Jump to content

Encrypted folder - Windows XP SP3


dc2000
 Share

Recommended Posts

Hi everyone:

I've never tried it before, so please bear with me. I got a second hard drive for my Windows XP SP3 system and I moved some bulky folders off of my documents into it. I know that My Documents folder was protected by my Windows user password, but when I moved my files to a separate hard drive this password protection went away. To restore it, I went to the folder on a new hard drive, right-clicked on it, went into properties, then advanced and set Encrypt contents check to on (see screenshot). Then it took almost a day (for 211 GB folder) to apply! and now what happens is that when I log in under a different user account I can still see files on that folder, but when I try to open them I get Access Denied message.

So here are my questions:

(1) Is it possible to set it up so that folders were not openable on that drive from outside of my original user account? Or at least, so that file names didn't show?

(2) If I decide to upgrade and move that second hard drive to a new computer, how can I be able to access it there?

(3) Just curious, how secure is such protection? I know it depends on the strength of my password, but say, if the password is a 6 letter word that is not a word from a dictionary, it is not in any way associated with me, nor it's written anywhere on my actual desk :) So, just curious ...

Thanks in advance...

post-10969-1259699848_thumb.jpg

Link to comment
Share on other sites

I'm not sure about the correct answers to all your questions, but, in general, since the conditions covering Windows encryption also apply across the internet (including email) they should apply to an external hard drive. Perhaps you could experiment a little using some unimportant files and folders.

Be aware that encryption has it's own inherent dangers, e.g. if you lose your key, the data is lost to you forever (unless you go to a forensic expert), also if the key or the system becomes corrupt, the same thing applies. For those reasons encryption should only be carried out if it's absolutely essential.

You can purchase large capacity USB drives with software password capabilities, but the same possibility of the protection becoming corrupt also applies - in which case you find you can't access your files.

Some of the answers to your questions depend on the make of the external hard drive, so it might be worth while going to the maker's website and seeing if they have a FAQ page or a users group you can consult.

A password of only 6 letters is not strong. For maximum security the guidelines are:

-make it as long as possible - at least 14 digits;

-don't use complete words no matter how obscure, use a meaningless combination of letters (upper and lower case) and symbols;

-for maximum security, change it periodically.

By the way, there's no such thing as a completely secure electronically stored data. If it's stored, it's potentially accessible to people with the appropriate tools & abilities.

Link to comment
Share on other sites

Thank you, guys. I don't think I want to use any third party encryption, especially anything that's open source. There's too much to lose for me here :)

I also probably did not express myself right. I was talking about an internal hard drive that I'm using besides the one that is used by Windows (i.e. C:).

I'm still puzzled by one dilemma -- why is that EFS encryption still showing file names when I try to access it from unauthorized account? That is kinda like a major flaw. isn't it? Does anyone know how to fix it?

I found one solution to add user restrictions, but somehow I can't find the Security tab in the Properties for any folders on that HDD (drive E:) to add user access restrictions. Again, I'm using Windows XP SP3 Pro.

Link to comment
Share on other sites

The default XP setting is that the names of hidden files and folders are displayed in green in Windows Explorer. Have you tried the standard XP method of hiding folders? Right click on the folder, select Properties > General, then check Hidden. There's also various items of 3rd party software you can use to hide folders and files, see THIS LIST. Experiment with unimportant folders in case things get messed up.

For a good introduction to encryption in XP see chapter 21 of "Microsoft Windows XP Networking and Security" by Bott and Siechert.

Link to comment
Share on other sites

Be aware that encryption has it's own inherent dangers, e.g. if you lose your key, the data is lost to you forever (unless you go to a forensic expert), also if the key or the system becomes corrupt, the same thing applies. For those reasons encryption should only be carried out if it's absolutely essential.

You can purchase large capacity USB drives with software password capabilities, but the same possibility of the protection becoming corrupt also applies - in which case you find you can't access your files.

I don't think encryption on Windows requires keys to open the files. It's based on or in the Encryption File System (EFS). EFS isn't as good as Gpg. :)

Well, I didn't mean that. What I was talking about is that if someone gets hold of my encrypted drive and is able to see the file names and file structure of the encrypted disc. Wouldn't that be a breech in security?

Either that or theft.

Link to comment
Share on other sites

Well, I didn't mean that. What I was talking about is that if someone gets hold of my encrypted drive and is able to see the file names and file structure of the encrypted disc. Wouldn't that be a breech in security?

Well that's the default setting - they are listed but cannot be opened except by the person who knows the access keys, or, of course, a skilled computer forensic expert. But if someone got hold of your encrypted drive and had the necessary skills they would be able to read the files even if they were completely hidden and encrypted. There is no way to make electronically stored data completely inaccessible to someone with the right skills and technology. The best that can be done is to make access very difficult - but that doesn't mean impossible.

But you can hide the files from appearing, I believe, by following the advice I gave earlier.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy