Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Backing up Bitlocker Encrypted Drive Equals Not Encrypted

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 03-03-2007   #1 (permalink)
markbyrn
Guest


 

Backing up Bitlocker Encrypted Drive Equals Not Encrypted

When attempting to use the backup utility on the Bitlocker protected
drive, the following informative notification is received:

"You have chosen to backup disk C: which is encrypted. The backup
location will not be encrypted. Make sure the backup is kept in a
physically secure location."

One doesn't need to be a security guru to realize the inherent
weakness in making non-encrypted backups of your encrypted data. So
the options are to either user use a third party program like
DriveCrypt (or TrueCrypt when they have a Vista ready release) to
secure the backup drive or not backup at all. If you choose the
former option, you don't need Bitlocker and the latter option is
untenable. Of all the Ultimate Extra's, I was hoping Bitlocker would
save the day. Oh well.


My System SpecsSystem Spec
Old 03-03-2007   #2 (permalink)
Jupiter Jones [MVP]
Guest


 

Re: Backing up Bitlocker Encrypted Drive Equals Not Encrypted

The weakness you refer is eliminated by "kept in a physically secure
location."
There is no weakness if the data is properly secured.
The security required depends on the sensitivity of the data.
Many use a safe deposit box or other off site secure location.
For less sensitive, some use something as simple as a locked filing
cabinet.

--
Jupiter Jones [MVP]
http://www3.telus.net/dandemar
http://www.dts-l.org


"markbyrn" <markbyrn@gmail.com> wrote in message
news:1172977195.168096.65390@t69g2000cwt.googlegroups.com...
> When attempting to use the backup utility on the Bitlocker protected
> drive, the following informative notification is received:
>
> "You have chosen to backup disk C: which is encrypted. The backup
> location will not be encrypted. Make sure the backup is kept in a
> physically secure location."
>
> One doesn't need to be a security guru to realize the inherent
> weakness in making non-encrypted backups of your encrypted data. So
> the options are to either user use a third party program like
> DriveCrypt (or TrueCrypt when they have a Vista ready release) to
> secure the backup drive or not backup at all. If you choose the
> former option, you don't need Bitlocker and the latter option is
> untenable. Of all the Ultimate Extra's, I was hoping Bitlocker
> would
> save the day. Oh well.


My System SpecsSystem Spec
Old 03-04-2007   #3 (permalink)
Robert Moir
Guest


 

Re: Backing up Bitlocker Encrypted Drive Equals Not Encrypted


"markbyrn" <markbyrn@gmail.com> wrote in message
news:1172977195.168096.65390@t69g2000cwt.googlegroups.com...
> One doesn't need to be a security guru to realize the inherent
> weakness in making non-encrypted backups of your encrypted data.


So it's a good thing the backup program warned you about it and told you to
store your backups in a physically secure location, right?

> So
> the options are to either user use a third party program like
> DriveCrypt (or TrueCrypt when they have a Vista ready release) to
> secure the backup drive or not backup at all. If you choose the
> former option, you don't need Bitlocker and the latter option is
> untenable. Of all the Ultimate Extra's, I was hoping Bitlocker would
> save the day. Oh well.


Actually it isn't that simple at all. To backup with encryption, either the
backup program stores the encryption keys/details with the backup which
would take us back to the backup being insecure unless it's stored in a
physically secure location, or you rely on setting a password to secure the
backups which means you're at the mercy of the user a) setting a good
password to begin with and b) not forgetting it. Past experience suggests
that people will manage to fall down on both those conditions, picking a
weak and easy to crack password, forget it, then whinge like hell about it
prompting someone to write a "password recovery" tool which can then easily
be subverted for malicious purposes.

Or you can fail to worry about any of that, in which case you don't have a
proper backup suitable for DR purposes because it doesn't worry about
backing up anything required to re-create the encrypted state of the data,
just the data in encrypted format. Hence it relies on the computer it was
backed up from being in perfect working order when a restore is needed.
Great for people who delete files by mistake and want to restore them but
lousy for someone whose computer did a halt and catch fire and who needs to
restore their data to a new machine.

Life is full of compromises. How to deal with backing up encrypted data is
just another set of compromises to be worked out.

--
Robert Moir
http://www.rhymeswithgeek.com


My System SpecsSystem Spec
Old 03-18-2007   #4 (permalink)
Jeffery Jones
Guest


 

Re: Backing up Bitlocker Encrypted Drive Equals Not Encrypted

On 3 Mar 2007 18:59:55 -0800, "markbyrn" <markbyrn@gmail.com> wrote:

>"You have chosen to backup disk C: which is encrypted. The backup
>location will not be encrypted. Make sure the backup is kept in a
>physically secure location."
>
>One doesn't need to be a security guru to realize the inherent
>weakness in making non-encrypted backups of your encrypted data. So
>the options are to either user use a third party program like
>DriveCrypt (or TrueCrypt when they have a Vista ready release) to
>secure the backup drive or not backup at all.


How about EFS for the backup media?
My System SpecsSystem Spec
Old 03-18-2007   #5 (permalink)
Guest


 

Re: Backing up Bitlocker Encrypted Drive Equals Not Encrypted

"Jeffery Jones" <keineverbung@newsgroups.nospam> wrote in message
news:gvpqv294d4c9a1s5hen0l17vb6f8ni1981@4ax.com...
> On 3 Mar 2007 18:59:55 -0800, "markbyrn" <markbyrn@gmail.com> wrote:
>
>>"You have chosen to backup disk C: which is encrypted. The backup
>>location will not be encrypted. Make sure the backup is kept in a
>>physically secure location."
>>
>>One doesn't need to be a security guru to realize the inherent
>>weakness in making non-encrypted backups of your encrypted data. So
>>the options are to either user use a third party program like
>>DriveCrypt (or TrueCrypt when they have a Vista ready release) to
>>secure the backup drive or not backup at all.

>
> How about EFS for the backup media?



Also, if the backup target drive is a USB external hard drive, you can use
manage-bde.wsf to enable BitLocker on the external hard drive.

Then you simply have the issue of how to keep your keys backed up.

Alun.
~~~~
--
Texas Imperial Software | Web: http://www.wftpd.com/
23921 57th Ave SE | Blog: http://msmvps.com/alunj/
Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.


My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
Need to recover encrypted files from Windows XP drive owlfan12000 Vista security 4 04-24-2008 07:22 PM
Encrypted Files Bob Vista file management 0 01-17-2008 07:29 AM
Moving "Documents" to encrypted drive (worked in XP) ceed Vista General 8 07-28-2007 12:57 PM
ruined Pointsec encrypted drive with Vista installation rschatz Vista installation & setup 1 06-30-2006 03:23 PM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51