Microsoft Tightens USB Flash Drive Security
Microsoft is finally getting serious about USB flash drive security. It recently disabled the AutoRun and AutoPlay features in Windows (all older versions plus Windows 7), meaning users will no longer have directory trees and execution options presented when they pop a flash drive into a PC. More significant, though, is Microsoft adding flash drive encryption to Windows 7. Through a few, albeit not so simple steps (see below), users can encrypt and manage the files on these small, portable storage devices. Both are significant moves by Microsoft to improve the security of USB flash drives, which are increasingly being leveraged by hackers and malware writers to capture data and exploit machines. They are also increasingly a source of data loss and leakage. But how significant are these security measures by Microsoft? That's a difficult question to answer. USB flash drives have evolved in recent years from low-volume, low-capacity novelties to indispensable business tools and the foundation for countless electronic devices. Flash drives' small profile, ever-increasing capacity, high read-write rates, low energy consumption and, most significantly, declining costs have made them as ubiquitous as floppies were in the '90s. They are extremely useful in making data portable without overburdening users the way floppies and discs did. But those same elements have made flash drives a tempting carrier of malicious activity. Malware writers have revived the “sneakernets” of old with flash drives, hiding viruses and Trojans on the portable devices. The Windows AutoPlay feature made the sneakernet viable again by allowing executables to automatically surface with little to no user action. Some critics on various blogs have stated that Microsoft should take the additional step of eliminating AutoPlay on the optical drives; that's also a good idea but increasingly less relevant as CDs and their drives go the way of floppies. Flash drives are increasingly a source of data loss. Users often plug in flash drives or flash-enabled electronics, such as an iPhone, to take data outside the corporate domain. Sometimes the data is being outright pilfered, such as in several identity theft cases. Other times, data is being exposed because the device is lost or stolen. Flash drive encryption has been available for some time, but typically as a value-add solution. Microsoft's inclusion of the “BitLocker to Go” application will go a long way in preventing the accidental loss or disclosure of confidential data. According to Win7News, Windows 7's Bitlocker feature works this way:
We haven't actually used the encryption feature, but it looks relatively simple to use and will probably provide strong enough protection for average users. What it seemingly lacks is central manageability of both encryption keys and devices, such as provided by SanDisk's Enterprise Secure USB Drive. Enterprise users will likely appreciate the encryption function, but will probably turn to solution providers for more robust packages that afford centralized manageability, auditing and compliance. |

Comments (4)
what a bunch of bull.
this is strictly a corporate request so all that important financial information and secret don't get out of the company. and to also make windows more proprietary so we can share data with that nasty linux competition.
why would a hacker use a usb drive when you physically have to be at the machine when there is the security wholes of outlook and internet explorer posing as an email client and browser.
here is a thought how about declaring any use of active x illegal. there I just took care of about 60% of the security breaches.
Posted by suezz | September 16, 2009 9:01 AM
Speaking of nasty, it's MS that qualifies for that.
There is nothing nasty about Linux.
What would it do to a usb drive that's formatted with ext3 or Reiser? Knowing MS, their software would attempt to reformat it to NTFS without any warning. I think I'll reformat all of my flash drives to ext3 so those thieving Window's users can't steal anything from me.
It's not protection from hackers, but protecting data from proprietary crap ware!
Posted by John Bowling | September 17, 2009 5:08 AM
I Like Your post i found it very useful.All the useful information provided by you in this post
sounds very secure.Now a days data security is very important fact.For data security
USB Security has Become other important
factor.
Great Work.
-Thanks for Posting and bringing awareness among data security.
Posted by Safe Stick | October 5, 2009 10:45 AM
Using bitlocker and bitlocker to go on our Win 7 systems in conjunction with Active directory policies.
We are looking to supplement this with a way to centrally audit what is copied to the usb drives when on company network and copied off it say when the usb drive is taken off the company network (and then returned)? It would probably need to be some applet that stays hidden on the usb drive and will monitor and log all activity to the usb drive and then upload to a central location.
Thank you
Posted by DJ Bhatia | June 16, 2010 11:20 AM