ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Force USB encryption Windows and Mac

    IT Discussion
    10
    112
    4.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DashrenderD
      Dashrender
      last edited by

      Anyone using a solution that forces USB drives to be encrypted when connected to a PC? I need a solution that works for both Windows and Macs.

      DustinB3403D 1 Reply Last reply Reply Quote 0
      • DustinB3403D
        DustinB3403 @Dashrender
        last edited by

        @Dashrender said in Force USB encryption Windows and Mac:

        Anyone using a solution that forces USB drives to be encrypted when connected to a PC? I need a solution that works for both Windows and Macs.

        You mean like ransomware?

        I'm not understanding what you want with "force USB encryption"

        You can use Veracrypt and encrypt any USB volumes that'll work on Windows and Mac (specifically without needing admin rights to mount).

        DashrenderD 1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender @DustinB3403
          last edited by

          @DustinB3403 said in Force USB encryption Windows and Mac:

          @Dashrender said in Force USB encryption Windows and Mac:

          Anyone using a solution that forces USB drives to be encrypted when connected to a PC? I need a solution that works for both Windows and Macs.

          You mean like ransomware?

          I'm not understanding what you want with "force USB encryption"

          You can use Veracrypt and encrypt any USB volumes that'll work on Windows and Mac (specifically without needing admin rights to mount).

          LOL - exactly.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            No, An insurance company wants us to have a technical solution in place that when a USB drive is inserted into a computer, that the drive is only usable if the drive is encrypted.

            DustinB3403D 1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @Dashrender
              last edited by DustinB3403

              @Dashrender said in Force USB encryption Windows and Mac:

              No, An insurance company wants us to have a technical solution in place that when a USB drive is inserted into a computer, that the drive is only usable if the drive is encrypted.

              You would have no way to do this.

              You can setup encrypted volumes on USB drives you control, but there would be know way to do this for every USB drive.

              DashrenderD stacksofplatesS 2 Replies Last reply Reply Quote 0
              • DashrenderD
                Dashrender @DustinB3403
                last edited by

                @DustinB3403 said in Force USB encryption Windows and Mac:

                You would have no way to do this.

                You can setup encrypted volumes on USB drives you control, but there would be know way to do this for every USB drive.

                This is my initial reaction too.. but I'm trying to turn over a new leaf, and say 'yes.' which in this case starts with researching possible solutions.

                I'm wondering if there is some type of MDM/end user device management (something like Intune).

                DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                • DustinB3403D
                  DustinB3403
                  last edited by

                  I am going to guess that this insurance company has some statement that only encrypted drives are permitted to be used, but you can't encrypt something without first connecting it to some system.

                  So the entire policy is just stupid.

                  1 Reply Last reply Reply Quote 1
                  • DustinB3403D
                    DustinB3403 @Dashrender
                    last edited by

                    @Dashrender said in Force USB encryption Windows and Mac:

                    @DustinB3403 said in Force USB encryption Windows and Mac:

                    You would have no way to do this.

                    You can setup encrypted volumes on USB drives you control, but there would be know way to do this for every USB drive.

                    This is my initial reaction too.. but I'm trying to turn over a new leaf, and say 'yes.' which in this case starts with researching possible solutions.

                    I'm wondering if there is some type of MDM/end user device management (something like Intune).

                    How would it encrypt the drive? That would mean it would realistically ransomware people's devices if they mistakenly plug a personal USB into a work computer.

                    DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @DustinB3403
                      last edited by

                      @DustinB3403 said in Force USB encryption Windows and Mac:

                      @Dashrender said in Force USB encryption Windows and Mac:

                      @DustinB3403 said in Force USB encryption Windows and Mac:

                      You would have no way to do this.

                      You can setup encrypted volumes on USB drives you control, but there would be know way to do this for every USB drive.

                      This is my initial reaction too.. but I'm trying to turn over a new leaf, and say 'yes.' which in this case starts with researching possible solutions.

                      I'm wondering if there is some type of MDM/end user device management (something like Intune).

                      How would it encrypt the drive? That would mean it would realistically ransomware people's devices if they mistakenly plug a personal USB into a work computer.

                      yes it would... or at least could...

                      I would assume it would work something like this:

                      Insert the drive, it's scanned to see if it's encrypted - if not, a dialog would pop and say - this drive is not encrypted, due to policy only encrypted drives can be attached to this device. Do you want to encrypt this drive? (if yes, all data currently on this device will be lost).

                      then I would expect it to prompt me for a password to use to decrypt the drive.

                      the bigger issue I see is - how will it KNOW it's encrypted? There are tons of different types of encryption. It's unlikely that any solution would know them all.

                      DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                      • DashrenderD
                        Dashrender
                        last edited by

                        Here is the statement from the insurance company, perhaps I'm reading it wrong.

                        88a90920-77f4-4f1d-9ad8-e5530860b514-image.png

                        DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                        • DustinB3403D
                          DustinB3403 @Dashrender
                          last edited by

                          @Dashrender how the f*** would you know if it's encrypted or not all I would see is zeros and ones?

                          1 Reply Last reply Reply Quote 0
                          • black3dynamiteB
                            black3dynamite
                            last edited by

                            https://www.sophos.com/en-us/products/safeguard-encryption.aspx

                            DashrenderD 1 Reply Last reply Reply Quote 0
                            • DustinB3403D
                              DustinB3403 @Dashrender
                              last edited by

                              @Dashrender said in Force USB encryption Windows and Mac:

                              Here is the statement from the insurance company, perhaps I'm reading it wrong.

                              88a90920-77f4-4f1d-9ad8-e5530860b514-image.png

                              Yeah that makes 0 f****** sense.you can encrypt the drives that you own but you have no way to actually tell that a drive or volume is encrypted because the computer needs to know what format is used to encrypt it and would have to know what the password is in order to decrypt it to be able to tell if it's all

                              1 Reply Last reply Reply Quote 0
                              • DustinB3403D
                                DustinB3403
                                last edited by

                                You need to update your policy that any device that isnt encrypted cannot be used on company provided devices without first having an encrypted volume created on it this would fix your policy issue and address the concern of non-encrypted volumes being used on company devices

                                DashrenderD 1 Reply Last reply Reply Quote 0
                                • DustinB3403D
                                  DustinB3403
                                  last edited by

                                  The policy is the issue that is caused your impossible question simply update your policy to say that any external storage devices need to be encrypted before they can be used on company equipment by the IT department and any devices that is not provided by the IT department cannot be used on company equipment

                                  1 Reply Last reply Reply Quote 0
                                  • DashrenderD
                                    Dashrender @DustinB3403
                                    last edited by

                                    @DustinB3403 said in Force USB encryption Windows and Mac:

                                    You need to update your policy that any device that isnt encrypted cannot be used on company provided devices without first having an encrypted volume created on it this would fix your policy issue and address the concern of non-encrypted volumes being used on company devices

                                    that is not a technical safeguard.. that's only a policy based one.. and clearly not good enough according to what the request has stated.

                                    DustinB3403D scottalanmillerS 2 Replies Last reply Reply Quote 0
                                    • DashrenderD
                                      Dashrender @black3dynamite
                                      last edited by

                                      @black3dynamite said in Force USB encryption Windows and Mac:

                                      https://www.sophos.com/en-us/products/safeguard-encryption.aspx

                                      OK - this looks promising.

                                      1 Reply Last reply Reply Quote 0
                                      • DustinB3403D
                                        DustinB3403 @Dashrender
                                        last edited by

                                        @Dashrender said in Force USB encryption Windows and Mac:

                                        @DustinB3403 said in Force USB encryption Windows and Mac:

                                        You need to update your policy that any device that isnt encrypted cannot be used on company provided devices without first having an encrypted volume created on it this would fix your policy issue and address the concern of non-encrypted volumes being used on company devices

                                        that is not a technical safeguard.. that's only a policy based one.. and clearly not good enough according to what the request has stated.

                                        The insurance statement is made in response to the shitty policy.

                                        Fix the policy, and then the insurance request is resolved.

                                        DashrenderD 1 Reply Last reply Reply Quote 0
                                        • DustinB3403D
                                          DustinB3403
                                          last edited by

                                          In your example of a user plugging in a device that's encrypted already and then this is asked if they want to encrypt that the device and they say no would mean that the system would report that there's a unencrypted device because it doesn't know the difference.

                                          That's way more troublesome than just fixing your policy.

                                          1 Reply Last reply Reply Quote 0
                                          • DashrenderD
                                            Dashrender @DustinB3403
                                            last edited by

                                            @DustinB3403 said in Force USB encryption Windows and Mac:

                                            @Dashrender said in Force USB encryption Windows and Mac:

                                            @DustinB3403 said in Force USB encryption Windows and Mac:

                                            You need to update your policy that any device that isnt encrypted cannot be used on company provided devices without first having an encrypted volume created on it this would fix your policy issue and address the concern of non-encrypted volumes being used on company devices

                                            that is not a technical safeguard.. that's only a policy based one.. and clearly not good enough according to what the request has stated.

                                            The insurance statement is made in response to the shitty policy.

                                            Fix the policy, and then the insurance request is resolved.

                                            How do you figure? We haven't even shown them the policy.. only mentioned we have one.

                                            DustinB3403D 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 1 / 6
                                            • First post
                                              Last post