Centrally-Managed Drive Encryption

From the Beachhead Solutions FAQ
Q: How does the LDD application work?
A: LDD secures access to sensitive data on your computer by detecting user behaviors which are inconsistent with expected norms, an indicator that unauthorized persons may be attempting to access the device. Once this behavior is detected, sensitive data files are destroyed based on an administrator-controlled pre-determined set of rules that cover both location and depth of destruction.

More specifically, files are protected by encryption and destruction. Before your device is ever lost or stolen, the administrator can download pre-set rules which first encrypt all sensitive data and then inform the device software to take destructive action under specified conditions. Thus, the device is prepared to protect itself when an unauthorized access attempt occurs. Additionally, if the lost device ever communicates with the server again, the client software can be instructed to immediately destroy sensitive data.
Man, try explaining to your boss, that the "pre-set rules" glitched and the entire system got wiped. And like jrdonnaruma, I'm not sure SaaS and Cloud is the place for the IT security that j-sta is looking for...
 
#1 - we are using the GE Native Policy manager; it is not integrated into AD (note: I do not remember why it was decided to be setup this way. I had nothing to do with that process).

#2 - we have had numerous issues through all the versions. 9.2.0 through the current 9.5.3. Boot time is horrendously slow. My Dell Optiplex 620 (P4) with Credant is much faster than my Optiplex 745 (Core2Duo). Same model hard drives in both systems, and my 745 has more RAM.

Honestly if you redid your configuration, created some new installer packages you would be much happier. The GE native policy manager is for non domain computers and that's slowing you down by having to contact the GE server to recieve policy, it sounds like your requiring PBA (pre-boot authentication) which also slows things down and is a hassle for remote management and patching.

I've deployed GE to over 7500 systems anywhere from an Optiplex GX270 to a Optiplex 980, same with laptops and outside of the 5 second boot phase while it unlocks the drive there really hasn't been a noticable performance hit. Even encrypting the drive in the background is relatively painless.

I would figure out what your requirements really are and then reconfigure GE.
 
i-sta, I was actually commenting on SecurityGuy's reply directly above mine.

Also, SecurityGuy, I'm not sure how I feel about services that host my security software, especially encryption. In my companies, I would not ever recommend storing encryption keys or management tools on someone else's server. Someone else's datacenter on my hardware, maybe, but not someone else's hardware, inside someone else's database, with someone else responsible for management and source code. At least with things I run on my system, I can reverse engineer the tools to ensure no backdoors are available to the software developers. With the software on someone else's system, that I have no access to, provide access to people I do not have any control over.

SaaS and Cloud software is great, don't get me wrong, but it is not the place for serious IT Security.

Edit: I just finished going over Beachhead's website, and it leaves more questions to ask than it does answer them. And the only supported OSes are XP and Win Server 2003 (which for the OP is good... but doesn't bode well for their support or actual reliability)
jrdonnaruma,
In answer to your concern about hosting a security solution in the cloud, there is no data stored there, just the certificate server. If you have problems with a web based certificate authority, why has everyone been using certificates from Verisign and others for years. In the case of the encryption certificates, a hacker or thief must also have phyical posession of the computer before the certificate has any value.

With the server hosted in the cloud, you don't have to have remote devices connect to the corporate domain in order to take any actions. If you absolutely must have the server inside your domain, then Beachhead may not be the solution you're looking for. I would however, bet that if the size of the deal was big enough, they would allow you to run it in-house.

And by the way, They don't do encryption on servers, but XP, Vista and Windows 7 are supported.
 
From the Beachhead Solutions FAQ

Man, try explaining to your boss, that the "pre-set rules" glitched and the entire system got wiped. And like jrdonnaruma, I'm not sure SaaS and Cloud is the place for the IT security that j-sta is looking for...
By the way, the rules are configured by the Admin and any destruction that is done is only by direct intervention by the administrator. most of the other rules will end in destroying just the private key, which quarantines the data so that nobody, even someone with the pasword can't access it. If the computer is determined to be in friendly hands, the administrator just restores the key with a mouse click and access is restored.

Maybe instead of guessing based on what is on their website someone should try out the software and see for themselves.

Every one of the encryption products out on the market has its good points and its bad points. Encryption as a whole will burden both the user and IT. You have to ask your self how much burden am I willing to accept for how much added value. If you are protecting national security, then file and folder is probably not what you want because the OS is not protected. But, if you are complying with regulations and laws, they require a resonable level of protection and encrypting the sensitive data files is enough and that place the least amount of burden on the end users and IT staff.

Security is never absolute. You cannot protect from everything. A good security consultant will always balance security with productivity and cost. Best bang for the buck without heavily impacting performance.
 
Honestly if you redid your configuration, created some new installer packages you would be much happier. The GE native policy manager is for non domain computers and that's slowing you down by having to contact the GE server to recieve policy, it sounds like your requiring PBA (pre-boot authentication) which also slows things down and is a hassle for remote management and patching.

I've deployed GE to over 7500 systems anywhere from an Optiplex GX270 to a Optiplex 980, same with laptops and outside of the 5 second boot phase while it unlocks the drive there really hasn't been a noticable performance hit. Even encrypting the drive in the background is relatively painless.

I would figure out what your requirements really are and then reconfigure GE.

even without PBA, boot time is horrendous. Systems are slow. Horrible desktop performance would have nothing to do with contacting the GE server.

As for reconfiguring GE; it would be nice if GE tech support was of any use, but they are completely and utterly useless. At least, in our case they have been.
 
What would some of you guys suggest for encrypting about 30 laptops, some old some new. Bitlocker looked cool but the older machines are all XP.

These machines will not be tied into domain.
 
What would some of you guys suggest for encrypting about 30 laptops, some old some new. Bitlocker looked cool but the older machines are all XP.

These machines will not be tied into domain.
marley1,

The beachhead product would be the simplest method of supporting both old and new with a combination of EFS and BitLocker (where available) and the machines don't have to be on the domain. Self Encrypted Drives are also an option, if you are replacing hardware. You mix and match.
 
Not sure if i wanted to go with the hosted solution like that. What about out of the software packages? Somtehing on the cheaper price range?
 
even without PBA, boot time is horrendous. Systems are slow. Horrible desktop performance would have nothing to do with contacting the GE server.

As for reconfiguring GE; it would be nice if GE tech support was of any use, but they are completely and utterly useless. At least, in our case they have been.

By default it contacts the server every hour and if your having to refresh policy when it does that then it can take up cpu time. After the drive is encrypted GE just doesn't do anything on it's own to cause it to take up resources. What are the characteristics of the "horrible performance"?
 
Not sure if i wanted to go with the hosted solution like that. What about out of the software packages? Somtehing on the cheaper price range?
marley1,

As far as pricing goes, I think all the products price out about the same, but you have to take into account the server cost. none of the products seem to require much power on the server, but they can require SQL which has an additional cost. I am pretty sure that McAffee's Safeboot and others can run as standalones which eliminates the need for a server, but you will have to create recovery disks for each one to ensure you can get in if the user forgets the password.

I don't recommend Guardian Edge though. I have heard of too many issues with that product. And the fact that Symantec just bought PGP which is also a full disk encryption product indicates that they will probably phase out Guardian Edge.

One thing to keep in mind is that Software full disk as a classification of encryption products will be dead in just a few years. With the size of hard disks increasing, the performance of the initial encryption pass is horrendous. That combined with the boot performance issues is why Self Encrypted Drives and other hardware based encryption products have come to market. They provide significantly better performance and eliminate the initial encryption pass.

I use bitlocker with EFS on top with the Beachhead product. On my Dell Lattitude E6500 with 250Gb drive, the bitlocker encryption took 1.5 hours while the Efs encryption of the data files took 15 minutes and I have about 3 GB of data plus a 1.5GB PST file. BitLocker and SEDs will be the death of Software based FDE. Don't select a product unless you talk to a rep and determine their roadmap and your upgrade path and cost.

As you replace your Laptops consider SEDs or Windows 7 Ultimate or Enterprise which provide support for Bitlocker to keep your options open.
 
Last edited:
See on my case the system doesn't have any data except for one program that is an offline copy of the patient that is being treated, when it gets updated they sign into vpn and sync the data and then disconnect. So i need something that encrypts full system during startup. I contacted a few today, Checkpoint PointSec has RSA support which may be good and PGP will call me tomorrow.

Thats what they originally wanted, turn machine on, have to enter the RSA key or USB RSA and boot up.

Seems to be about 100ish a pc and then $500 a rsa usb key. Looking for cheaper solutions.

Does Truecrypt have some ability to be unlocked not by a password but by a rsa key or something?
 
And the fact that Symantec just bought PGP which is also a full disk encryption product indicates that they will probably phase out Guardian Edge.

I'm pretty sure they didn't spend $370 million to phase it out, it sounds like they are using PGP to manage keys across all of their encryption products and GE for the disk component. Also considering all of the government customers on GE they have to keep supporting them.
 
See on my case the system doesn't have any data except for one program that is an offline copy of the patient that is being treated, when it gets updated they sign into vpn and sync the data and then disconnect. So i need something that encrypts full system during startup. I contacted a few today, Checkpoint PointSec has RSA support which may be good and PGP will call me tomorrow.

Thats what they originally wanted, turn machine on, have to enter the RSA key or USB RSA and boot up.

Seems to be about 100ish a pc and then $500 a rsa usb key. Looking for cheaper solutions.

Does Truecrypt have some ability to be unlocked not by a password but by a rsa key or something?
marley1,

Truecrypt is open source and I am not sure they support RSA tokens. You might consider Upgrading to Windows 7 with Bitlocker as Bitlocker can be implemented with the key on usb. If the key is there it boots Windows normally. And you don't have to pay for the RSA token.

You will eventually need to go to Windows 7 anyway. Microsoft will stop doing security patches for XP soon, forcing everyone to have to upgrade to remain protected by security patches.

In addition, I have implemented Beachhead at many health organizations with many using products like McKesson for visiting nurse applications, which sounds like your application. That data file can be encrypted and protected.

The entire reason HIPAA and other regulatory bodies require or encourage encryption is that just about any IT guy can take the drive out of a PC and mount it as a slave on another PC and gain full access to the data in a matter of minutes reguardless of how secure the password is.

Encryption protects the data when the computer is turned off and not logged in. EFS has another advantage in that it is user level encryption, which means that it also protects against network born attacks and the prying eyes of rogue IT staff. If you log into the C$ share (C: drive) from the network with Domain Administrator priviledges. They cannot access the data encrypted by a user.
 
I'm pretty sure they didn't spend $370 million to phase it out, it sounds like they are using PGP to manage keys across all of their encryption products and GE for the disk component. Also considering all of the government customers on GE they have to keep supporting them.
Zlash,

Maybe your right about Symantec keeping Guardian Edge around for awhile. I personnally can't tell you whether it's underlying encryption technology is better than PGPs, but I have heard all kinds of stories from Guardian Edge users looking to leave because of hardware compatibility or performance issues. It may be from the way they implemented, but if that is the case Symantec should spend more time assisting in the implementation to make sure it is done right.

I know the folks at Beachhead personally train each customer and walk them through the implementation process having most customers up and running in less than 2 hours with policies set and at least one computer encrypted. Then all they have to do is push the installer via Active Directory or any software distribution product.

I have seen it pushed out to 4000 computers in less than a month. It could have been faster but the client wanted to push it to groups of a few hundred at a time.
 
By default it contacts the server every hour and if your having to refresh policy when it does that then it can take up cpu time. After the drive is encrypted GE just doesn't do anything on it's own to cause it to take up resources. What are the characteristics of the "horrible performance"?

our policies are not the "default" policies.
So "default" settings mean absolutely nothing.
One group is set to check-in every hour, the other group every 4 hours.

And considering the policies don't change, there should be virtually no CPU usage required.

As for performance; 5+ minutes to boot in to Windows. Then another 2 minutes or so to get a useable desktop.

Regardless; I don't care about GE. We are getting away from GE. It's done. This thread was about products similar to Credant. Not about GE.
 
Shoot GE or not, 5 min + 2 min to get a desktop on XP in a corporate environment with lots of GPOs, AV, Firewall, logon scripts...sounds in the realm of normalcy. But ok blame it on GE...just saying, we've had to do performance testing on our baseline software and boot and logon time differences were negligible after GE was added, 10-15 seconds if i recall. Most of our boot time is taken up by GPO processing.
 
i-sta and marley1.

I would really look into WinMagic, or the McAfee Endpoint encryption (if you already use McAfee Products, as they are managed by EPO). WinMagic is just encryption software, with a fairly simple to use enterprise management server.

McAfee EE integrates into the Total Protection for Business product (Total Protection for Secure Business).
 
Will try them tomorrow, WinMagic. Have you used them? Never heard of them before
 
I have used them. I moved from them to McAfee due to EPO, but I still recommend WinMagic often for clients. They are a Canadian company, 13 years old, and hold all of the major validations. (FIPS-140-1 Level 2, FIPS 140-2 Level 1 & 2, Common Criteria EAL4, and NIST Cryptographic Module Validation.

As for its real world security, I have not been able to decrypt any pulled hard drives, with any currently known methods.
 
Shoot GE or not, 5 min + 2 min to get a desktop on XP in a corporate environment with lots of GPOs, AV, Firewall, logon scripts...sounds in the realm of normalcy. But ok blame it on GE...just saying, we've had to do performance testing on our baseline software and boot and logon time differences were negligible after GE was added, 10-15 seconds if i recall. Most of our boot time is taken up by GPO processing.

boot time is atleast half that without GE. Tell me how it's normal.

Since you seem to think you know more about my environment than I do, please tell me how to make GE not cause a performance impact.

i-sta and marley1.

I would really look into WinMagic, or the McAfee Endpoint encryption (if you already use McAfee Products, as they are managed by EPO). WinMagic is just encryption software, with a fairly simple to use enterprise management server.

McAfee EE integrates into the Total Protection for Business product (Total Protection for Secure Business).

We don't use McAfee at all. Symantec AV, working on migrating to SEP.
I'll take a look at WinMagic.
 
Last edited:
I called WinMagic today, waiting on pricing now for Safenet Rainbow iKey 1000 for a 2nd authentication type.

Price seems to be the cheapest from the rest. $3500 for the 1 year software update/support/management and console.
 
Since I don't think anyone mentioned it. Checkpoint has a product called Pointsec that does what you are looking for, will do FDE or WIL (your choice), and will write logs/recovery keys back to a central point.
 
Pretty happy Credant customer here. Other than some issues due to older clients not supporting the Core iX Intel processor architectures, which was an easy fix, we haven't had any real difficulties with it. When we did our original research we looked at Pointsec, PGP, GE (before Symantec bought them), and Utimaco. Hate to sound like a shill, but nothing really compares. Deploy the agent with Altiris during our imaging process and don't really have to worry about it.
 
Pretty happy Credant customer here. Other than some issues due to older clients not supporting the Core iX Intel processor architectures, which was an easy fix, we haven't had any real difficulties with it. When we did our original research we looked at Pointsec, PGP, GE (before Symantec bought them), and Utimaco. Hate to sound like a shill, but nothing really compares. Deploy the agent with Altiris during our imaging process and don't really have to worry about it.

how has Credant support been? Like their turn-around for trouble tickets. Not necessarily how quickly do they get the issue resolved, but how quickly do they get back to you and say they're working on it, looking into it, etc? Fairly consistent contact while they're finding/fixing the issue?

Ultimaco, huh? odd name... haha.
 
We did Gartner Magic Quadrant studies on the products in that area which is why we looked at Utimaco. They got bought by Sophos and I haven't heard of anyone that uses them really.

As far as Credant support, I have never had an issue with them really. I call, they resolve it. I've called probably less than 10 times if even that in the 2 years we've had the product and they've always resolved my issue within a day. They're very familiar with their typical issues and I even had them help me with an EnCase issue which wasn't even their responsibility but they still helped as much as they could. We're a pretty light shop and only have around 800 laptops with the product, but other than the recovery of encrypted documents, which is easier in the newer version than it was in the older 5 versions, I don't even really have to do anything with it.

But seriously, if you have an issue you call them. I never email their support because calling them normally gets a resolution first call.
 
Have any of you used PGP? Price is the same for all these companies, just not sure which to go with. WinMagic looks good as I got a demo of it. Just PGP is a larger name player
 
Have any of you used PGP? Price is the same for all these companies, just not sure which to go with. WinMagic looks good as I got a demo of it. Just PGP is a larger name player

considering PGP is owned by Symantec now, Symantec is planning on "creating" a new product by, essentially, combining PGP's and GE's FDE products.

We'll find out how good Credant is with support... we currently stumped one of their senior engineers. Atleast, I believe that's his position.
 
We'll find out how good Credant is with support... we currently stumped one of their senior engineers. Atleast, I believe that's his position.

so I figured out what the issue was.... can't believe Credant never came across this before. They even said they have numerous clients that use roaming profiles.

Turns out Credant pukes when a file in the roaming profile on the server is NTFS compressed.

But looks like we've chosen Credant. Now just if GuardianEdge/Symantec could tell us how to script the uninstall of the damn removable storage piece that requires a GE Client Admin account's credentials. Supposedly some of their clients have found a way, but they don't know how. hah.
 
That's interesting because before we finally disabled roaming (vomit) profiles, we had Credant installed. I guess the one thing we didn't do was compress the files though so that might be the kicker.
 
It's too bad I didn't see this until now.

I work for Winmagic (have for the last 6 years) our product is stellar I hope all went ok with your choice of Credant.
 
Back
Top