Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner

Redirecing C:\Users and C:\ProgramData folders to a USB memory stick

microsoft.public.windows.vista.security






Speedup My PC
Reply
  #1 (permalink)  
Old 10-11-2008
Audun
 

Posts: n/a
Redirecing C:\Users and C:\ProgramData folders to a USB memory stick
I am experimenting with a configuration that redirects the C:\Users and
C:\ProgramData folders to a USB memory stick. This allows me to always keep
user data in personal care when travelling with the laptop. The redirection
is done by setting the value of the ProfilesDirectory and ProgramData
attributes in [Auto]Unattend.xml during Vista setup. This method is
supported, albeit reluctantly, by Microsoft.

To secure and enhance this configuration, I also:

- encrypt the hard disk with BitLocker and the TPM key, TPM PIN, and USB
startup key
- encrypt the memory stick with BitLocker autounlock
- lock down C:\ and S:\ (BitLocker) so that users cannot add data to these
folders
- disables the Windows pagefile to avoid user data "residue" on the system
disk
- enables write-caching on the memory stick (for performance reasons)
- enables a large system cache (LargeSystemCache registry value) for the
same reasons
- uses Roaming Profiles to copy user profiles to a central server share (for
backup)
- uses Folder Redirection to redirect user folders to a central server share
(for backup)
- uses Offline Files to locally cache server-side user folders and "user
group" folders (i.e. folders shared between groups of users)
- redirect the local Client-Side-Cache (C:\WIndows\CSC) to the memory stick
to avoid user data "residue" on the system disk
- disable Hibernation to avoid user data "residue" on the system disk
- disable the Windows Search service since I don't use it, I don't like it,
and it seems to generate a lot of traffic to the memory stick

AFAIK, this leaves no room for user data to be written to the hard disk
except to those subfolders of C:\Windows that Microsoft has made
user-writable by default. I have not closed down these subfolders, but
intend to do it at a later stage.

In addition, I lock down Windows with a configuration similar to the SSLF
profile of the W2008/Vista security guides and uses SRP to block end-user
program execution outside Windows, Program Files, and the logon server
SYSVOL share.

I have been running this configuration for a few months now without any
apparent problems arising from doing the redirection. Performance is
acceptable even on the fairly slow (but conveniently small) Sony MicroVault
Tiny 8GB USB2.0, 7/12MB sec write/read.

The reason for posting this message is to get some feedback on my apporach,
in particular

- are there any potential problems or pitfalls that I ought to know about?
- are there any uncovered ways that user data can be written to the hard
disk?
- should I expect to run into trouble when I lock down the user-writable
subfolders of C:\Windows?

Audun



Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
SD Memory and Memory Stick Slow and Errors Ed microsoft.public.windows.vista.music pictures video 0 07-07-2008 14:53
USB hub and memory stick Rich microsoft.public.windows.vista.general 0 03-13-2008 14:56
memory stick andrew microsoft.public.windows.vista hardware devices 8 02-11-2008 05:23
USB memory stick Mike of Wrexham microsoft.public.windows.vista.general 1 10-27-2007 14:13




All times are GMT +1. The time now is 11:14.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com , Win7Heads.com and Win8Heads.com.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.6.0 RC 2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120