How my company and MSFT are killing Ubuntu Linux - Please Fix!!!!

Bug #182190 reported by kubuntu_user
4
Affects Status Importance Assigned to Milestone
Ubuntu
Invalid
Undecided
Unassigned
Nominated for Hardy by kubuntu_user

Bug Description

So a few knuckleheads have at my company have had their laptops stolen, some with important information. What's the company reaction? Encryption. OK so far. They require encryption for USB disks and laptops. OK so far.

Now here are the killers:

1- they require hardware encryption for USB disks. BAD FOR UBUNTU (No support anywhere).
2- They also require Whole Disk Encryption from PGP corporation (BAD FOR UBUNTU - no Support) - which has centralized key management.

So they basically have shunted the growing community of engineers using LInux for development by only allowing WIndows with PGP Corp's software, and Sandisk USB sticks (and others) with Windows software.... nice move. Any Linux work that we need is replied with "install virtual machine" --- not an option for hardware development or serious work.

So please, someone from Canonical please contact PGP Corp and make WDE available for Linux now!!!!!!!

Revision history for this message
Corey Burger (corey.burger) wrote : Re: How my company and MSFT are Ubuntu Linux - Please Fix!!!!

I believe you are asking for the following items: encryption of USB keys and whole disk encryption. Both of them exist in Ubuntu:
 For the USB key, see http://www.emcken.dk/weblog/archives/164-Encrypted-USB-drive-in-Ubuntu.html
For the full root encryption, you need the alternate cd and need to manually partition the computer creating encrypted drives.

If you need help setting these up, please ask a question on Launchpad Answers:
https://answers.edge.launchpad.net/ubuntu

Revision history for this message
kubuntu_user (anibalmorales) wrote :

"Invalid" is not really the status here

Revision history for this message
kubuntu_user (anibalmorales) wrote :

Corey: you misunderstood.
I am asking for COMPATIBILITY, not equivalent functionality, with:

1- hardware encryption of USB keys (only supported by a couple companies, both using WIndows software for the passwords)
2- Whole Disk Encryption (WDE), a product from PGP Corporation that enables centralized management of keys, only via Windows obviously.

Both these are liked by big companies because the lawyers can argue that even if a company laptop with financial or health records is lost (read the news lately!!), since the information is still encrypted they can claim that there is not really a loss. They also want to be able to manage the keys in a centralized fashion.

Both the above functions are usually only available through Windows software, so foresee a bleak future for UBUNTU laptops in the corporate world once all big companies get scared and succumb to the MSFT-only "solution". Please note that a Windows with WDE will not support bootable Linux.

Just my request/suggestion to improve UBUNTU.

Revision history for this message
Corey Burger (corey.burger) wrote :

Ok, lets break this out. There are two requests here.

1. You want to be able to plugin encrypted USB keys created on a Windows machine and have them mount correctly
2. You want to be able to use the centralized management of keys for whole disk encryption

Ok, for the former, you need to create a spec and detail the following (as well as the rest of the normal process of a spec):
1. *Exactly* what pieces of software already exist on windows and any docs about what kind of encryption they use

For the latter, you need to create another spec. This one needs to have all details you have about how the centralized management of keys by WDE/PGP works and any docs you might have.

If you need help with writing these specs, I can help you with that.

Revision history for this message
Corey Burger (corey.burger) wrote :

As stated in the previous comment, these are spec items as they require considerable work and new code. As such, this bug (not the ideas itself)o s not a bug and thus invalid.

Revision history for this message
kubuntu_user (anibalmorales) wrote :

I would love to help create specs if I knew exactly what was required. I am not familiar with the implementation details of the products mentioned. I figured that this is something that Canonical can negotiate and maybe create 'Restricted Drivers".

From my perspective, all I know is that the small but [formerly] growing community of Linux laptop engineering users at my (Forbes 100) company has been essentially wiped out by two requirements:

1- Use WDE from PGP Corp.
2- Use encrypted USB drives from this list:
   * SanDisk Cruzer Enterprise
   * Kingston Data Traveler Secure Privacy Edition

Both of these only work for Windows, so we are dead in the water, with only virtual machines as alternatives. They will not relinquish the specific encryption requirement due to the previously discussed concerns, which I completely understand.

I think the time is ripe for Linux to join the enterprise game and support these particular technologies.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.