Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > What are the risks of turning off pre-boot authentication?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What are the risks of turning off pre-boot authentication?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 June 2007
I recently read about full-disk encryption (FDE) products that turn off pre-boot authentication to provide transparent single sign-on and help with patch management. What are the risks of turning off PBA.

>
EXPERT RESPONSE
The risks associated with turning off pre-boot authentication (PBA) are actually quite high, and it's not a recommended best practice. Pre-boot authentication is the whole point of full-disk encryption (FDE) and, in fact, is what makes FDE such a powerful tool for protecting data.

First, let's briefly explain what pre-boot authentication is and its role in FDE. Pre-boot authentication is a process that requires a user to authenticate prior to the operating system loading. In other words, on a system with pre-boot authentication installed, the user is prompted for a user ID and password before the system boots up. Once the user successfully logs in, then the operating system starts. If the user enters the wrong user ID and password, the operating system won't load and the computer locks up.

Pre-boot authentication prevents the common hacker trick of using a Linux boot disk, like Knoppix, to bypass the operating system authentication and enter the system without login credentials. Pre-boot authentication operates at a lower level than the operating system. If the OS doesn't load, then the tools that try to bypass it won't work and attackers won't even get a chance to maliciously enter the system.

Pre-boot authentication is also cross-platform. It not only blocks Linux CDs but also blocks Windows emergency disks that might be used to gain access to Microsoft systems.

Pre-boot authentication doesn't operate alone; it works hand-in-hand with FDE, operating as a front-end to FDE applications. Products such as SafeBoot, SafeGuard and SafeNet, which offer FDE, encrypt the hard drive silently in the background. The pre-boot authentication generates the key needed to encrypt the hard drive and then decrypt it later when the system is booted up again.

FDE tools are great for protecting data loss from stolen laptops. If a thief -- or malicious user, for that matter -- tries to turn on the computer, he or she will be blocked by the pre-boot authentication – and a boot disk won't help them get in either. The attacker will be stuck with an encrypted hard drive.

With PBA turned off, not only could the attacker possibly get access to the machine, but the hard drive might also not be encrypted. It's not necessary to turn off pre-boot authentication to enable single sign-on (SSO) or patch management.The commercial FDE products mentioned above can be adapted to SSO, and fully integrated with common authentication systems like Active Directory and LDAP.

Finally, if something stronger than just a plain old user ID and password is required for higher-risk data, pre-boot authentication can be integrated into two-factor authentication systems such as smart cards or biometrics.

For more information:

  • Security expert Joel Dubin examines what components are necessary to create a secure authentication system.
  • Learn how data loss can be controlled with full-disk encryption.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    What precautions should be taken if biometric data is compromised?
    How to choose the right biometric security product
    How to prevent hackers from accessing your router security password
    How does identity propagation work?
    Is it secure to use .NET membership class for user authentication?

    Disk Encryption and File Encryption
    Websense, Reconnex top Forrester ranking of DLP vendors
    Embedded Security Safeguards Laptops
    Should whole disk encryption products be used with data backup software?
    Does FTPS encrypt data packets at the hardware or software level?
    Should disks be encrypted at the hardware level?
    Is Triple DES a more secure encryption scheme than DUKPT?
    Windows BitLocker: Enabling disk encryption for data protection
    NAC, disk encryption gaining attention, survey shows
    Symantec fills gap with whole disk storage encryption
    Case Study: Company Deploys Full-Disk Encryption on All Laptops

    Enterprise Single Sign-On (SSO)
    Startup Symplified delivers SSO in the cloud
    SaaS Offering Handles SSO
    Kerberos security evolves for B2B, mobile tech
    IBM acquires Encentuate for single sign-on software
    Security360: Identity management market
    Top 10 access-related controls for PCI compliance
    What type of protections should security question and answer authentication credentials have?
    Traditional single sign-on (SSO) products versus federated identities
    Best practices for deploying enterprise single sign-on (SSO)
    Does single sign-on (SSO) improve security?
    Enterprise Single Sign-On (SSO) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Advanced Encryption Standard  (SearchSecurity.com)
    data key  (SearchSecurity.com)
    Encrypting File System  (SearchSecurity.com)
    Escrowed Encryption Standard  (SearchSecurity.com)
    International Data Encryption Algorithm  (SearchSecurity.com)
    network encryption  (SearchSecurity.com)
    output feedback  (SearchSecurity.com)
    quantum cryptography  (SearchSecurity.com)
    Quiz: Cryptography  (SearchSecurity.com)
    Rijndael  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts