swap file or not for VM Virtual PC
swap file priority Vista performance & maintenance
Swap file on USB flash drive? Vista hardware & devices
Vista Swap File? Vista General
swap file Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46