BLOG

This is SmallBizPod's blog dedicated to practical advice, news and insight for small business owners, entrepreneurs, and anyone needing help starting a business. You can read all sections of the blog from here or go straight to the topic you prefer by clicking the appropriate channel above.

Sponsors

Freeform Dynamics sponsors SmallBizPod's blog


Encrypt your memory sticks (HMG)

Yet another security breach fo the Home Secretary to wrestle with. This time PA Consulting managed to lose a memory stick containing some rather sensitive information. According to the BBC, “The memory stick contained un-encrypted details about 10,000 prolific offenders as well as names, dates of births and some release date of all 84,000 prisoners in England and Wales - and 33,000 records from the police national computer.”

It’s quite unbelievable that the information was not encrypted before placing it on the stick. Or that the stick didn’t have some built-in encryption itself.

“It can’t be rocket science,” thought I. And, in about two minutes, I’d Googled an answer. It’s possible to encrypt these drives easily and at zero cost, apart from some time, using an open source program from TrueCrypt.

So, for anyone uneasy about securing the information that leaves their organisation on memory sticks, here’s how to protect yours. If it looks too techie, give this blog and your sticks to a techie and he or she will sort you out. A special folder will be created on the stick which, when plugged into a computer, acts exactly like a disk drive. Except, of course, everything in it is encrypted.

Preparing an encrypted drive on your memory stick

1 ) Visit TrueCrypt http://www.truecrypt.org/downloads.php and download the version for your computer type. The instructions that follow are biased towards a Windows PC. (Vista in my case.)

2 ) Run the downloaded program, accept the licence terms and select the ‘Extract’ option. This puts all the TRUECRYPT files into a folder.

3 ) Empty the memory stick of its contents - I copied mine to a folder on my computer and then deleted them.

4 ) Copy across TrueCrypt.exe, truecrypt.sys and TrueCrypt Format.exe from the TrueCrypt folder to your memory stick. They may come in handy when you go to another computer.

5 ) Run TrueCrypt.exe from your computer or from your stick and click on Create volume then, in the dialogue that appears, choose the ‘Create a file container’ option. Click Next.

6 ) In the Volume Type dialogue that appears, choose ‘Standard TrueCrypt volume. Click Next.

7 ) Type the drive letter of your thumb drive followed by :\ then the name you want to give the folder. I chose f:\myfolder. ‘Never save history’ is already checked, so I left it alone. Click Next.

8 ) You’ll be asked to choose your encryption options. Unless you have mugged up on the subject, you may as well accept the defaults. Click Next.

9 ) You’re shown how much space you have and are invited to provide a container size. I was using a 500MB card, so I settled for 400MB, in case I needed to keep some non-encrypted files on the thumb-drive as well. (Such as the TrueCrypt files that I copied just now.) Click Next.

10) Now it’s time to provide the password. Helpful suggestions are provided on screen. Hope you don’t mind if I keep mine a secret! I left ‘Use keyfiles’ and ‘Display password’ unchecked. Click Next.

11) Waggle your mouse over the next box for thirty seconds or so in order to generate an encryption key. Accept the defaults (unless you know what you’re doing) and click Format. Wait until a dialogue box appears to announce that it has finished - it will be a little while after the on screen counters stop counting.

12) A ‘Volume Created’ dialogue box appears. Click OK then click Exit in the Volume created dialogue.

That’s it. 12 steps that need to be taken only once to protect (part of) a thumb drive. Is this too much to ask of government employees and contractors?

Mounting the encrypted drive

Whenever you want to use the encrypted part of the drive, you need to run TrueCrypt. If it’s not on the target machine, run it from your memory stick.

The first thing you need to do is to assign the encrypted folder to a spare drive letter. TrueCrypt provides a list of spares - take your pick. Z is good, and unlikely to be claimed by the system for anything else.

Use ‘Select file…’ to locate your encrypted folder on the memory stick. Click Open.

Now Click Mount.

You will be asked for your password. Provide it and Click OK.

You will see that details appear against the appropriate drive letter. You can open it immediately by double clicking on it.

You will not be asked for your password again until you need to remount the drive.

Using the encrypted drive

Now just use it as a normal drive - you can open files and drag and drop them just as you would on any other drive.

When you’re done, choose the dismount option from TrueCrypt. You should then perform the ‘Eject’ operation if available (right-click the device in the ‘Computer’ or ‘My Computer’ list), or use the ‘Safely Remove Hardware’ function (built into Windows, accessible via the taskbar notification area). Otherwise you could lose some data.

If you have a power cut or the memory stick is removed any other way, the content of the encrypted folder always remains encrypted

A user guide is provided as part of the download. It will give you all sorts of additional clever tricks and advice. But what I’ve outlined here is safe. It works.

Perhaps someone should tip off PA Consulting and the Home Office about this blog …

Related Posts

Alibaba.com sponsors SmallBizPod small business podcast

Sponsor SmallBizPod - the podcast for small business and entrepreneurs



4 Comments »

Subscribe to SmallBizPod feedRSS feed for these commments. SmallBizPod trackbackTrackBack address

    As you say, encryption is easy. The Justice Ministry data was lost because it was there to be lost.

    The real question remains: Why should such sensitive data be removed in the first place?

    I am not convinced that losing sensitive data on an encrypted device is really any better than losing unencrypted data, the principle of neglect remains.

    The latest debacle is symptomatic of a shoddy ignorance when it comes to securing sensitive information. Why can’t HMG apply the same handling rules for databases that they apply to printed documents in secure registries?

    Comment by Colin Beveridge — 25 August 2008 #

    Good question Colin.

    Accepting that government departments, agencies and suppliers are incontinent when it comes to our records, I figured it worth showing how trivial a reasonable fix would be. And, more to the point, show our readers how easily they could deal with the same issue themselves.

    Then comes the much harder bit of changing the culture…

    Comment by David Tebbutt — 25 August 2008 #

    Just wanted to say thank you. The news story bought to my attention the lack of security on my own memory stick (nothing quite as sensitive as the recent news) and thanks to your very useful and informative blog I now know how damn easy it actually is.
    Thanks again.

    Comment by Lee — 27 August 2008 #

    Hey. Thanks for the thanks, Lee. And you’re very welcome.

    Comment by David Tebbutt — 27 August 2008 #

Leave a comment

XHTML: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Alibaba.com sponsors SmallBizPod small business podcast

Podcasts

Subscribe to small business podcast on iTunes

Click on one of the blue triangles below on the right to listen to inspirational interviews with entrepreneurs from the SmallBizPod archive.

SmallBizPod #33 - overcoming the business skills shortage

SmallBizPod #33 - overcoming the business skills shortage

Jo Ray of Sage, Mike Harris of the Institute of Directors and Lawrence Jones of UKFast talk about recruitment and the skills shortage facing UK small businesses.

play small business podcast now
SmallBizPod #40 - Interview with Colin Crooks of Greenworks

SmallBizPod #40 - Interview with Colin Crooks of Greenworks

Colin Crooks, managing director of Greenworks, talks about recyclying business and the challenges and benefits of social entrepreneurship.

play small business podcast now
SmallBizPod #66 - Dan Harple, entrepreneurship and the mobile web

SmallBizPod #66 - Dan Harple, entrepreneurship and the mobile web

Dan Harple, veteran internet entrepreneur and ceo of mobile networking platform GyPSii, interviewed on search, the mobile web, entrepreneurship and the European tech scene.

play small business podcast now
SmallBizPod #51 - Interview with thebestof

SmallBizPod #51 - Interview with thebestof's Nigel Botterill

Nigel Botterill, founder and managing director of theBestOf on business growth, franchising, online business & big ideas.

play small business podcast now

Small Business Podcast RSS FeedWhat is this? Small Business Podcast RSS FeedMore business podcasts

Recent

Comments
  • David Tebbutt: Cheers Simon. That one’s been popular with BrainStorm users for years. It’s pretty relaxed...
  • Simon JOnes: I’m using FreeMind, which is Java-based,cross-platform and free. It really helps when trying to...
  • Dan Wilson: @ed from builaskill. Only one correction: I am not a vzaar employee or working for them. eBay and Amazon...
  • Adaptiv Media: Great read, exposing eBay’s dastardly new(ish) policies. Since killing off its digital...
  • Alex Bellinger: Thanks Martyn, the cashflow issue hadn’t occurred to me and exactly why your insight here is so...
  • Martyn: >> Non-registered Agreed that their inputs will fall by 2% but they may have to cut their prices to...
  • Alex Bellinger: Hi Martyn Indirectly, I guess, assuming it helps to stimulate spending. Alex P.S. Forgot to say, many...
  • Martyn: Alex How does a cut in VAT help small business? Martyn
  • Ed: Good old Dan The ex-eBay employee is always a good read (no, seriously, he is), and always ready to plug his...
  • Sherry Borzo: Thanks for the silver lining news and ha, ha, on the blowing bit. Nothing like tooting the horn for...

Topics
  • Archives
    Contact

    Other Info

    Check out other information and ways to subscribe for free to this blog

    • Add to Google
    • Subscribe in NewsGator Online
    • Subscribe in Bloglines
    • Add SmallBizPod - small business blog to Newsburst from CNET News.com
    • Small Business Blogs - BlogCatalog Blog Directory

    Small Business Trends review

    Creative Commons License

    © Copyright BizPod Media Ltd, 2005-2008