PGPDisk Available to Any "Switched User" Under Windows XP
22 Oct. 2003
Summary
When a user mounts a PGPDisk and for whatever reason leaves his computer, the PGP disk stays "mounted".
If another user, with a local login right, uses the Windows XP "switch user" function, he will have full access to the mounted PGP Disk. Thus, the data is compromised.
Under Windows 2000 and Terminal server activated, it is possible that the data become then remotely compromised.
Mitigating factors:
* If you log off, the disk is automatically unmounted.
* NTFS access rights can be defined on the PGP Volume (with the known limitation, regarding powerful users that can take ownership of files) and the question regarding the usage of PGP Disk if the only security is NTFS...
* You can activate the auto unmount option after a certain period. The problem is that if you have files open, you may loose your work.
Vendor response:
The vendor has been contacted and acknowledges this was a "known" problem. However, they were not able to tell Thierry if they plan to fix this issue or not.