Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

[BitLocker:] One USB key for more than one computer

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 02-12-2007   #11 (permalink)
Jamie Hunter [MS]
Guest


 

Re: [BitLocker:] One USB key for more than one computer

USB+PIN (without a TPM) is not secure. I've posted about this somewhere
before, but basically without the anti-hammering ability of a TPM, a PIN can
trivially (within a few days) be cracked brute-force negating any benefit of
having it.

I considered it, then Niels (the cryptographer) gave me a reality check
-
Jamie Hunter [MS]

"Alun Jones [MS-MVP - Windows Security]" <alun@texis.invalid> wrote in
message news:aPadnVnv2sl16FLYnZ2dnUVZ_hOdnZ2d@comcast.com...
> "Paul Adare" <padare@newsguy.com> wrote in message
> news:MPG.202fc3d9eacff16998a3d7@msnews.microsoft.com...
>> In article <72FF4DFD-2112-4A3D-9AD7-F02B308B5FE1@microsoft.com>,
>> in the microsoft.public.windows.vista.security news group, =?
>> Utf-8?B?Sm9uYXRoYW4gU2Nod2FydHogMg==?= <JonathanSchwartz2
>> @discussions.microsoft.com> says...
>>
>>> Hello Thomas D.,
>>>
>>> First, a TPM Module is -not- absolutely necessary.
>>>
>>> Second, must have one TPM+PIN+USB-key for each HDD that has BitLocker
>>> Activated. <(that statement is greatly condensed!)

>>
>> This is wrong. In the first place, you can't currently use both
>> a TPM with a PIN and store the encryption key on a USB disk. The
>> TPM+PIN+USB feature is being looked at for Vista SP1. Secondly,
>> if you're using a USB device to store the key, then you do not
>> need a separate USB device for each key. You can store multiple
>> keys on a single USB device.

>
>
> Please tell me they're also working on "PIN+USB" for those of us without a
> TPM in our existing laptops.
>
> I'm _so_ not going to tell my corporate masters that they need to replace
> several hundred laptops over the coming year before we implement Vista,
> not because they can't run Vista, but because Vista's implementation of
> BitLocker doesn't let them use a PIN without a TPM.
>
> Alun.
> ~~~~
> --
> Texas Imperial Software | Web: http://www.wftpd.com/
> 23921 57th Ave SE | Blog: http://msmvps.com/alunj/
> Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
> Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.
>
>



My System SpecsSystem Spec
Old 02-13-2007   #12 (permalink)
Junior Member


Join Date: Nov 2006
 
Rep Power: 15
niknik is on a distinguished road
  niknik is offline

USB+PIN (without a TPM)

>I considered it, then Niels (the cryptographer) gave me a reality check

Yes Niels really knows his stuff.

I'm convinced very soon we'll see 3rd party vendors providing smartcards + pin that integrate with bitlocker.
My System SpecsSystem Spec
Old 02-16-2007   #13 (permalink)
Alun Jones
Guest


 

Re: [BitLocker:] One USB key for more than one computer

"Jamie Hunter [MS]" <jamiehun@nospam.microsoft.com> wrote in message
news:0D62472A-A3E4-4CB3-B4CC-E03C2FA95072@microsoft.com...
> USB+PIN (without a TPM) is not secure. I've posted about this somewhere
> before, but basically without the anti-hammering ability of a TPM, a PIN
> can trivially (within a few days) be cracked brute-force negating any
> benefit of having it.
>
> I considered it, then Niels (the cryptographer) gave me a reality check


Pass this by Niels:

Many corporate laptops do not have a TPM chip, but need to be protected
against theft.

USB alone is somewhat secure, as long as you can persuade the users to
remove the USB keys. If the USB key is left with the laptop, and the pair is
stolen, there is no barrier to entry. A USB key can be trivially cracked
brute force by simply plugging it in when you boot.

USB plus a PIN is a higher barrier to entry than USB alone, and may be a
sufficiently high barrier to cause the thief to simply wipe the drive,
rather than try to whack his way through a PIN.

Replacing a company's entire fleet of laptops is unlikely to happen
immediately - wouldn't it be nice if your data on those laptops was
protected, even if only against the guy who doesn't have several days to
hack into it, until the spanking new laptops get deployed?

Sometimes it's difficult to remind cryptographers that "better than I have
right now" is often worth achieving, for people who find "best possible" to
be unobtainable.

Alun.
~~~~


My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
Restored Factory Settings on Laptop that had BitLocker - Now want to do bitlocker again Blake Mengotto Vista General 0 08-24-2008 04:39 PM
Bitlocker sync with XP computer on network waterguy Vista security 3 11-15-2007 03:36 AM
Bitlocker ; Do I need it If? PCfixinman Vista security 3 07-13-2007 12:34 AM
BitLocker. Eugene Pinero Vista security 5 05-08-2007 02:37 PM
Bitlocker killed my computer - no really! David Vista General 17 02-19-2007 06:42 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51