Archived from groups: microsoft.public.win2000.security (
More info?)
Thanks so far.
But ...
For security reasons are the laptops never conected to our network. Our
network is not connected to the internet, too. The encrypted data have to be
available at the customer, too. So the local SAM is the only one. The key of
the administrator is exported. The only key currently left would be the
private key of the user (only one as every user has its own laptop).
What is about following idea: Not exporting but simply moving the users
encryption key to a memory stick should secure the encrypted files. Just
wether the stick is plugged or unpluged during booting decides if the
encrypted data are available. If this could work, what do I have to do?
For several reasons upgrading to XP is currently not a solution.
Thomas Weigel
"Roger Abell [MVP]" <mvpNoSpam@asu.edu> schrieb im Newsbeitrag
news:uqGQYl#uEHA.3200@TK2MSFTNGP14.phx.gbl...
> The problem was fixed by an architectural change for XP and
> Windows 2003. This is not backported to Windows 2000.
>
> One thing Steve omitted is that if you force use of domain
> accounts on your W2k then what he outlined for replacing the
> admin password, then getting the SAM and cracking against
> the encrypting user accounts (so as to be able to log into them
> in a way that even EFS in XP/W2k3 will allow) would not work
> since the encrypting accounts are not in the local SAM.
>
> --
> Roger Abell
> Microsoft MVP (Windows Server System: Security)
> MCDBA, MCSE W2k3+W2k+Nt4
> "Thomas Weigel" <entwicklung_nospam__at__octagon_minus_gmbh_dot_de> wrote
in
> message news:utBFPh2uEHA.1984@TK2MSFTNGP14.phx.gbl...
> > Hello,
> >
> > using w2k on laptos we would like to keep there some sensible data too.
> > Searching for a solution EFS looked fine till I found the EFS backdoor
> > problem mentioned in 2002.
> > Where booting from a floppy, changing the password of the user (using
> > certain programms) grants access to the encrypted directories and files
> > too...
> >
> > I did not find any article about this problem (the only link I found, is
> > worthless because of the new structure of MS-homepage...)
> > I did not find any information searching for patches and within the
> > service
> > packs.
> > Has the problem not been solved yet? If it has been solved, where can I
> > find
> > the solution?
> > I would prefer to use the Windows 2000 EFS rather than a third party
> > solution or updating to XP.
> >
> > thanks ahead and kind regards
> >
> > Thomas Weigel
> >
> >
> >
> >
>
>