May 2, 2006
Windows Vista’s Bitlocker Overview
Bruce has a good overview of the upcoming features of BitLocker, the whole disk encryption feature of Windows Vista. In typical style, he analyzes the encryption (thumbs up), and talks about the practical of implementation:
For most people, basic mode is the best. People will keep their USB key in their computer bag with their laptop, so it won’t add much security. But if you can force users to attach it to their keychains — remember that you only need the key to boot the computer, not to operate the computer — and convince them to go through the trouble of sticking it in their computer every time they boot, then you’ll get a higher level of security.
This is a particularly timely features as large organizations try to deal with data leakage by lost or stolen hardware. There certainly is enough of it happening.
The real question will be managability. XP SP2 firewall is adequate for most purposes, but most large organizations don’t use it because it’s difficult to manage on a large scale.



