When BitLocker made its debut in the form of Windows Vista, it could only encrypt the system volume. As of Vista SP1 and Server 2008, BitLocker could encrypt non-system volumes. Continuing the march of progress, in Server 2008 R2 (and Windows 7), BitLocker can be used to encrypt USB drives with a configurable-length passphrase.
This is good news for organizations trying to come to grips with the security risks of ever-increasing-capacity thumb drives. You can set a Group Policy to require BitLockering removable drives before you can write to them. As with prior versions of BitLocker, users can create, print, and/or store a recovery key, and the recovery key can be escrowed in Active Directory. The technology still seems to be volume-oriented in that you can’t encrypt particular folders and leave others alone. And Microsoft definitely has some work to do in making BitLockered USB drives conveniently readable in Vista and XP; the current system is a total kludge.
The biggest practical problem with BitLocker, though, as I learned from one of my certification bootcamp students, is that you have to hunt down a domain administrator to gain access to a recovery key if you need one. Depending on the organization, that could be a real bottleneck (it was in his). Microsoft needs to make recovery easier, and I’ll be surprised if they don’t do something along the lines of EFS recovery agents for BitLocker. We’ll see.
Recent posts:




