Encryption

May 03, 2006 44 Replies

So what? It provides little security and is easily defeated. Instead of finding it in the default spot you have to look around a little bit. Big deal

Exactly, it's really no security.

The point is inserting a slt folder in the path to the profile does nothing to keep things secure as any programmer with 1/2 a brain can simply scan for the files. The slt folder does nothing. It's akin to saying "I left my car keys on my desk instead of hanging up on the key rack therefore my car is secure".

I don't think that's true (I haven't tested it however).

EFS creates a personal security certificate based on the user account. You can copy this certificate onto removable media (mine is on a thumb drive, protected with a password), remove it from Windows, and then nobody can read the encrypted files (including yourself) until you import the certificate again and supply the password.

Presumably, if you have the certificate and password, you can import it into another account and read the encrypted files (I'll try this tonight).

To get access to your encryption certificate, enable EFS, go to Internet Options in the Control Panel, select the Content tab, and then select Certificates -- you should then see your personal certificate in the next pane. From there you can export it to anywhere you want, and remove it if you like. To re-import it, double click on its icon from wherever you copied it.

I use EFS because it's convenient and transparent, but it probably isn't as strong as I would like.

-- Mark

IIRC in a domain environment, domain admins also have the ability to unlock your EFS files for you. This is probably a last resort if users of a domain lose their certs. Then again, I think it probably very rare the number of home users who have bothered to set up a domain! I know I haven't.

So that adds a vulnerability as well as a method of recovery...

Yep, it works as expected.

-- Mark

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required