Download the Tom's Hardware App from the App Store
The reference for current tech news
Yes No
Ads
Tom's Hardware > Forum > Windows 7 > Security > How to secure data on desktop machines Raid array??

How to secure data on desktop machines Raid array??

Forum Windows 7 : Security How to secure data on desktop machines Raid array??

Word :    Username :           
 

Hi,

I think I'm chasing my tail with how to lock up data on a desktop's raid array, for the purpose of covering it if the machine was stolen.

Basically I want to prevent the scenario where the array is pulled out of this machine and plugged into another machine, so the data drives can be read.

1 - Products like PGP Whole disk encrypt/Truecrypt work fine on single disks, but do not work on arrays.
2 - Having a domain server so I can use NTFS permissions is not 100%, because you can just take over the permissions with an admin account on another network
3 - Bitlocker on a desktop machine using an onboard TPM appears to be non-existant. The motherboards that have the header for an onboard TPM (eg Asus) have no-one selling the TPM module that plugs into it (used to be made by infineon). However bitlocker does work across an array - I tested this using a mobo with no TPM chip and ran bitlocker off a USB key. The USB version I discount because I would just leave the USB key in the machine = has to have onboard TPM chip.

Has anyone else found a way around these issues?

Thanks,
Herb

Reply to herb1
Register or log in to remove.

Using Becrypt Full Disk Encryption on a laptop in raid-1, without issues or speed loss, plus you get the option to do encryption to usb devices. :D


Message edited by das_stig on 01-28-2010 at 01:43:05 PM
------------------------------ HP Pavilion DV7-3020EA Entertainment Notebook PC + Win 7 Pro SP1 x64
GA-870A-UD3 + AMD PH-II X6 1100T BE + Hyper212+ + 8GB DDR3-1600 + GTX460 + Win 7 Pro SP1 x64
GA-870A-UD3 + AMD PH-II X4 840 + 4GB DDR3-1333 + ATI 3450 + SVR08 R2 SP1 x64
Reply to das_stig

I checked with becrypt, they were very helpful - but support is not a given. They think it maybe will work for raid5 on ICH*R setups, but are pretty sure it won't with my adaptec cards.

So yeh, basically I'm back in a loop where whole disk encryption over Raid5 doesn't seem possible without it being at the OS level (eg bitlocker), but then I can't use bitlocker cause there are no current mid-high end motherboards that have TPM chips built onto them - or TPM modules availabe for the ones that have headers!

:??:

Reply to herb1

My understanding is that you CAN use Bitlocker without a TPM by putting the encryption keys on a USB flash drive. Of course it would then be incumbent on the user to NOT leave the flash drive plugged into the machine all the time.


Message edited by sminlal on 02-03-2010 at 07:05:46 PM
Reply to sminlal

Yep, that's exactly why I'm trying to find a suitable board that can handle bitlocker using TPM not USB :)

Reply to herb1
Register or log in to remove.
Tom's Hardware > Forum > Windows 7 > Security > How to secure data on desktop machines Raid array??
Go to:

There are 1578 identified and unidentified users. To see the list of identified users, Click here.

Please mind

You are about to answer a thread that has been inactive for more than 6 months.
If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.

Add a reply Cancel
  • Ask the community now
  • Publish
Ad
Ads
Latest best answer
Moving an operating system
By Pinhedd, 6 hours ago:

You will not be able to drag and drop the files because that will not copy the parts of...

Best offers
They won a badge
Join us in greeting them
Top experts