<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>paranoidmike's WebLog</title><link>http://blogs.msdn.com/paranoidmike/default.aspx</link><description>Data security (EFS, RMS, DPAPI, PKI) and other security rants</description><dc:language>en-CA</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>(Security) Tools I frequently use</title><link>http://blogs.msdn.com/paranoidmike/archive/2005/01/29/363155.aspx</link><pubDate>Sun, 30 Jan 2005 01:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:363155</guid><dc:creator>paranoidmike</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/paranoidmike/comments/363155.aspx</comments><wfw:commentRss>http://blogs.msdn.com/paranoidmike/commentrss.aspx?PostID=363155</wfw:commentRss><description>&lt;font face="Arial" size="2"&gt; &lt;p&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;This may be deemed an exercise in WTF, but I thought I'd share the tools that I have installed on my system that I can't work without.&amp;nbsp; Some of these help me deal with security issues, some are loosely related to security, and some are just downright Cool-But-Unrelated-To-Security.&amp;nbsp; If you've already got them all, then you're probably more of a packrat than me, and I'd be worried ;)&amp;nbsp; If you know of something else that you think I'd really like (aside: wouldn't it be cool if download.com made recommendations to you based on the tools you have, a la Amazon?), comment away!&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;Enjoy, or skip it and do something useful. [more or less in order of how often I use 'em]&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;ul&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="/aaron_margosis/archive/2004/07/24/193721.aspx"&gt;MakeMeAdmin&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://www.sysinternals.com/"&gt;Sysinternals tools&lt;/a&gt; (Regmon, Filemon, ProcExp, Autoruns)&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;a title="http" href="http://stevemiller.net/PureText"&gt;PureText&lt;/a&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://beta.toolbar.msn.com/"&gt;MSN Desktop Search&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://channel9.msdn.com/wiki/default.aspx/Channel9.DesktopSearchIFilters"&gt;IFilters &lt;/a&gt;for Desktop Search&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;/font&gt;&lt;/span&gt;&lt;a title="http" href="http://www.microsoft.com/downloads/details.aspx?FamilyID=9d467a69-57ff-4ae7-96ee-b18c4790cffd&amp;amp;DisplayLang=en"&gt;Windows 2003 Resource Kit tools&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/span&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt; &lt;li&gt;&lt;a title="http" href="http://www.microsoft.com/windowsxp/downloads/powertoys/xppowertoys.mspx"&gt;XP Power Toys &lt;/a&gt;(TweakUI, &lt;/font&gt;&lt;/span&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;Open Command Prompt Here)&lt;/font&gt;&lt;/span&gt;&lt;span class="843503419"&gt;&lt;font face="Times New Roman" size="3"&gt; &lt;/font&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="/michael_howard/archive/2004/11/18/266033.aspx"&gt;DropMyRights&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://fileforum.betanews.com/detail/1069854583/1"&gt;Adobe Reader Speedup&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;a title="http" href="http://go.microsoft.com/fwlink/?linkid=21813"&gt;&lt;font title="http" face="Arial" size="2"&gt;Group Policy Management Console&lt;/font&gt;&lt;/a&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://www.microsoft.com/athome/security/spyware/software/default.mspx"&gt;Microsoft AntiSpyware&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://www.mapilab.com/outlook/security"&gt;Advanced Security for Outlook&lt;/a&gt;&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://www.spamihilator.com/"&gt;Spamhilator&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;span class="843503419"&gt; &lt;li&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;&lt;a title="http" href="http://go.microsoft.com/fwlink/?linkid=20760"&gt;RMS Toolkit&lt;/a&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div&gt;&lt;span class="843503419"&gt;&lt;font face="Arial" size="2"&gt;I've got a ton of other stuff &lt;em&gt;installed&lt;/em&gt;, but these are the ones I regularly &lt;em&gt;use&lt;/em&gt;.&amp;nbsp; [well, plus the usual array of MS software apps of course...]&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt; &lt;hr id="null" /&gt; &lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;&lt;em&gt;&lt;font face="Garamond" color="#008000" size="3"&gt;[Comments feedback...]&lt;/font&gt;&lt;/em&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;Robert: good point, I have all three of those tools &lt;em&gt;installed&lt;/em&gt;, but I actually only rarely use them.&amp;nbsp; For network diagnostics, I have spent way too many years poring over NetMon traces to get to the bottom of all the authentication issues I've encountered, as well as basically any other network or network security issues I've felt compelled to understand.&amp;nbsp; Basically anytime I can't&amp;nbsp;troubleshoot an issue with FileMon, Netmon or ProcExp, I'll fire up &lt;a href="ftp://ftp.microsoft.com/PSS/Tools/NetMon/netmon2.zip"&gt;NetMon &lt;/a&gt;and &lt;a href="http://support.microsoft.com/?id=148942 "&gt;capture &lt;/a&gt;two traces of a transaction: one of the failing operation, and another of the same (or very similar) operation that succeeds.&amp;nbsp; Then I just pop open the captures, start comparing them packet by packet until I see a divergence, and then start digging into the data bits of the unique packets.&amp;nbsp; If I can't figure it out from there, that usually means it's a code-level issue and I'm already drowning :)&amp;nbsp; [few more tips &lt;a href="http://support.microsoft.com/?id=294818"&gt;here&lt;/a&gt;]&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;I don't do a lot of remote scanning anymore - not that it isn't useful, but when I'm &lt;strong&gt;designing &lt;/strong&gt;secure solutions (the majority of my consulting work these days), I want to know more than whether certain ports are remotely accessible or what vulnerabilities are currently identified on the box.&amp;nbsp; The former I can figure out pretty much from within the box itself, and the latter is *always* changing, and the solution shouldn't depend on which unpatched holes are available, since they'll generally be fixed at some point [i.e. "install all current security fixes" is usually all I bother documenting in these solutions, not that anyone needs reminding].&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;&lt;span class="843503419"&gt;Richard: thanks for the offer.&amp;nbsp; I actually have three approaches to securely managing passwords that I need to protect from prying eyes:&lt;/span&gt;&lt;/div&gt; &lt;ul&gt; &lt;li&gt;&lt;span class="843503419"&gt;Excel w/EFS - I have a spreadsheet that currently has 184 entries, of site, username, password.&amp;nbsp; I encrypt the spreadsheet using EFS, which given my passphrase and the amount of time it'd take to brute force, gives me plenty of time to reset those passwords if someone ever stole my laptop.&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;MSN Toolbar w/ form fill - if I'm getting prompted to fill in a forms-based username &amp;amp; pasword, these days I find it's reasonable to use the form filling application that comes with MSN Toolbar&amp;nbsp;Suite (the beta that includes the really nice MSN Desktop Search).&amp;nbsp; It's not perfect, but I believe that the form fill app uses DPAPI to protect my passwords, so it means an attacker needs my domain password before they can get any others.&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;CodeWallet Pro: for storing my passwords on my smartphone, I use CodeWallet Pro.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div&gt;&lt;span class="843503419"&gt;Note two things:&lt;/span&gt;&lt;/div&gt; &lt;ul&gt; &lt;li&gt;&lt;span class="843503419"&gt;I did &lt;strong&gt;not&lt;/strong&gt; say I'm protecting &lt;em&gt;all&lt;/em&gt; passwords to this degree; some of them are just for personalization on all the sites I visit, and frankly I don't care if someone else can spoof me there - not that most of them would bother - they probably would have a better reputation under their own name ;)&lt;/span&gt; &lt;li&gt;&lt;span class="843503419"&gt;I am generally avoiding the use of IE's "Save this password for future use" feature, as it stores your usernames &amp;amp; passwords using the Protected Store feature, rather than DPAPI.&amp;nbsp; The former is LSA secrets-based, so any attacker with admin or LocalSystem can dump them out with tools you can find on the 'net; the latter is the basis for protecting all private keys and other sensitive application data on Windows 2000 and up, and depends on an attacker being able to guess my password to be able to decrypt the data that's protected via DPAPI.&amp;nbsp; I know not everyone uses a really strong password/phrase, but personally I'm pretty safe against brute-force attacks - domain account, 15-20 character passphrase on average, hardly things you'd find in a dictionary.&amp;nbsp; Heck, I'm pretty sure that factoring my RSA keys would take less time than brute-forcing the cached credential verifier for my domain passphrase.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/font&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=363155" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/paranoidmike/archive/tags/EFS/default.aspx">EFS</category></item><item><title>DropMyRights: incompatibility with SSL</title><link>http://blogs.msdn.com/paranoidmike/archive/2005/01/26/360704.aspx</link><pubDate>Wed, 26 Jan 2005 15:48:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:360704</guid><dc:creator>paranoidmike</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/paranoidmike/comments/360704.aspx</comments><wfw:commentRss>http://blogs.msdn.com/paranoidmike/commentrss.aspx?PostID=360704</wfw:commentRss><description>&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Mike Howard kindly coded up a neat little tool called DropMyRights (follow this &lt;A href="http://blogs.msdn.com/michael_howard/archive/2004/11/18/266033.aspx"&gt;link&lt;/a&gt;) that lets us run an application in a "low-privileged" context - i.e. if you logon to your computer with an account that's a member of the local Administrators group, you can run certain apps that you'd like to restrict in a context that is less-privileged than your full logon context.&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&amp;nbsp;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;There has been a raging debate lately about the scenarios in which DropMyRights doesn't work well, and there are two significant ones:&lt;/div&gt; &lt;ul&gt; &lt;li&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;using DropMyRights to run Internet Explorer in "C" or "U" mode, and access SSL-protected web sites&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;using DropMyRights to run Internet Explorer in "C" or "U" mode, and access web sites that require SSPI-based user authentication (e.g. NTLM)&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p xmlns="http://www.w3.org/1999/xhtml"&gt;In the former case, IE will merely fail to load the page, giving me the famous "Cannot find server or DNS Error" message. So, sick geek that I am, I wanted to know what exactly was being blocked in this context - what was IE being blocked from doing in Constrained or Untrusted mode.&lt;/p&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;I first fired up Filemon from &lt;a href="http://www.sysinternals.com"&gt;www.sysinternals.com&lt;/a&gt;, and watched both the successful loading of an example http: web page, and then the failed loading of an https: web page. Turns out there's nothing really interesting at the filesystem level. Well, that's not entirely true - IE failed to open the Temporary Internet Files folder about 200 times, and a few other folders in my profile once or twice, but this occurred whether IE was accessing the SSL'd or non-SSL'd site (in Constrained mode).&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&amp;nbsp;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;Not to be so easily discouraged, I gave Regmon (sysinternals again - those guys…) a try, same scenario. This time, a very interesting set of differences arose:&lt;/div&gt; &lt;ul&gt; &lt;li&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;IE failed to CreateKey under HKCU\Software\Microsoft\SystemCertificate\MY [what is IE doing creating new keys related to digital certs? It's not that I think it *shouldn't*, but merely that I don't *get it*.] This occurred only in the IE-browsing-SSL case.&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;IE failed to CreateKey under HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings. This occurred in both cases.&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;IE failed to SetValue under HKCU\Software\Microsoft\Windows\Explorer\Shell Folders\History. This only occurred in the IE-browsing-SSL case.&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;To me it's pretty clear that the primary cause of failure is the lack of permissions to write to the MY key in the registry. Makes me want to change the ACL on that key and see what happens, but ACL-muddling in HKCU is a fool's errand - at the very least, it's not a permanent solution.&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&amp;nbsp;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;What's my advice? I've been struggling with this for a few weeks now, hoping some "magic bullet" would come through; at this point however, I think it's best to just continue to heed &lt;A href="http://blogs.msdn.com/aaron_margosis"&gt;Aaron's&lt;/a&gt; wise words that he wrote when I first started down this road:&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;"&lt;font face="Arial" color="navy" size="2"&gt;&lt;span style="FONT-SIZE: 10pt"&gt;My experience has been that SSL just does not work when you’re running with a Constrained or Untrusted token, in our current implementation.&lt;/span&gt;&lt;/font&gt;"&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&amp;nbsp;&lt;/div&gt; &lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;I'll see about digging into the root cause on the latter case later on.&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=360704" width="1" height="1"&gt;</description></item><item><title>Is it possible to prevent encrypted data from being copied to non-encrypted/NTFS media?</title><link>http://blogs.msdn.com/paranoidmike/archive/2005/01/24/359390.aspx</link><pubDate>Mon, 24 Jan 2005 10:11:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:359390</guid><dc:creator>paranoidmike</dc:creator><slash:comments>4</slash:comments><comments>http://blogs.msdn.com/paranoidmike/comments/359390.aspx</comments><wfw:commentRss>http://blogs.msdn.com/paranoidmike/commentrss.aspx?PostID=359390</wfw:commentRss><description>&lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;&lt;font color="#000000"&gt; &lt;div&gt;&lt;span class="031071109"&gt;&lt;font face="Verdana" size="2"&gt;Recently I was asked to assist a customer in trying to prevent their sensitive data from walking out on unencrypted media:&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span class="031071109"&gt;&lt;font face="Verdana"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div&gt;&lt;span class="031071109"&gt;&lt;font face="Verdana" size="2"&gt;"By default, encrypted data on NTFS will be decrypted when copied/moved to non-NTFS media.&amp;nbsp; &lt;/font&gt;&lt;/span&gt;&lt;span class="031071109"&gt;&lt;font face="Verdana" size="2"&gt;We want a solution so that EFS encrypted data cannot be copied to non-NTFS removable media."&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt;&lt;/font&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;There are no known solutions that *only* target this problem - solutions are typically too narrow or too broad for what you're trying to achieve:&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;ul dir="ltr"&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Once a user can decrypt an EFS-encrypted file, they are authorized to do *anything* with the file that the shell (or application calling shell functions) allows them to do.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;If the user is blocked at the shell (or device driver) level from being able to write to certain types of media, that could help to prevent copying this sensitive data - but it will also prevent them from writing non-EFS'd files to the same "blocked" media.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt; &lt;ul&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;There is the recent update to Windows XP SP2 (&lt;a title="http" href="http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2otech.mspx#ECAA"&gt;http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/sp2otech.mspx#ECAA&lt;/a&gt;) that allowed administrators to control the usage of USB block storage devices (e.g. USB flash drives) only.&amp;nbsp; Does not affect 1394 devices, other non-block storage USB devices.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;ul&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Key = HKLM\System\CurrentControlSet\Control \StorageDevicePolicies&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Setting = WriteProtect&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt; &lt;li&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;It's also possible to prevent all access to USB storage devices using the setting Start under the USBStor key (see &lt;a href="http://support.microsoft.com/kb/823732"&gt;this&lt;/a&gt; KB article).&lt;/font&gt;&lt;/span&gt; &lt;li&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;There is also the older Group Policy function "Prevent access to drives from My Computer" that blocked the user's ability to access drives by their specified drive letters:&lt;/font&gt;&lt;/span&gt;&lt;/li&gt; &lt;ul&gt; &lt;li&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;This would allow the administrators to block access to non-permanent drive letters (e.g. E: through Z:), so that even if the user could add a new removable drive,&amp;nbsp;they'd have a hard time accessing them.&lt;/font&gt;&lt;/span&gt;&lt;/li&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;You can find this &lt;a href="http://msdn.microsoft.com/library/en-us/gp/340.asp"&gt;setting &lt;/a&gt;under User Configuration &amp;gt; Administrative Templates &amp;gt; Windows Components &amp;gt; Windows Explorer &amp;gt; "Prevent access to drives from My Computer".&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;While the GPO UI only lists the ability to "block all drives" and not "all removable drives" or "all drives *except* C: and D:", you could manually edit the registry value that controls this Group Policy setting, and name specific drive letters that you want blocked - see for example this &lt;a href="http://www.winguides.com/registry/display.php/1157/"&gt;article &lt;/a&gt;for detailed instructions.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Check the &lt;a href="http://msdn.microsoft.com/library/en-us/gp/gpref.asp"&gt;Group Policy reference &lt;/a&gt;for related settings, such as NoDrvive&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;/ul&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Even if these options are what you're after, keep in mind that a determined user, who understands how to use NTBackup &amp;amp; cipher /X (or the Certificates MMC), also may try to backup the encrypted files + export their private key off the system, and import them later to a different system (where such restrictions may not be in place).&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;However, I like to think that most organizations would prefer to take reasonable steps to reduce the overall incidence of these issues from occuring - prefer that over not doing anything until a "bulletproof" solution became available.&amp;nbsp; I'll agree that it's forseeable that some users will actively try to work around these kinds of measures, and some might succeed in copying encrypted data onto removable media.&amp;nbsp; However, in my experience this is far removed &lt;/font&gt;&lt;/span&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;from "what's likely or typical from &lt;em&gt;most &lt;/em&gt;users", and I will assert that you would still achieve a measurable decrease in risk of data exposure if *most* of the users were effectively discouraged by the above approach.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Also keep in mind that, if an individual really wants to take copies of encrypted data off-premises, there are plenty of ways a creative person could do that - from uploading the files to a home-based web or FTP server, to emailing files to themselves (or attaching them to emails in a web-based email account they use); accessing their email via web-based access (e.g. Outlook Web Access) from a home computer, burning the data to CD, or even (ugh) the old "spanning floppies" technique.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;&lt;/font&gt;&lt;/span&gt;&amp;nbsp;&lt;/div&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;The next logical stage of controlling what people can do with data is to use technology (as well as well-thought-out processes, and effectively communicated policies)&amp;nbsp;to limit what people are authorized to do once they receive a copy of the data:&lt;/font&gt;&lt;/span&gt;&lt;/div&gt; &lt;ul dir="ltr"&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;only allowing access to the data via applications that run only on Terminal Servcies systems - so that the most a user can do is print screen from their Terminal Services session.&amp;nbsp; [I'd recommend setting IPSec rules that only allow incoming requests from the TS servers and block other computers; then you could further set up rules that only allow 3389/tcp access to the Terminal Services systems, so that users couldn't copy their data from the TS system to their client, and only allow users - e.g. using Software Restriction Policies or appsec.exe - to use the authorized applications on the TS servers.]&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt; &lt;li&gt; &lt;div align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;deploying ever-controversial rights management technologies (e.g. RMS, IRM, ERM, DRM) that make it difficult to perform unauthorized activities with the data, and/or require authorized/restricted software and/or hardware to be able to view this restricted data.&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;These kinds of approaches often cost a great deal more in terms of effort to configure/operate/support/train, and can also cost significant money to acquire the software/hardware.&amp;nbsp; Trade-offs between how much you're willing to invest, and the sensitivity of the data you're trying to protect, are the inevitable final stage of this line of thinking.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;p align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;Til next time.&lt;/font&gt;&lt;/span&gt;&lt;/p&gt; &lt;div dir="ltr" align="left"&gt;&lt;span class="686413322"&gt;&lt;font face="Arial" color="#0000ff" size="2"&gt;[Please note: these ideas haven't been fully tested by me nor the product teams at Microsoft, and as such can't be officially supported by Customer Support Services - aka PSS.]&lt;/font&gt;&lt;/span&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=359390" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/paranoidmike/archive/tags/EFS/default.aspx">EFS</category></item><item><title>EFS and RMS/IRM together?</title><link>http://blogs.msdn.com/paranoidmike/archive/2005/01/19/355907.aspx</link><pubDate>Wed, 19 Jan 2005 09:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:355907</guid><dc:creator>paranoidmike</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.msdn.com/paranoidmike/comments/355907.aspx</comments><wfw:commentRss>http://blogs.msdn.com/paranoidmike/commentrss.aspx?PostID=355907</wfw:commentRss><description>&lt;p&gt;&lt;font face="Arial"&gt;Customer asked me recently:&lt;/font&gt;&lt;/p&gt;&lt;font size="2"&gt; &lt;p&gt;"Are there any considerations to deploy both RMS/IRM and EFS?&amp;nbsp; As far as I understand, RMS/IRM and EFS can work together."&lt;/p&gt; &lt;p&gt;My response was this:&lt;/p&gt;&lt;font color="#0000ff" size="2"&gt; &lt;p&gt;No problems of which I'm aware - I've been running the two interdependently for months now, without any known or visible issues.&lt;/p&gt; &lt;p&gt;My approach has been:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;encrypt the %USERPROFILE%\Local Settings\Application Data\Microsoft\DRM folder (i.e. the location for the RAC, CLC and all ULs), so that only the person with the user's credentials (password or smart card) would be able to unlock the files that grant any access to the content. &lt;li&gt;Don't worry whether the RM-protected files are EFS encrypted or not. Since the RM-enabled applications only see the file once EFS has decrypted it, there's no possibility of EFS and RMS "colliding" in memory, and since RMS doesn't operate at the filesystem level, they can't collide on disk.&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Personally, all my documents are encrypted, whether they're RM-protected or not, so there's no *harm* in applying both to the documents. The benefit is in leveraging DPAPI (to protect each file from anyone who doesn't know the user's logon credentials) and the RM protections (to control the authorized use of the data once it's been unlocked by the user's logon credentials via DPAPI &amp;amp; EFS).&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000000" size="3"&gt;I could go into more of the technical detail, and I intend to discuss things like "what if I only wanted to choose one of the two?" and "when is it better to use one or the other?".&amp;nbsp; For now though, I just wanted to make sure that people have some idea that these two technologies won't *conflict* - at least at a technical level, and that in their current form they can complement each other.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000000" size="3"&gt;[Plus I didn't want to bog this down so early in the life of a nascent blog...]&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font face="Arial" color="#000000" size="1"&gt;&lt;em&gt;[EDIT: spelling error and expanded the path to the DRM folder]&lt;/em&gt;&lt;/font&gt;&lt;/p&gt;&lt;/font&gt;&lt;/font&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=355907" width="1" height="1"&gt;</description><category domain="http://blogs.msdn.com/paranoidmike/archive/tags/RMS/default.aspx">RMS</category><category domain="http://blogs.msdn.com/paranoidmike/archive/tags/EFS/default.aspx">EFS</category></item><item><title>Manifesto?  We don't need no stinkin' manifesto</title><link>http://blogs.msdn.com/paranoidmike/archive/2005/01/15/353734.aspx</link><pubDate>Sat, 15 Jan 2005 22:43:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:353734</guid><dc:creator>paranoidmike</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.msdn.com/paranoidmike/comments/353734.aspx</comments><wfw:commentRss>http://blogs.msdn.com/paranoidmike/commentrss.aspx?PostID=353734</wfw:commentRss><description>&lt;p&gt;I'm a security guy, driven by a long-standing paranoia, who happens to like the feeling that no one can get into my own files.&lt;/p&gt; &lt;p&gt;So there.&lt;/p&gt; &lt;p&gt;[BTW, the next time someone asks, this is coming to you live from Mike Smith-Lonergan, also known as Mike Lonergan.]&lt;/p&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=353734" width="1" height="1"&gt;</description></item></channel></rss>