My~Cuz~n~Vinny~ Posted May 4, 2013 Report Share Posted May 4, 2013 Most Big Banks use ( Encrypted File Systems) for the genuiness of their records. Can a discover question be raised to the plaintiff about the accuracy of their records? Like were there any security breaches on the account? If the records maintained by the plaintiffs witness, was the witness granted Administrator Privileges to the computer record? Does the plaintiff employ a records retention manager certified as havung Administrator Privileges? Was the witness certified with current EFS programs involving data recovery and storage removal if data was stored on another disk in the record retention department and transfers there of? EFS advantages and disadvantagesEFS technology makes it so that files encrypted by one user cannot be opened by another userif the latter does not possess appropriate permissions. After encryption is activated, the file remainsencrypted in any storage location on the disk, regardless of where it is moved. Encryptionis can be used on any files, including executables.The user with permission to decrypt a file is able to work with the file like with any other, withoutexperiencing any restrictions or difficulties. Meanwhile, other users receive a restricted accessnotification when they attempt to access the EFS encrypted file.This approach is definitely very convenient. The user gets the opportunity to reliably and quickly(using standard means) limit access to confidential information for other household members orcolleagues who also use the computer.EFS seems like an all-around winning tool, but this is not the case. Data encrypted using thistechnology can be entirely lost, for example during operating system reinstallation. We should remember that the files on disk are encrypted using the FEK (File Encryption Key),which is stored in their attributes. FEK is encrypted using the master key, which in turn is encryptedusing the respective keys of the system users with access to the file. The user keysthemselves are encrypted with the users’ password hashes, and the password hashes use theSYSKEY security feature.This chain of encryption, according to EFS developers, should reliably protect data, but in practice,as explained below, the protection can be ultimately reduced to the good old login-passwordcombination.Thanks to this encryption chain, if the password is lost or reset, or if the operating system failsor is reinstalled, it becomes impossible to gain access to the EFS-encrypted files on the drive. Infact, access can be lost irreversibly.Regular users do not fully understand how EFS works and often pay for it when they lose theirdata. Microsoft has issued EFS documentation that explains how it works and the main issuesthat may be encountered when encrypting, but these are difficult for regular users to understand,and few read the documentation before starting to work.4Data can be lost for goodLet’s figure out in what situations can EFS-encrypted data can be lost. How dangerous can asituation be? We’ll take it from the top.How can one lose access to EFS-encrypted data?Almost all of us have encountered a situation where it was necessary to fully reinstall Windows.This may have been due to the operating system’s functioning being disrupted by softwarefailure, a virus attack, or a mistake made by an inexperienced user, the system password for auser account was lost or a user profile was deleted. In this case, all encrypted data in the oldconfiguration would most likely be lost.Consider the following typical scenarios in detail:1. The system is not booting due a component having been replaced or failed or due tooperating system failure. For example, the motherboard is out of order, the boot sectoris damaged, system files are corrupted, some “half-baked” updates or a different unstablepiece of software was installed. In this case, the hard drive can be connected to a differentcomputer and the data can be read off it, but if it is EFS encrypted, this would not work.2. The system administrator at the company or the user has reset the user password. Inthis case, access to EFS-encrypted data would also be lost.3. The user profile was deleted. In this case, the files (and the user keys) may still be on thedisk, but the system cannot see them, even if the user is recreated with the same name, adifferent ID will be assigned to the account, which is used in the encryption process. In thissituation, access to the data encrypted using EFS will also be lost.4. The user is migrated to a different domain (is authenticated through a different server). Ifthe user encryption keys were stored on the server at the times of the migration (usually thisis the case), then an unprofessional migration can result in the loss of access to the EFS-encrypted data.5. System reinstallation. In this case, access to EFS-encrypted data would naturally be lost.If a backup copy of the entire system disk is made at the time, or at least of the user profile(“Documents and Settings”), then access could be restored with the use of special software,but only if the keys are not damaged.It is fairly common for the system itself to be stored on one disk, while encrypted files are storedon a different disk. When the administrator reinstalls the operating system, usually a backup ofjust the disk with the data is made and then the system is reinstalled. Obviously, in this case thekeys are lost and with them goes the access to encrypted data.It should be said that there is a straightforward way to avoid this situation, if before using EFS theEFS Recovery Agent is set up, but this, just like the workings of EFS in general, are too complicatedfor the average user, as demonstrated below.5What is the EFS Recovery Agent?The EFS Recovery Agent is a user with permission to decrypt data, encrypted by another user,if the latter lost the encryption certificate keys or if the user’s account was deleted, but the encrypteddata is needed.As a rule, the Recovery Agent is the Administrator, but it can also be a different user. There canbe multiple Recovery Agents. In order to assign Recovery Agent permissions to a user, first RecoveryAgent certificates need to be created using the command “Cipher /R: filename”, where“filename” is the path and name of the created certificates without the extension.After this, the user will be asked to enter a password to protect the private key and to confirm it(the password is not displayed in the console on entry). Then two files are created with the specifiedname: *.cer and *.pfx. These contain the public and private certificate keys, respectively.Now the certificate must be added to the user’s personal storage, specified by the RecoveryAgent (this step can be skipped, then the Recovery Agent can do it later, when the recoveryfunctions need to be used) importing the file *.pfx (double-click on the file icon to launch the certificateimport wizard). Here, the administrator had to open the “Local Security Settings” snap-in(Start - Run - secpol.msc), select “Public Key Policy - EFS” and in the menu “Action” select “AddData Recovery Agent.” The “Add Recovery Agent Wizard,” will open, and on the second pageone must click on “View folders” and select the *.cer file created earlier.In order to restore access to the encrypted files after system reinstallation or after a private keyhad been lost, the Recovery Agents’ private keys must be kept in a secure location or (if theyare not assigned), the private keys of all users using EFS, by exporting them from the “Private”depository of the “Certificates” snap-in (certmgr.msc). In Windows Vista, there is finally a way tostore the keys on a smart card, which is much more reliable in terms of security.It is clear that this kind of safety measure with the use of the EFS Recovery Agent contradictsits intended principle of simplicity and requires non-trivial, from the average user’s point of view,though routine for an administrator, actions and manipulations. It is no surprise that few use it.It should be noted that if the administrator tried to reset the account password for a local user,the user will lose all private certificates and with them the access to EFS-encrypted files (a correspondingwarning will appear when this action is attempted). The same will happen if the localadministrator, using special means, tried to force a password change (i.e., without entering theold password).Consequently, the risk of losing the most important data, encrypted using EFS technology, whenthere is a system failure or due to an administrator/user error, is rather high and must always be taken into consideration. Link to comment Share on other sites More sharing options...
nascar Posted May 5, 2013 Report Share Posted May 5, 2013 You can ask anything you want. If the requested information is reasonably calculated to lead to the discovery of admissible evidence, you should get it. Ask yourself if the evidence you seek is admissible. Is it relevant? Evidence is relevant if it has any tendency to make the existence of any fact that is of consequence to the determination of the action more probable or less probable than it would be without the evidence. 2 Link to comment Share on other sites More sharing options...
My~Cuz~n~Vinny~ Posted May 6, 2013 Author Report Share Posted May 6, 2013 You can ask anything you want. If the requested information is reasonably calculated to lead to the discovery of admissible evidence, you should get it. Ask yourself if the evidence you seek is admissible. Is it relevant? Evidence is relevant if it has any tendency to make the existence of any fact that is of consequence to the determination of the action more probable or less probable than it would be without the evidence. Thanks nascar! The OC in my case is all over the place regarding inept , patently false and missing information in documentation they sent me in favor of their MSJ which they lost twice regarding record keeping. Link to comment Share on other sites More sharing options...
Recommended Posts