<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to create secured Outlook data files</title>
	<atom:link href="http://www.online-tech-tips.com/cool-websites/secure-outlook/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/</link>
	<description></description>
	<lastBuildDate>Mon, 23 Nov 2009 13:38:56 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: How to recover a lost PST password for free</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-19456</link>
		<dc:creator>How to recover a lost PST password for free</dc:creator>
		<pubDate>Thu, 16 Apr 2009 10:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-19456</guid>
		<description>[...] April 16th 2009&#160;&#160;&#160;  16Apr         Previously, I’ve written about how you can secure your Outlook PST file with a password, which is great, unless you forget the PST password! Luckily for you, the password encryption for a [...]</description>
		<content:encoded><![CDATA[<p>[...] April 16th 2009&nbsp;&nbsp;&nbsp;  16Apr         Previously, I’ve written about how you can secure your Outlook PST file with a password, which is great, unless you forget the PST password! Luckily for you, the password encryption for a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ben</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8798</link>
		<dc:creator>ben</dc:creator>
		<pubDate>Fri, 20 Jun 2008 01:56:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8798</guid>
		<description>Haha! the guys at University of California, Berkeley went as far as making an algorithm to listen to keyboard sounds to crack anything typed on the keyboard with a 10$ microphone!

http://news.zdnet.com/2100-1009_22-5865318.html</description>
		<content:encoded><![CDATA[<p>Haha! the guys at University of California, Berkeley went as far as making an algorithm to listen to keyboard sounds to crack anything typed on the keyboard with a 10$ microphone!</p>
<p><a href="http://news.zdnet.com/2100-1009_22-5865318.html" rel="nofollow">http://news.zdnet.com/2100-1009_22-5865318.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Hunter</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8787</link>
		<dc:creator>Ian Hunter</dc:creator>
		<pubDate>Thu, 19 Jun 2008 14:08:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8787</guid>
		<description>Yes, or one could put a hardware based keylogger (here&#039;s a good one: http://www.keyghost.com/) on there and read the password typed into before the OS loads.  Depends on how far you want to take it.  I&#039;ll stick with EFS encrypted PSTs. :)</description>
		<content:encoded><![CDATA[<p>Yes, or one could put a hardware based keylogger (here&#8217;s a good one: <a href="http://www.keyghost.com/)" rel="nofollow">http://www.keyghost.com/)</a> on there and read the password typed into before the OS loads.  Depends on how far you want to take it.  I&#8217;ll stick with EFS encrypted PSTs. <img src='http://www.online-tech-tips.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ben</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8778</link>
		<dc:creator>ben</dc:creator>
		<pubDate>Thu, 19 Jun 2008 00:53:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8778</guid>
		<description>Ian, good point in pointing out the weakness of the attack.  

but there are many ways around this... if I can get the admin password then I can install rogue hacking softwares right?

what if I have a rogue keylogger service running in a computer that can log all keystrokes?  you can find implementations of this that sends logs to a hacker&#039;s email in the background.

I can easily install a keylogger by logging in as a rogue admin. The hacker will just wait until the password arrives to his inbox.

even the strongest encryption passwords typed while the OS is running is always hacked.  If the hacker gets the logs of keystrokes all of the OS level security like EFS is useless.</description>
		<content:encoded><![CDATA[<p>Ian, good point in pointing out the weakness of the attack.  </p>
<p>but there are many ways around this&#8230; if I can get the admin password then I can install rogue hacking softwares right?</p>
<p>what if I have a rogue keylogger service running in a computer that can log all keystrokes?  you can find implementations of this that sends logs to a hacker&#8217;s email in the background.</p>
<p>I can easily install a keylogger by logging in as a rogue admin. The hacker will just wait until the password arrives to his inbox.</p>
<p>even the strongest encryption passwords typed while the OS is running is always hacked.  If the hacker gets the logs of keystrokes all of the OS level security like EFS is useless.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Hunter</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8765</link>
		<dc:creator>Ian Hunter</dc:creator>
		<pubDate>Wed, 18 Jun 2008 13:05:34 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8765</guid>
		<description>The attack described is not valid.  If an administrator (authorized or not) changes a *local* user account password, it destroys the EFS key and the previously encrypted data is lost.  Using EFS to house the PST file is a perfectly acceptable way to protect stored email messages, and is easy for a casual user to implement.  There&#039;s no need to complicate this with boot-time passwords or disk partition or such.  Those things have their place (I use TrueCrypt for some things, I love it, and it&#039;s free), but they&#039;re not needed here.  I&#039;m all about using the easiest effective tool for a job.

Here&#039;s a detailed description of why that attack won&#039;t work:

(Reference this site: http://technet.microsoft.com/en-us/library/bb457065(TechNet.10).aspx )


Resetting Local Passwords on Windows XP

Windows XP has new behavior regarding locally changed passwords and EFS. In Windows 2000, when a local user password was reset by an administrator, the administrator or third party could theoretically use the newly changed account to log on as the user and decrypt the encrypted files. In Windows XP, the changing of a local user password by an administrator, or through a method other than by the user, will block all access to previously encrypted files by the user.

In summary, the profile and keys of the user will be lost and will not be available to the account with the reset password. Windows XP gives the following warning when attempting to reset a user account password:

Warning Resetting this password might cause irreversible loss of information for this user account. For security reasons, Windows protects certain information by making it impossible to access if the user&#039;s password is reset.

This feature helps to guard against offline attacks and prevents rogue administrators from gaining access to encrypted files of other users.</description>
		<content:encoded><![CDATA[<p>The attack described is not valid.  If an administrator (authorized or not) changes a *local* user account password, it destroys the EFS key and the previously encrypted data is lost.  Using EFS to house the PST file is a perfectly acceptable way to protect stored email messages, and is easy for a casual user to implement.  There&#8217;s no need to complicate this with boot-time passwords or disk partition or such.  Those things have their place (I use TrueCrypt for some things, I love it, and it&#8217;s free), but they&#8217;re not needed here.  I&#8217;m all about using the easiest effective tool for a job.</p>
<p>Here&#8217;s a detailed description of why that attack won&#8217;t work:</p>
<p>(Reference this site: <a href="http://technet.microsoft.com/en-us/library/bb457065(TechNet.10).aspx" rel="nofollow">http://technet.microsoft.com/e.....t.10).aspx</a> )</p>
<p>Resetting Local Passwords on Windows XP</p>
<p>Windows XP has new behavior regarding locally changed passwords and EFS. In Windows 2000, when a local user password was reset by an administrator, the administrator or third party could theoretically use the newly changed account to log on as the user and decrypt the encrypted files. In Windows XP, the changing of a local user password by an administrator, or through a method other than by the user, will block all access to previously encrypted files by the user.</p>
<p>In summary, the profile and keys of the user will be lost and will not be available to the account with the reset password. Windows XP gives the following warning when attempting to reset a user account password:</p>
<p>Warning Resetting this password might cause irreversible loss of information for this user account. For security reasons, Windows protects certain information by making it impossible to access if the user&#8217;s password is reset.</p>
<p>This feature helps to guard against offline attacks and prevents rogue administrators from gaining access to encrypted files of other users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ben</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8741</link>
		<dc:creator>ben</dc:creator>
		<pubDate>Wed, 18 Jun 2008 02:46:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8741</guid>
		<description>As pointed out by Graeme, outlook passwords are easy to hack. Worse, there is no patch from Microsoft yet that could fix this problem within Outlook.  

Windows EFS could also be easily hacked if you can have the admin password, and there are a lot of write-ups on how to do this on the Net: http://internetbusinessdaily.net/how-to-hack-a-window-xp-admins-password/
Once you get the admin password, it&#039;s easy to change all the passwords of each PC user. I am sharing computers and securing data on the OS level is a nightmare! 

This problem made me look out for an ever more stronger security solutions that will run BEFORE boot time so even when my laptop is stolen, I could be assured that my whole disk is protected (not only my Outlook files!). I use a product called checkpoint to do this and I am yet to find a hacking software for this product: http://www.checkpoint.com/products/datasecurity/pc/index.html
I configured my setup in such a way that even if they know the OS admin password, they can&#039;t boot or change it without my pre-boot checkpoint password!

Ofcourse, security doesn&#039;t stop there... in computers there is always a way to hack around passwords!</description>
		<content:encoded><![CDATA[<p>As pointed out by Graeme, outlook passwords are easy to hack. Worse, there is no patch from Microsoft yet that could fix this problem within Outlook.  </p>
<p>Windows EFS could also be easily hacked if you can have the admin password, and there are a lot of write-ups on how to do this on the Net: <a href="http://internetbusinessdaily.net/how-to-hack-a-window-xp-admins-password/" rel="nofollow">http://internetbusinessdaily.n.....-password/</a><br />
Once you get the admin password, it&#8217;s easy to change all the passwords of each PC user. I am sharing computers and securing data on the OS level is a nightmare! </p>
<p>This problem made me look out for an ever more stronger security solutions that will run BEFORE boot time so even when my laptop is stolen, I could be assured that my whole disk is protected (not only my Outlook files!). I use a product called checkpoint to do this and I am yet to find a hacking software for this product: <a href="http://www.checkpoint.com/products/datasecurity/pc/index.html" rel="nofollow">http://www.checkpoint.com/prod.....index.html</a><br />
I configured my setup in such a way that even if they know the OS admin password, they can&#8217;t boot or change it without my pre-boot checkpoint password!</p>
<p>Ofcourse, security doesn&#8217;t stop there&#8230; in computers there is always a way to hack around passwords!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: akishore</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8736</link>
		<dc:creator>akishore</dc:creator>
		<pubDate>Tue, 17 Jun 2008 19:38:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8736</guid>
		<description>Ian, that&#039;s a really good idea! You can rest assured your email cannot be read by anyone else as long as they don&#039;t have your password or access to your user account.</description>
		<content:encoded><![CDATA[<p>Ian, that&#8217;s a really good idea! You can rest assured your email cannot be read by anyone else as long as they don&#8217;t have your password or access to your user account.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ian Hunter</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8733</link>
		<dc:creator>Ian Hunter</dc:creator>
		<pubDate>Tue, 17 Jun 2008 17:40:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8733</guid>
		<description>Here&#039;s a MUCH better way, assuming you log into Windows with your own account, rather than a shared account:

Use Windows EFS to create an encrypted folder (go to My Documents, create a folder called &quot;Encrypted&quot; or something like that, right click it, select &quot;Advanced&quot; and select &quot;Encrypt this folder&quot;), then create an UNENCRYPTED PST file located in that directory.  Now, when you log into Windows and open Outlook, the PST file is available, but if someone else logs into the machine or steals the hard drive, the PST file is scrambled.

:)</description>
		<content:encoded><![CDATA[<p>Here&#8217;s a MUCH better way, assuming you log into Windows with your own account, rather than a shared account:</p>
<p>Use Windows EFS to create an encrypted folder (go to My Documents, create a folder called &#8220;Encrypted&#8221; or something like that, right click it, select &#8220;Advanced&#8221; and select &#8220;Encrypt this folder&#8221;), then create an UNENCRYPTED PST file located in that directory.  Now, when you log into Windows and open Outlook, the PST file is available, but if someone else logs into the machine or steals the hard drive, the PST file is scrambled.</p>
<p> <img src='http://www.online-tech-tips.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: akishore</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8729</link>
		<dc:creator>akishore</dc:creator>
		<pubDate>Tue, 17 Jun 2008 16:11:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8729</guid>
		<description>Graeme, I guess it&#039;s better than nothing! Do you have any other ideas? Another idea I had for securing your Outlook file is to hide the actual folder where the PST is stored using a program like FolderHide.</description>
		<content:encoded><![CDATA[<p>Graeme, I guess it&#8217;s better than nothing! Do you have any other ideas? Another idea I had for securing your Outlook file is to hide the actual folder where the PST is stored using a program like FolderHide.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Keep Your Outlook Database Secure - Contact Management - Technology For Agents</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8724</link>
		<dc:creator>Keep Your Outlook Database Secure - Contact Management - Technology For Agents</dc:creator>
		<pubDate>Tue, 17 Jun 2008 15:01:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8724</guid>
		<description>[...] to your laptop or computer can simply open Outlook and see your database in it&#8217;s full form.  Online Tech Tips recently published a nice how-to on securing your Outlook database that deserves a [...]</description>
		<content:encoded><![CDATA[<p>[...] to your laptop or computer can simply open Outlook and see your database in it&#8217;s full form.  Online Tech Tips recently published a nice how-to on securing your Outlook database that deserves a [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Graeme</title>
		<link>http://www.online-tech-tips.com/cool-websites/secure-outlook/comment-page-1/#comment-8723</link>
		<dc:creator>Graeme</dc:creator>
		<pubDate>Tue, 17 Jun 2008 14:37:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.online-tech-tips.com/?p=6031#comment-8723</guid>
		<description>PST &quot;security&quot; is an absolute joke. All you&#039;re doing is giving a false sense of security with this article, a &quot;secured&quot; PST can be opened in seconds using a freeware tool at http://www.nirsoft.net/utils/pst_password.html.</description>
		<content:encoded><![CDATA[<p>PST &#8220;security&#8221; is an absolute joke. All you&#8217;re doing is giving a false sense of security with this article, a &#8220;secured&#8221; PST can be opened in seconds using a freeware tool at <a href="http://www.nirsoft.net/utils/pst_password.html." rel="nofollow">http://www.nirsoft.net/utils/pst_password.html.</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
