Utimaco privatedisk or IBM FFE?

Performance, hardware, software, general buying and gaming discussion..
Post Reply
Message
Author
tom2517
Freshman Member
Posts: 109
Joined: Sun Jul 31, 2005 11:28 am

Utimaco privatedisk or IBM FFE?

#1 Post by tom2517 » Tue Sep 20, 2005 6:45 am

I am currently using CSS 5.41 and are looking for a program that protect my files. I do not want to upgrade to CSS 6.0. My question is, both privatedisk and FFE seems to do the samething, so which is better? Or which do you guys prefre to use? Thanks.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#2 Post by s0larian » Wed Sep 21, 2005 4:44 am

Privatedisk is much better, it uses container (like Truecrypt) and is working on any drive, even network drive. FFE just works on C:\ and filenames of encrypted files are still visible.
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

tom2517
Freshman Member
Posts: 109
Joined: Sun Jul 31, 2005 11:28 am

#3 Post by tom2517 » Wed Sep 21, 2005 8:41 am

I am using the privatedisk, for some reason FFE doesn't work for my CSS??? I right click and only sees "folder status" and when I select it, it only says it is not protected, but doesn't offer me options to encrypt it. Was my settings wrong? I uninstalled and reinstalled and samething still happen.

Anyway, now that I use privatedisk, I have a question, when I defrag the HD, will it cause me any problems? What about when I backup, do I need to decrypt it first? Thanks

blueboy
Posts: 9
Joined: Thu May 12, 2005 12:57 pm

#4 Post by blueboy » Tue Sep 27, 2005 2:29 pm

as far as defrag it should not have any effect. private disk is seen as a single file and should stay that way. If you are backing up data i would recomend un-incripted for surity but thats just me :lol:

a31pguy
Moderator1
Moderator1
Posts: 605
Joined: Wed Mar 16, 2005 12:14 pm
Location: San Francisco Bay Area
Contact:

#5 Post by a31pguy » Wed Sep 28, 2005 12:43 am

Try Pointsec - I just completed a project on this and did a vendor RFI / vendor comparison. Leads the field currently on whole hard drive encryption.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#6 Post by s0larian » Wed Sep 28, 2005 6:14 am

a31pguy wrote:Try Pointsec - I just completed a project on this and did a vendor RFI / vendor comparison. Leads the field currently on whole hard drive encryption.
Can you provide us with a little more information? What are the key advantages/disadvantages of Pointsec over Utimaco Safeguard Easy? Does Pointsec support the IBM TPM Chip?

Thank You!
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

tom2517
Freshman Member
Posts: 109
Joined: Sun Jul 31, 2005 11:28 am

#7 Post by tom2517 » Wed Sep 28, 2005 7:41 am

s0larian wrote:
a31pguy wrote:Try Pointsec - I just completed a project on this and did a vendor RFI / vendor comparison. Leads the field currently on whole hard drive encryption.
Can you provide us with a little more information? What are the key advantages/disadvantages of Pointsec over Utimaco Safeguard Easy? Does Pointsec support the IBM TPM Chip?

Thank You!

Yes, that would be great.

a31pguy
Moderator1
Moderator1
Posts: 605
Joined: Wed Mar 16, 2005 12:14 pm
Location: San Francisco Bay Area
Contact:

#8 Post by a31pguy » Wed Sep 28, 2005 10:29 am

Whole hard drive encryption for one. Doesn't support the TPM chip - but the chip is hardware specific - which doesn't work across an enterprise with multiple hardware vendors. Blind password recovery (a challenge response recovery mechanism), windows password synchronization, LDAP/Active directory integration, no modifications to the boot sector, wake-on-lan support, SMS software package delivery, encrypts disk while you work, 3DES/AES cipher support, token authentication support. Remote policy pushes, 3 different options for enterprise management (active directory (Pointsec MI), Remote Help Server (Pointsec RH), or a File Share) console, not hardware specific, USB key fob encryption. Retail price $127/per seat. A Gartner Group report is available online - see "Magic Quadrant '05 - Mobile Data Encryption".

The chip is great - but for other purposes. Encryption cannot be tied to a specific vendor if data encryption is to succeed in protecting an organization. If you cannot deploy universally - then it defeats the purpose. It would only take one incident of confidential data leakage to cause damage.

Poinsec also offers phone/pda encryption as well.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#9 Post by s0larian » Thu Sep 29, 2005 6:15 am

ok, Pointsec sounds pretty much like Utimaco Safguard Easy. Except that Pointsec doesn't make modifiactions to the bootsector. This might be an advantage for some people. On the other hand Safeguard Easy supports IBM's TPM Chip (but you can install SGE without the TPM support as well), Client Security and Rescue & Recovery.

@a31pguy: Thanks for your Pointsec summary.
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

beq
Sophomore Member
Posts: 180
Joined: Mon Jan 31, 2005 2:17 am
Location: TX, USA

#10 Post by beq » Fri Oct 07, 2005 2:12 am

Just wondering, are we sure IBM's partner encryption products like Ultimaco Safeguard Easy (for whole hard drive encryption) or even the bundled PrivateDisk file encryption actually use the IBM TPM chip?

For other uses such as logon authentication, password manager, etc, the TPM chip seems to take quite a bit of time to process authentication, so I can't imagine it being fast enough for on-the-fly (realtime) encryption applications?

And even if I'm a home user (not enterprise), I can still see some drawbacks of having your encrypted data tied to a specific laptop hardware and not accessible otherwise. But then again that's also a benefit in some ways... :)

a31pguy
Moderator1
Moderator1
Posts: 605
Joined: Wed Mar 16, 2005 12:14 pm
Location: San Francisco Bay Area
Contact:

#11 Post by a31pguy » Fri Oct 07, 2005 7:05 pm

BTW - Windows Vista (formally codename: longhorn) will also support the TPM 1.2 chipset. Don't know about the T43 TPM - I know my A31p has spec 1.1 of the TPM. Newest features in VISA for security is whole hard drive encryption, anti-spware/anti-virus (soon to be called anti-malware), a new firewall, host hardening, and better user / profile restrictions. Maybe Microsoft isn't so idiotic about security after all.

Which seems to show that if your hardware will support the 1.2 spec of the TPM chip - you get these features bundled with the Vista OS. (BTW - I think I liked "Longhorn" better)

Perhaps TPM will become industry accepted in the future - but as of right now there are too many older/offbrand systems without the TPM or CPUs without buffer overflow prevention.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#12 Post by s0larian » Sat Oct 08, 2005 10:21 am

beq wrote:Just wondering, are we sure IBM's partner encryption products like Ultimaco Safeguard Easy (for whole hard drive encryption) or even the bundled PrivateDisk file encryption actually use the IBM TPM chip?

For other uses such as logon authentication, password manager, etc, the TPM chip seems to take quite a bit of time to process authentication, so I can't imagine it being fast enough for on-the-fly (realtime) encryption
Yes, we are sure. The TPM chip is just used for authentification, and the key and certificates can be stored in the chip. Unfortunately the authentification takes a few seconds, but after that encryption or decryption is just as fast as without the TPM chip. The TPM chip is just one more security layer, because no key is stored anymore on the harddisk. And it is more difficult to crack the chip to get the key.
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Thinkpad - General HARDWARE/SOFTWARE questions”

Who is online

Users browsing this forum: No registered users and 2 guests