How to protect your laptop from data theft

How to protect your laptop from data theft
Logging in via fingerprint is just one extra layer of security you can add to your laptop

Ten years ago, a laptop was an expensive and specialist purchase, but today it's become an everyday item widely used as people's primary work device.

That casualness breeds complacency and that leads to leaving a laptop on the train, unattended in a café or library and having it stolen (we do still have libraries don't we?).

For your eyes only

Prey

We've already touched on the issue that a solid password isn't much help, if an attacker can get their hands physically on the hard drive. Again, on a desktop system this may seem less of an issue, but with a laptop or netbook the likelihood of having a device stolen is far higher.

Encryption is the answer and of course more passwords, probably. Both the Business and Ultimate editions of Windows 7 and Vista both come with file, folder and full-drive encryption options built in.

Right-click on folder or file, select Properties > Advanced and click Encrypt contents to do just that. There are no passwords involved and it's locked to the system and user log-in details. This system generates a cypher key that needs to be backed up. Windows will prompt you to do so, as without it, if Windows needs to be reinstalled you won't be able to access any encrypted data.

The Ultimate and Business editions of Windows 7 and Vista both come with a full-drive encryption solution called BitLocker. This works slightly differently for the Windows boot partition and all other partitions. The big difference is that for all other partitions you're able to just use a password. For the primary boot partition, your hardware has to use a compatible Trusted Platform Module (TPM), more common on business-targeted desktops and laptops than home consumer systems.

The quickest way to check is to fire it up by opening the Start Menu, typing BitLocker and pressing return. If you click the Turn On BitLocker link for the Windows drive, marked with a Windows flag, you'll be given the good or bad news. Often the TPM will need to be switched on within the BIOS and then initialised using the TPM link from the BitLocker Control Panel that generates the secret key.

Once initiated it'll begin encrypting the entire drive, which can take quite a while, so set aside a few hours of downtime if you plan this.

BitLocker To Go extends the protection to removable devices. If you're not running a version of Windows that supports encryption worry not.

The TrueCrypt open source system is a long standing, well regarded and highly secure partition, full drive and virtual drive encryption solution. It'll happily encrypt a Windows boot partition, even on the fly as you continue to use it, along with handling the pre-boot environment.

Other cool extras include its ability to create a file that's then mounted as an encrypted virtual partition, while 'hidden modes' enable you to enter an emergency encryption code that keeps the true partition hidden but reveals a working fake one.

If these all seem a little full-on then we'd also suggest AXCrypt. This sweet little freeware program is right up to date, supporting 32-bit and 64-bit versions of Windows 7 and back to Windows 9x. Once installed it enables you to encrypt single files and folders with just a right click and the entry of a password. Job done, and that will be all of your stuff protected end-to-end - from on the internet to your home devices.