<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MartijnBrant.net &#187; problems</title>
	<atom:link href="http://www.martijnbrant.net/tag/problems/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martijnbrant.net</link>
	<description></description>
	<lastBuildDate>Fri, 23 Dec 2011 01:55:27 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>HP harddisk encryption software and me&#8230;</title>
		<link>http://www.martijnbrant.net/2008/10/hp-harddisk-encryption-software-and-me/</link>
		<comments>http://www.martijnbrant.net/2008/10/hp-harddisk-encryption-software-and-me/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 00:43:54 +0000</pubDate>
		<dc:creator>Martijn Brant</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Website / personal]]></category>
		<category><![CDATA[compaq]]></category>
		<category><![CDATA[drive]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[hdd]]></category>
		<category><![CDATA[hp]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[notebook]]></category>
		<category><![CDATA[problems]]></category>
		<category><![CDATA[protecttools]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[safeboot]]></category>

		<guid isPermaLink="false">http://www.martijnbrant.net/?p=73</guid>
		<description><![CDATA[<script type='text/javascript' src='http://www.martijnbrant.net/wp-includes/js/jquery/jquery.js?ver=1.7.1'></script>
As you may now, I usually use a HP Compaq business notebook (the 15” 8510p to be exact). For the last 9 months I have been using this model for both work and personal usage and it’s my weapon of choice when needing a mobile powerhouse without breaking my back. Performance is great (you can [...]]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">As you may now, I usually use a HP Compaq business notebook (the 15” 8510p to be exact). For the last 9 months I have been using this model for both work and personal usage and it’s my weapon of choice when needing a mobile powerhouse without breaking my back. Performance is great (you can get better these days, I got one of the last pre-Penryn models) and overall it’s a reliable and sturdy device.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">So last week I was going over some security principles and decided that file-based encryption wasn’t enough for my mobile system. I decided to look at drive encryption and for my scenario I had 2 very good and supported choices:</span></span></span></p>
<p class="MsoListParagraphCxSpFirst" style="text-indent: -18pt; margin: 0cm 0cm 0pt 36pt; mso-list: l0 level1 lfo1;"><span style="font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;" lang="EN-US"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Windows Vista Bitlocker<br />
I run Windows Vista Ultimate x64 so using Bitlocker would be a viable option for me</span></span></span></p>
<p class="MsoListParagraphCxSpLast" style="text-indent: -18pt; margin: 0cm 0cm 10pt 36pt; mso-list: l0 level1 lfo1;"><span style="font-family: Symbol; mso-ansi-language: EN-US; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol;" lang="EN-US"><span style="mso-list: Ignore;"><span style="font-size: small;">·</span><span style="font: 7pt &quot;Times New Roman&quot;;">         </span></span></span><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">HP Protecttools Drive Encryption<br />
The official business-level encryption solution provided by the OEM, HP, itself.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">At first I wanted to use Bitlocker and I used the Bitlocker preparation Vista Ultimate Extra to prepare my harddrive for Bitlocker usage. The tool however refused to use my harddrive as it didn’t understood some of the partitions located on the drive (yes, even I have a dualboot to Linux, don’t like it tough) and it refused my harddrive.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Too bad and I decided to use the OEM-supported solution HP ProtectTools Drive Encryption. I figured as HP is a large and <span style="mso-spacerun: yes;"> </span>good company (who has always given me great tech support here in the Netherlands), there would be no recovery issues in the event something should go horribly wrong.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">And boy did things go wrong…</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Earlier this month I turned on Drive Encryption in the software (which is buggy, doesn’t autolaunch the admin tool as Administrator in Windows Vista with UAC turned on, crap HP software). It took about 2 hours to encrypt my drive and it installed a little on-the-fly decryption app in the bootloader. All was working great and performance was still very good. I backed up a recovery key to 2 different USB sticks (just in case). It also asked me whether I wanted to use the online recovery service. As the service does nothing but store your decryption key for a ridiculous amount of money / year, I declined and used the USB-only solution.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Exactly one week ago, Thursday afternoon, I was prepping a demo I was going to give the following day @ 9AM. At around 15:00, I was done with my notebook and switched it to standby. Sometime later I had to change some boot arguments of the Windows Vista bootloader and used a few applications to reflect the changes needed (who I’m guessing rewrote the Vista bootloader, nothing fancy). All was good and I rebooted to test my changes and I noticed it didn’t load the HP decryption software (usually asking me for my password) and it just gave me a flashing cursor.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">I rebooted again .. same. I booted a recovery dvd with a few partition manager applications on it. Double checked whether Vista partition was the active one. It of course was. I booted the Vista DVD and try to use auto fix. It couldn’t find my Windows drive (which is explainable as it is encrypted).</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">The HP system relies on the bootloader software to be present in order to decrypt the harddrive. Messing with the bootloader (which a normal OS installation next to you current OS would also do), seems to wipe away the HP software. Ok great.. now I have a locked drive.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Next up .. recovery.. I had my decryption key but no means to use it as the recovery option was a part of the bootloader decryption software. I quickly visited the HP.com support site in search of a recovery solution for the encrypted harddrive. No luck. Googled on the product name and found nothing usefull.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">I quickly rang up HP Netherlands as it was about a hour before lines closing. Quickly got a pro (no level-1/level-2 filtering here, GREAT!) and explained the situation. However unfortunately due to some issues with the phone systems when using T-Mobile as a provider, I got disconnected. This happened a number of times and I quickly switched to landlines (after being on hold and being disconnected 3x). Ultimately had an employee working with me on how to resolve the issue. No luck. I explained my level of expertise on Windows Vista and systems overall and we both gave great ideas on how to possibly resolve the issue (recover the drive or reinstall the bootloader software). He looked in the central database and had no luck. It was over closing time and they had to cut the call short (which I understand). I asked them whether HP USA could help me further as they are 24/7. The Dutch support line said no as they use the same internal support KB.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-family: Calibri; font-size: small;">I was getting late and quickly went to the shops to grab some food before they all closed. Some cooking later, I was looking at the software being used by HP for the encryption. HP ProtectTools uses a branded version of Safeboot (</span><a href="http://www.safeboot.com/"><span style="font-family: Calibri; color: #0000ff; font-size: small;">www.safeboot.com</span></a><span style="font-size: small;"><span style="font-family: Calibri;">, now owned by McAfee). I again searched the internet but didn’t find a lot of useful stuff. One forum post noted the name (which I can’t say according to HP) of a recovery solution used by enterprises.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Via sources (I’m not allowed to say which ones according to HP) I got my hands on the decryption DVD. Great! Quickly inserted the disc and booted the system yet again. “Please enter daily 4 digit code”. Oh .. euh. 1234 .. nope. Tried some other numbers and couldn’t guess the number. I opted to cancel and the recovery app locked down. It had one other option “Activation via HP backup”. Hey! I have that. Inserted my USB stick and selected the file. “Valid”. Awesome! .. “Now please enter 4 digit daily code”. Arghh.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Looked up the support number for the Safeboot tool. The Dutch number was disconnected as McAfee had bought them. When trying the US number, I got connected to McAfee Enterprise support. I opted for Safeboot support. 1 minute waiting later, I had a tech person on the line. I explained my situation and stated I had the software. Just needed the key. The kind sir explained nicely to me they couldn’t give me the key without the proper SLAs. I understood however still lame the only thing holding me is a 4 digit code which the guy had displayed on his screen but couldn’t give me. I tried asking real real nice. Nope .. no go. He advised me to ring up HP USA.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">So I did. Got disconnected 3 times whilst waiting (and having to pass the horrible voice-activated menu’s, what’s wrong with keyinput?) and had to wait another 15 minutes. Ultimately I got my tech person on the phone. Took about half an hour to explain the situation. Of course the ma’am couldn’t find anything in the KB either. I also explained my situation was urgent and I had to have the drive back before 9AM next morning. She would “look into it and do some research” while I would wait on hold (with the WORST waiting music EVER). I waited for up a to an hour. She was no help and couldn’t find anything. It took her over 90 minutes to realize with the Dutch guy did in 15 minutes. Ultimately she rang McAfee USA again and we had a little conference call (after I waited another 30 minutes whilst she was explaining the situation to McAfee). Ultimately I had the McAfee tech guy on the phone but again just like before, they couldn’t do anything for me.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">I thanked them both and hang up (as waiting any longer or making a escalation ticket would be pointless and take way too long).<span style="mso-spacerun: yes;">  </span>Nearly 5 hours of calling, waiting and being disconnected, I was no further in my quest to unlock my harddrive. </span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">Another desperate 15 minutes of Googling and ringing up 4 IT Pro’s out of their beds, I gave up. I decided the best thing to do, was to wipe the harddrive and install a clean image. As I was using special software for the demo the following day, I couldn’t just use a backup. I had to reinstall from scratch. Of course all my documents and vital information was backed up to external hdd, LAN share and trusty Sharepoint sites so that wasn’t a too big a problem. However I did took me another couple of hours to setup the demo software again from scratch. By the time I got in bed, it was nearly 4AM.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">The following day I got up at 7AM and give my demo at 9AM using my cleanly installed software (which went great dispite the 3 hours of sleep). Stayed on location till 6PM. After that I went to a friends house for dinner. Fixed his internet and had a good time. By the time I was back in my bed, it was 3AM/4AM.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">So basically HP is providing a encryption solution they cannot support or recover for you in case something should go wrong. There are no external decryption tools provided. If you are using HP ProtectTools Drive Encryption right now, I really suggest turning it off and migrating away from the solution. At the very least, find some way to backup your bootloader containing the decryption software.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="mso-ansi-language: EN-US;" lang="EN-US"><span style="font-size: small;"><span style="font-family: Calibri;">As for the recovery service which SafeBoot is providing for HP.. It’s a yearly fee to store your (kinda useless) recovery key online and a support service (allowing you to ring the 2 McAfee persons I talked to earlier directly). I asked McAfee whether that would have saved me in my situation had I taken up the subscription. The short answer: No. They only provide you your key and provide support for resetting the password remotely. They don’t provide support when your bootloader committed suicide.</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><strong style="mso-bidi-font-weight: normal;"><span style="mso-ansi-language: EN-US;" lang="EN-US">I’m never ever using full drive encryption software by HP again!</span></strong><span style="mso-ansi-language: EN-US;" lang="EN-US"> Perhaps HP could have given me a better solution had I waited a couple of days so they could escalate the problem to other departments and McAfee. I didn’t have the luxury of time, and you might not too when things go wrong. <strong style="mso-bidi-font-weight: normal;">Stay away from HP Drive Encryption solutions</strong> (or anything Safeboot related).</span></span></span></p>
<p class="MsoNormal" style="margin: 0cm 0cm 10pt;"><span style="font-size: small;"><span style="font-family: Calibri;"><em style="mso-bidi-font-style: normal;"><span style="mso-ansi-language: EN-US;" lang="EN-US">One small note: I heard that Safeboot supported the HP software directly via their own helpdesk line thus unloading complex support calls to the HP helpdesk. However McAfee bought Safeboot in 2007. The HP agreement still stands but support is limited to enterprise SLA holders only.</span></em><span style="mso-ansi-language: EN-US;" lang="EN-US"> </span></span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martijnbrant.net/2008/10/hp-harddisk-encryption-software-and-me/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Moving Exchange away from Sherweb, to ItSolutionsNow</title>
		<link>http://www.martijnbrant.net/2008/07/moving-exchange-away-from-sherweb-to-itsolutionsnow/</link>
		<comments>http://www.martijnbrant.net/2008/07/moving-exchange-away-from-sherweb-to-itsolutionsnow/#comments</comments>
		<pubDate>Sat, 19 Jul 2008 01:07:38 +0000</pubDate>
		<dc:creator>Martijn Brant</dc:creator>
				<category><![CDATA[Exchange]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hosted exchange]]></category>
		<category><![CDATA[mail]]></category>
		<category><![CDATA[migration]]></category>
		<category><![CDATA[outlook]]></category>
		<category><![CDATA[problems]]></category>
		<category><![CDATA[windows mobile]]></category>

		<guid isPermaLink="false">http://www.martijnbrant.net/?p=17</guid>
		<description><![CDATA[I&#8217;ve had it with Sherweb. If you didn&#8217;t know, I had my 3GB hosted Exchange account hosted at http://www.sherweb.com for about 5 to 6 months now and overall the overall experience was great. However &#8230; there was one thing that was bothing me&#8230; I didn&#8217;t get all my email. Let me explain.. I set up [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had it with Sherweb. If you didn&#8217;t know, I had my 3GB hosted Exchange account hosted at <a href="http://www.sherweb.com">http://www.sherweb.com</a> for about 5 to 6 months now and overall the overall experience was great. However &#8230; there was one thing that was bothing me&#8230; I didn&#8217;t get all my email.</p>
<p>Let me explain.. I set up my account (<a href="mailto:...@martijnbrant.net">&#8230;@martijnbrant.net</a>) and made sure the DNS settings for my domain were properly set. They were and in no time the account was up and running using Microsoft Outlook 2007 and Windows Mobile 6.0 (Push email). All was great and all my email was being delivered to my inbox.</p>
<p>Half a day later .. I got a (what the server thought to be) spam message and I didn&#8217;t recieve it. At the end of the day, the server had send me a anti-spam reporting showing I had one message waiting for me at the webinterface for anti-spam. Turns out .. Sherweb was using a product called Barracuda Spam Firewall. It sat between my email and my inbox.. filtering emails and quarantining them in the webinterface. I found this annoying and I quickly turned it off (making it tag spam instead..).</p>
<p>All was fine again .. untill I was planning my trip to Florida. I had the hotel I was going to be staying in (which was great, Choicehotels are awesome value) on the phone and manager who booked my stay said he sended the confirmation of my hotel reservation to my mb.net email account. One hour later, I still hadn&#8217;t recieved it. I rang them up and had them send it to my <span style="text-decoration: line-through;">Hotmail </span>Windows Live Mail account. Sure .. 2 secs later I had recieved the email. &#8220;That&#8217;s strange huh?&#8221;</p>
<p>I dismissed the problem and went on my trip to Florida. After I got back .. I was curious as to how this could have happened. I tried to forward the stored email from my WLM account to my Sherweb account. Never recieved it. Surprised by this, I rang Sherweb. After going trough the usual Level-1-support stuff, I got through to Level 2. The guy was friendly enough and tracked down the email. &#8220;Ah I see .. blocked&#8221;. Ok sure, I replied .. why is it blocked and why can&#8217;t I see that?</p>
<p>&#8220;Well sir the Barracuda filtering system uses 3rd party blacklists in order to tag spam. Messages containing keywords from that list will be deleted&#8221;. Wait what? You deleted my email?!?! &#8220;Yes sir, for your protection&#8221;. Erhmm Ok .. On what word was it blocked? &#8220;Lemme just see here &#8230; ah .. choicehotels.com sir&#8221;. Wait what? As for as I understand it, Choicehotels is a pretty large organisation with 1000s of hotels all over the USA. &#8220;Yeah the word is blocked sir&#8221;.</p>
<p>It turned out I couldn&#8217;t see what emails were being blocked or for what reason. I had no idea on how much emails (read: business) I had lost over this. I asked Sherweb &#8220;What should I do with my important email? Just use my Windows Live Mail for all the important bits?&#8221;. He replied &#8220;Err yeah you could do that&#8230;&#8221;. &#8220;- Why am I paying you then?&#8221; &#8230; &#8220;Well sir, you could still use your Sherweb account for all personal stuff&#8221;. What?!?! Sure buddy .. I&#8217;ll just use my 100$ email account for personal stuff&#8230; I have WLM for that..</p>
<p>So .. as of today I&#8217;m migrating over to <a href="http://www.exchangemailhosting.com">http://www.exchangemailhosting.com</a>. I rang them up and told them/asked them about my Sherweb problems and if they had similar systems. They chuckled and replied &#8220;No sir, we believe in NOT trowing email away&#8221;. Hehe.</p>
<p>I hope exchangemailhosting.com will be better. We&#8217;ll see. Just about done with the DNS. Wait a couple of more days and then cancel my Sherweb service. They told me they&#8217;ll refund my pre-paid 3 month period. So have to hand it to them .. that&#8217;s great. Overall Sherweb is great if it wasn&#8217;t for their email-eating practice.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martijnbrant.net/2008/07/moving-exchange-away-from-sherweb-to-itsolutionsnow/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
	</channel>
</rss>

