RE: Disk encryption killer: Anyone see this?

2012-12-24 Thread Ziots, Edward
killer: Anyone see this? Simple to get past the screensaver password then? -Original Message- From: Ziots, Edward [mailto:ezi...@lifespan.org] Sent: Friday, December 21, 2012 12:59 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? Its not hard to get

RE: Disk encryption killer: Anyone see this?

2012-12-23 Thread Ken Schaefer
Subject: Re: Disk encryption killer: Anyone see this? On Fri, Dec 21, 2012 at 7:20 PM, Ken Schaefer k...@adopenstatic.com wrote: Another option would be to trick the user into installing this software, or trick the user into somehow giving away access to the machine (aka these APTs we keep

Re: Disk encryption killer: Anyone see this?

2012-12-23 Thread Ben Scott
Good point. (Although I bet stealing the laptop would be prone to being uncovered, too. ;-) (Yes, I get that it's before vs after the data theft. :) ) ) On Sun, Dec 23, 2012 at 7:03 AM, Ken Schaefer k...@adopenstatic.com wrote: Do you mean, snag the clear-text version of the user's

RE: Disk encryption killer: Anyone see this?

2012-12-23 Thread Ken Schaefer
System Admin Issues Subject: Re: Disk encryption killer: Anyone see this? Good point. (Although I bet stealing the laptop would be prone to being uncovered, too. ;-) (Yes, I get that it's before vs after the data theft. :) ) ) On Sun, Dec 23, 2012 at 7:03 AM, Ken Schaefer k

Re: Disk encryption killer: Anyone see this?

2012-12-22 Thread Ben Scott
On Fri, Dec 21, 2012 at 7:20 PM, Ken Schaefer k...@adopenstatic.com wrote: Another option would be to trick the user into installing this software, or trick the user into somehow giving away access to the machine (aka these APTs we keep hearing about) and layering this on top. But if you

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Chinnery, Paul
Oh, great. I wonder what view CMS will take if a laptop is stolen\lost and it's encrypted. Will they still say it's a HIPAA violation? From: David Lum [mailto:david@nwea.org] Sent: Friday, December 21, 2012 12:29 PM To: NT System Admin Issues Subject: Disk encryption killer: Anyone see

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Ziots, Edward
Issues Subject: Disk encryption killer: Anyone see this? Comments anyone? Looks like bad news... http://thenextweb.com/insider/2012/12/20/this-299-tool-is-reportedly-cap able-of-cracking-bitlocker-pgp-and-truecrypt-disks-in-real-time/ David Lum Sr. Systems Engineer // NWEATM Office

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Ziots, Edward
+, Network + Security Engineer Lifespan Organization ezi...@lifespan.org From: Chinnery, Paul [mailto:pa...@mmcwm.com] Sent: Friday, December 21, 2012 12:37 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? Oh, great. I wonder what view CMS will take

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Steven Peck
...@lifespan.org ** ** *From:* Chinnery, Paul [mailto:pa...@mmcwm.com] *Sent:* Friday, December 21, 2012 12:37 PM *To:* NT System Admin Issues *Subject:* RE: Disk encryption killer: Anyone see this? ** ** Oh, great. I wonder what view CMS will take if a laptop is stolen\lost and it's

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Matthew W. Ross
...@lifespan.org] To: NT System Admin Issues [mailto:ntsysadmin@lyris.sunbelt-software.com] Sent: Fri, 21 Dec 2012 09:57:51 -0800 Subject: RE: Disk encryption killer: Anyone see this? I would say off the record no, if you used popular encryption software and a repeatable process, but when you lose

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Steve Kradel
System Admin Issues [mailto:ntsysadmin@lyris.sunbelt-software.com] Sent: Fri, 21 Dec 2012 09:57:51 -0800 Subject: RE: Disk encryption killer: Anyone see this? I would say off the record no, if you used popular encryption software and a repeatable process, but when you lose physical security

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Jonathan Link
-software.com] Sent: Fri, 21 Dec 2012 09:57:51 -0800 Subject: RE: Disk encryption killer: Anyone see this? I would say off the record no, if you used popular encryption software and a repeatable process, but when you lose physical security of an asset, given a reasonable amount of time

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Andrew S. Baker
E. Ziots, CISSP, Security +, Network + Security Engineer Lifespan Organization ezi...@lifespan.org From: Chinnery, Paul [mailto:pa...@mmcwm.com] Sent: Friday, December 21, 2012 12:37 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Ben Scott
On Fri, Dec 21, 2012 at 2:38 PM, Andrew S. Baker asbz...@gmail.com wrote: You could unlock my safe if I gave you the keys as well, which is all that is happening here. Even the bit about using the hibernation file is not worthy of the headline they provided... It's not like they're

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Jonathan Link
Sensationalist tech press is sensational? On Fri, Dec 21, 2012 at 2:47 PM, Ben Scott mailvor...@gmail.com wrote: On Fri, Dec 21, 2012 at 2:38 PM, Andrew S. Baker asbz...@gmail.com wrote: You could unlock my safe if I gave you the keys as well, which is all that is happening here. Even

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread David Lum
is encrypted, how do they get to it? Dave -Original Message- From: Steve Kradel [mailto:skra...@zetetic.net] Sent: Friday, December 21, 2012 10:59 AM To: NT System Admin Issues Subject: Re: Disk encryption killer: Anyone see this? I don't find this alarming at all: it requires access

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Ziots, Edward
Message- From: David Lum [mailto:david@nwea.org] Sent: Friday, December 21, 2012 3:39 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? So I'm hearing we shouldn't be concerned about a PGP-encrypted laptop *unless* it's hibernation file is unencrypted (read

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread David Lum
Simple to get past the screensaver password then? -Original Message- From: Ziots, Edward [mailto:ezi...@lifespan.org] Sent: Friday, December 21, 2012 12:59 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? Its not hard to get a memory dump from a PC

Re: Disk encryption killer: Anyone see this?

2012-12-21 Thread Kurt Buff
the screensaver password then? -Original Message- From: Ziots, Edward [mailto:ezi...@lifespan.org] Sent: Friday, December 21, 2012 12:59 PM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? Its not hard to get a memory dump from a PC that is running, and you have

RE: Disk encryption killer: Anyone see this?

2012-12-21 Thread Ken Schaefer
: David Lum [mailto:david@nwea.org] Sent: Saturday, 22 December 2012 7:39 AM To: NT System Admin Issues Subject: RE: Disk encryption killer: Anyone see this? So I'm hearing we shouldn't be concerned about a PGP-encrypted laptop *unless* it's hibernation file is unencrypted (read, no full disk