Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: data protection in the hard-drive
From: "Marcus J. Ranum" <mjr @ nfr . net>
Organization: Network Flight Recorder, Inc.
Date: Thu, 28 Aug 1997 08:45:28 +0000
To: Firewalls @ GreatCircle . COM
Cc: Zoltan . KINCZLI @ Synergon . hu
Comments: Authenticated sender is <mjr @ mail . clark . net . >
In-reply-to: <199708280420 . VAA20929 @ honor . greatcircle . com>
Reply-to: mjr @ clark . net

Zoltan .
 KINCZLI @
 Synergon .
 hu writes:


>  My concern is confidental data stored on a PC hard-drive,
> but the PC is in a physically unprotected area. Software
> protection (like PGP) from security point of view would be 
> acceptable: but it needs user co-operation and this is the 
> problem here... we can't relay on users' co-operation 

It sounds like you're worried about their stealing your
data. Years ago I was involved with such a situation,
in which a consultant was holding a friend's database
for ransom. We hooked kermit up into a session log
and a query loop and sucked the database dry, then
it was easy to parse the session log and recover the
database. If you don't trust your "friends" not to take
the data from the hard disk, they could easily enough
grab things from the video controller or any of a number
of other points in the system.

I don't know about protection at the disk controller, but
there are packages for DOS (which may be available
for W95) like Fischer Int'l "Watchdog" that encrypt the
hard disk, make it non-bootable (encrypted boot block)
without a password, and un-mountable (encrypted FAT)
from standalone. They also support a notion of an
"administrator mode" which can control the overall
settings of the system such as keying, file write permissions,
etc. I think newer versions let you use an external key,
giving dongle-like protection.

This isn't a product plug for "Watchdog" -- I last used it
4 years ago, and I know it does what you're asking about.
I'm sure there are other products on the market.

mjr.
-----
Marcus J. Ranum, CEO, Network Flight Recorder, Inc.
<A HREF=http://www.clark.net/pub/mjr>Personal</A>
<A HREF=http://www.nfr.net>Work</A>
<A HREF=http://www.clark.net/pub/mjr/websec>New Book!!</A>


Indexed By Date Previous: Re: RADIUS for NT?
From: "Konstantin Yarchuk" <kyar @ it . ru>
Next: Re: CLUSTERED FIREWALLS
From: Dennis_Gnatowski @ USFG . COM
Indexed By Thread Previous: RE: data protection in the hard-drive
From: Erick Alejandro Villarreal Gálvez <evillarreal @ scanda . com . mx>
Next: Re: -->Firewalls-Digest V6 #394
From: Da Vinci Assistant <-ASSIST- @ SCBSING . MHS . CompuServe . COM>

Google
 
Search Internet Search www.greatcircle.com