file security on T42

T4x series specific matters only
Post Reply
Message
Author
zver17
Freshman Member
Posts: 109
Joined: Mon Jan 10, 2005 1:37 pm
Location: Humbert, NJ

file security on T42

#1 Post by zver17 » Mon Jan 10, 2005 11:06 pm

I am curious about file security on T42. What exactly is the "security subsystem", "active protection system" and what is the difference between "admin" password (same as "supervisor" password?) and power-on password and HDD password?
my understanding is that winXP passwords can be bypassed simply by reinstalling windows on top of the existing one, whereas HDD passwords require more special software. What would the next step be in beefing up data security? What about EFS - does it provide any further protection beyond that given by the HDD password? I read somewhere that it can be bypassed fairly simply. I realise more generally no security is bomb-proof, so I am just looking at that break in the security vs cost/inconvenience curve beyond which things just get too complicated to maintain.
many thanks
z.

erik
moderator
moderator
Posts: 3596
Joined: Sun Apr 25, 2004 12:52 pm
Location: United States

#2 Post by erik » Tue Jan 11, 2005 1:00 am

the short answer is to not leave your thinkpad without bios and power-on passwords and don't let it get stolen.

the windows password can be reset if rebooted with certain linux-based software, making the power-on password crucial.   the hardware passwords can be reset if the thinkpad is stolen and the thief has the knowledge and hardware available to reset those passwords -- but, that's usually risky.   i don't know enough about the hard drive password to know what happens if that drive is installed in a non-ibm system which can read the drive's partitions.

ibm's active protection system is a gyroscopic sensor that monitors the hard drive's attitude and unmounts the read/write head in the event of shock or if the thinkpad is dropped.

hope that helps.

-erik
ThinkStation P700 · C20 | ThinkPad P40 · 600

zver17
Freshman Member
Posts: 109
Joined: Mon Jan 10, 2005 1:37 pm
Location: Humbert, NJ

#3 Post by zver17 » Tue Jan 11, 2005 1:14 am

thanks - very informative.

do you know if the power-on password is HDD-based or motherboard-based? Ie, does it remain useful if the laptop is stolen? that is the scenario I would be more concerned with.

From what I see I can have 4 passwords in a row operating at 4 distinct levels : power-on, BIOS, HDD and windows.

In addition, presumably smart-cards coud be used with HDD encryption - would they provide a further, different kind of protection?

btw, i am not totally paranoid - just wanted to understand it better once and forall.

s0larian
Junior Member
Junior Member
Posts: 289
Joined: Sat Jun 05, 2004 5:15 am
Location: Munich, Germany

#4 Post by s0larian » Tue Jan 11, 2005 8:24 am

There are 3 passwords you can configure in the Bios:

1. User Password: not safe at all, can be resetted through the cmos battery
2. HD Password: stored on the HD, pretty safe, but there are companies who can recover the content (with destroying the HD)
3. Supervisor password: for the Bios Access. If you know it, you need a new motherboard. I don't know if there is a workaround.

If you want further security: use Utimaco Safeguard Easy for full HD encryption. For Backups it works with IBM Rescue and Recovery (IBM and Utimaco have a partnership)
T40p 2373-g1g: 1.6 GHz, 1536 MB RAM, 160 GB @ 5400 rpm drive, 64 MB Video, IBM a/b/g II, CD-RW/DVD Combo II, M10 Fan, Ubuntu 8.04

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad T4x Series”

Who is online

Users browsing this forum: No registered users and 6 guests