Thursday, August 29, 2013

Encryption, Data-Centric Approach Needed To Secure Cloud, Mobile Users

Encryption, Data-Centric Approach Needed To Secure Cloud, Mobile Users


The ever-growing mobile workforce with its head in the cloud has created what seems like an endless list of IT challenges to overcome, and with anywhere, anytime access to information a necessity for many enterprises, the new IT world is having an impact on the kind of encryption enterprises need to protect their sensitive and proprietary data. InformationWeek's "Data Encryption: Ushering In a New Era" report found that cloud and mobility are adding new challenges to security, but only 47% of 506 IT professionals that responded to a survey on data encryption stated that have mobile-device encryption has been made a priority. Another InformationWeek survey, "Research: 2012 State of Cloud Computing," of 511 IT professionals regarding cloud computing found that 64% of enterprises using cloud services are dealing with between two and five different providers. As the number of servers and applications move into the cloud, the more the use of encryption drops off. "The problem of mobility and cloud is it forces policies, processes and encryption technologies to have to scale to an outside device, organization, and too many more use cases," says Michael Davis, CEO of Savid Technologies and author of the report. "This usually means the governance/audit team isn't ready, the security team gets bogged down in details related to deployment, but in the end we don't see users impacted too much by encryption in these spaces as the technology is usually transparent." All of the encryption technologies require keys, but in the case of mobile devices, the keys are usually controlled by end users when they turn on their phones, Davis explains. In that case, the user must have a lock/password screen or encryption isn't able to do its job. IT can create policies around using lock/password screens, but end users frequently ignore policies. In the case of mobile devices, it leaves potentially sensitive data open to anyone who comes into physical contact with the phone. Of the 506 respondents to the data encryption survey, 38% said their organizations have comprehensive formal policies in place that expressly require encryption of personally identifiable information (PII) or confidential data on certain devices within their networks. They said the policies are strictly enforced. Another 38% noted that although they have policies, enforcement is limited or done on an application-by-application basis.

"If the organization doesn't start looking at their data in terms of who, what, why and where the access to that data needs to occur, they won't be able to properly encrypt the data and know what devices need to decrypt the data," states Davis. "Furthermore, when it comes to cloud, if you don't encrypt and have control of your keys, you are basing your security on the fact that the cloud provider promises to implement security at or above the level your organization does, and, sadly, most organizations don't check to see that the cloud provider actually meets the same level of security requirements."
From a mobility perspective, enterprises have been lucky because of the type of data typically being stored on mobile devices, Davis says. End users have not wanted to work with large documents, spreadsheets and other files not easily viewable on mobile devices, but as the form factors, available applications and performance of mobile devices have increased, users are becoming more likely to work with such data on their smartphones and tablets. "Mobility has enabled anywhere, anytime access. I call it the Starbucks problem. Every Starbucks is now the corner office for most workers, and mobility is going to continue to demand that employees access files anywhere from any device," he says. IT organizations need to ask themselves some tough questions about security and encryption, with a focus on securing data that is not under their control (because most of those mobile devices aren't). The solution to the problem is usually taking a data-centric approach to security instead of the traditional premise-based model, says Davis. Learn more about Strategy: SIEM by subscribing to Network Computing Pro Reports (free, registration required).

ICO Blog: Why encryption is important to data security

ICO Blog: Why encryption is important to data security

Subscribe via RSS

Simon RiceBy Simon Rice
28 August 2013


Storing any personal information is inherently risky. By recording it, you risk losing it, and that risks upsetting people, and no-one likes upsetting people. But quite often, if you don’t store personal data, you can’t provide a proper service. And that risks upsetting people too.

This is why, if you are collecting personal information, you must make sure you are looking after it in a safe and secure manner.
In order to do this effectively action must be taken to reduce the risks of inappropriate disclosure. Given that a large amount of data can now be stored on something as small as a smartphone or tablet PC, there is a real danger that personal information could be compromised should such a device end up being lost or stolen.
Using appropriate encryption can be a simple and effective means to protect personal data in these circumstances, and one which we advise all organisations to take if the loss of the data could cause damage and distress to the individuals affected. However evidence shows that data controllers are still not addressing the problem.
This blog article aims to provide you with a useful insight into how encryption works and the encryption options available to you and your organisation to help you keep personal information secure.
The big misconception

Let’s get this one out of the way first. A common misconception is that just requiring users to login to a device, or service, with a username and password provides an equivalent level of protection to encryption. This isn’t the case. A password or PIN to control access to a device isn’t encryption and it isn’t enough to protect against unauthorised or unlawful access. In practice a password can be easily circumvented and full access to the data can be achieved.

How does encryption work?

Encryption software uses a complex series of mathematical algorithms to protect and encrypt information. This hides the underlying data and prevents any inadvertent access to, or unauthorised disclosure of, the information. This means that even if a device containing personal information is lost or stolen, the information will remain secure as long as the would-be data thief isn’t able to access the encryption key required to crack the algorithm.
Appropriate encryption products are widely available, but it is important that organisations understand the type of protection a particular encryption product offers and the circumstances under which personal data will be protected from unauthorised or unlawful access.

What encryption software should I use?

There are a variety of different encryption options available. The option that will be the most appropriate for your organisation will depend on the sensitivity of the information you are using and how it is being stored and processed.

For this reason it is difficult to provide a comprehensive list of software as everyone’s needs are different. You can however look out for internationally recognised standards such as those described on the encryption section of our website.
Full disk encryption

This is a process which encrypts the entire disk including all of the information and personal data it contains. It is commonly used when encrypting laptops, desktops and mobile devices, such as mobile phone and tablets. The disk will need to be decrypted with a key, which is often protected by a password entered by the user, before the operating system boots up.

However, this may mean that there are circumstances when the data could still be at risk. For example, if someone left a tablet unlocked and unattended in a restaurant then anyone who picked up that device would have an opportunity to extract the unprotected data. It is also important to recognise that if a file is transferred off the disk, for example if you sent the information in an email or saved it to a different device, then the file will no longer be encrypted.
Full disk encryption is provided through a range of widely available third-party software and some modern operating systems have a full disk encryption mode built-in, but they will usually require the user to enable the protection.
Individual file encryption

This is a process which will encrypt an individual file or create an encrypted container into which a set of files can be stored. When the container is closed it is encrypted. This means that if the container itself is transferred to a different device, for example if it is emailed or saved to a USB drive, then the personal data remains encrypted. However once the file is removed from the container it is no longer encrypted.

Some modern operating systems are able to create encrypted containers, while a range of third-party software can also offer the same level of encryption. However it is important that this encryption technique is not confused with adding password protection to a file or folder, as this process will not result in the data being encrypted.
Most email client software will also support sending emails with the message content and any attachments in an encrypted format. This approach does however require some initial configuration of both the sender and recipient’s email software.
Encrypting data in transit

It is also important to know the difference between the encryption techniques used for data storage and the encryption techniques used in data transfer.

You can transfer data using an encrypted data transfer protocol, such as Secure Sockets Layer (SSL) or Transfer Layer Security (TLS). This is the technology that displays the padlock symbol in protected web browsing. It provides assurance that the communication between client and server cannot be intercepted. Furthermore it provides you with a means to validate where the data is being transferred to.
The use of an encrypted transfer protocol does not provide any guarantee that data will remain encrypted, or otherwise processed securely, once it is received at its destination. This will need to be assessed separately.
The importance of keeping the key secret

You wouldn’t install high end locks on your house, only to leave the front door key under the mat. The same applies for storing a laptop encryption key or password in the same bag as an unencrypted laptop, or equally, sending encrypted data as an email attachment with the means to decrypt it included in the body of the email.

If you do any of these then the safeguards provided by the act of encryption are illusionary, because all of the necessary information required to decrypt the data is readily available. The secrecy of the key used to encrypt the data is therefore of paramount importance.
To ensure the maximum level of protection offered by encryption, the key or password should be transmitted using an alternative means of communication. For example the encrypted data could be sent by email and the key provided over the telephone once the intended recipient has confirmed that the data has been successfully received. By adopting this approach, even if you accidentally send the data to the wrong recipient, the information will remain secure as the person will not have the necessary key to access it.
And finally…

While encryption sounds like a complicated means of protecting sensitive personal information, the crucial aspect to making it work is to identify the most suitable form of encryption and follow a common sense approach to keeping the key, and therefore the data, secure. Using effective encryption is usually easier to manage than adopting an alternative means of providing a similar level of data security.

And the time and cost of proper encryption is put into sharp perspective by a quick glance over the penalties issued in three recent cases where encryption wasn’t used (£700,000 in total). The price of getting it wrong could therefore extend well beyond upsetting people…

Simon Rice
Group Manager, Technology
28 August 2013


If you'd like to get in touch with feedback or comments please find us on Twitter @ICOnews or email blog@ico.gsi.gov.uk.

< << Blog homepage

 

 

U.S. Secret Service: Five Retailer Breaches Are Linked

U.S. Secret Service: Five Retailer Breaches Are Linked

Written by Frank Hayes
August 28th, 2013
If it seems like this spring and summer have seen a rash of supermarket-chain security breaches, it turns out there’s a reason. Five recent cyberattacks against smaller retail chains all appear to have come from the same overseas criminal gang, according to the U.S. Secret Service. That includes the breach at Schnuck Markets that netted thieves as many as 2.4 million card numbers, four other breaches at chains a Secret Service spokesman declined to name, and a collection of retailers in Kentucky and Indiana who all shared the same local reseller who provided the POS remote-access software that thieves exploited.
While investigators wouldn’t finger the victims other than Schnuck’s, it’s easy to make a short list of likely suspects who reported apparent remote-access breaches over the past six months. They include regional grocery chains Bashas and Raley’s, restaurant chain Zaxby’s, convenience store chain Mapco Express (NYSE:DK) and discount hardware chain Harbor Freight Tools. Craig Hutzell, a spokesman for the Secret Service’s Kentucky Electronic Crimes Task Force, told Bank Info Security that the malware used in the attacks and the methods of entry all trace back to a single hacker using an overseas IP address. “It’s the same [modus operandi], and the malware matches what we had here in our breach,” Hutzell said. Hutzell confirmed the connection between the Schnuck’s breach and attacks on a group of retailers in Kentucky and southern Indiana, but would not name the other four retailers, saying it was not clear if all of those incidents had been made public. But the attacks on the Kentucky and Indiana retailers all exploited an unpatched vulnerability in the same POS software. That strongly suggests that all the other attacks used what’s essentially the same vulnerability, exploited by the same malware, whether it’s actually the same POS software or not. Investigators haven’t named either the software or the local reseller who provided it. And that, of course, leaves every other chain, large or small, twisting in the wind. The thieves know about the vulnerability, and they can keep testing remote access to more chains’ POS systems to see if they have the same security hole. But without knowing what the vulnerability is, how it’s exploited or even the POS software involved, chains (and, in the case of small chains, resellers) can’t check to confirm that everything is properly patched, and test to make sure the POS systems are secure. That can’t continue. Knowing as much as possible about current common attacks is critical for any retailer trying to defend against them. (Again, for smaller retailers who don’t have in-house security expertise, we’re talking about resellers and consultants. They’re the ones who are doing the actual defending.) And knowing current attacks is going to be even more crucial when PCI 3.0 kicks in, four months from now. That’s when penetration testing joins more traditional PCI security verification. It’s essential for pen testers to have as many of the bad guys’ weapons as possible in their testing arsenals. After all, that’s what pen testing is for: to mimic what real attackers will do if they get the chance. Right now, cyberthieves are getting too many chances. If a single eastern-European attacker really is responsible for a five-chain, six-month card-siphoning spree, that PCI pen-testing requirement comes none too soon. Even better will be the point when smaller chains doing self-assessments also start hiring pen testers for low-end services. There’s a lot of potential revenue for little work by pen testers with a comprehensive automated script that probes for vulnerabilities—and that’s what cyberthieves are going to be using anyway. But that still depends on investigators being a little less stingy with information on how breaches happen. The active thieves already know, and they’ve probably already shared vulnerability details with other potential thieves. By keeping security people and retailers in the dark, who are investigators protecting—well, besides the resellers who failed to patch their customers’ software and the software vendors who sold buggy POS systems in the first place?


Read more: http://storefrontbacktalk.com/securityfraud/u-s-secret-service-five-retailer-breaches-are-linked/#ixzz2dM4swkNm

Tuesday, August 27, 2013

The Biggest Data Thefts In Recent History [Infographic]


It's a big-data look at the loss of lots of big data. That's pretty big.

Major Breaches in 2013
Major Breaches in 2013:  Information is Beautiful

The internet is a giant vault where people store some of their most private information, trusting that the company holding on to it can keep it all safe. That's not always the case, as this infographic of data breaches in recent history--by Information is Beautiful--reveals. Viruses, hacks, lost computers, accidental publishing, inside jobs and more have all been sources of major leaks over the last 9 years. The infographic identifies breaches by amount of information stolen, type of organization that was breached, year of theft, and the sensitivity of information lost or stolen. An intriguing upshot: By showing major breaches over time, the infographic illustrates how internet use has changed over the past decade. AOL (remember AOL?) has the first major breach in 2004, healthcare providers dominate leaks around 2009, and gaming companies had the major data losses in 2012.
Major data breaches in 2004-2007
Major data breaches in 2004-2007:  Information is Beautiful

Wikileaks shows up big in 2010
Wikileaks shows up big in 2010:  Information is Beautiful

Militarysingles.com leaked sensitive information
Militarysingles.com leaked sensitive information: I get that dating is important, but is it more important than national security?  Information is Beautiful

Sunday, August 25, 2013

How encryption and tokenization help with cloud services adoption

How encryption and tokenization help with cloud services adoption
Posted on 23 August 2013.
Today’s CIOs and CISOs are facing continued pressure to adopt the cloud enterprise-wide while managing the increasing operational and security risks associated with it.


While the challenge can be daunting, a new Gartner report highlights the role that encryption and tokenization technologies can play in helping enterprises adopt cloud services, even those in highly regulated industries or in regions with strict data sovereignty requirements.

CIOs and CISOs should simplify audits such as the Payment Card Industry Data Security Standard (PCI DSS) when using cloud services by implementing access controls and encryption or tokenization of sensitive data.

Gartner highlights sector-based data compliance requirements, such as PCI DSS, as drivers for organizations to consider adopting encryption and tokenization technologies. Another catalyst is referred to as data residency requirements, where the protection is required to prevent access by government authorities and agencies while data resides in or is passing through other jurisdictions.

Regarding this issue, an alternative is to avoid storing the data in those jurisdictions, such as the U.S. and U.K., which use legal access or interception of data through laws such as the USA Patriot Act and the U.K. Regulation of Investigatory Powers Act.

But the report cautions enterprises to clearly think through the implications of deploying these technologies in their environments. Gartner’s research helps enterprises understand these risks and highlights the following:
  • Protect sensitive fields/columns while using cloud SaaS applications
  • Do not store keys or use keys in other jurisdictions, or use a third party; otherwise the encrypted data could be accessed if the keys are available
  • It is important to review the claims of vendors carefully due to the novel and unique implementations of encryption solutions. … Enterprises should always check the claims of vendors that their solutions are based on proven security models
  • When keys or tokens are managed on-premise, always check the impact on the access and availability of the cloud service provider (CSP) and the performance of appliances
  • A growing best practice is emerging where enterprises encrypt data stored in the cloud and manage the keys locally.
“This Gartner report is timely because of the increased concern about data ownership and privacy in the cloud fueled by ongoing reports of data surveillance and the implications these revelations will likely have on future regulations and compliance mandates,” said David Canellos, CEO of PerspecSys.

“The security strength of the underlying data protection techniques that an enterprise uses is critical. This is why PerspecSys has refused to use any of the weakened security approaches that the report urges CIOs and CISOs to fully understand. I’m astonished to see some competitors tell enterprises they need to use modes of encryption modules that have not been opened up to public scrutiny and do not have well-vetted security proofs when they want to preserve cloud application functionality. This is a totally unacceptable position that opens these organizations to security risks as well as compliance and audit challenges. We do not force this tradeoff on our customers, which is why we are seeing our approach win in the marketplace,” Canellos added.

Saturday, August 24, 2013

Architecten willen groot deel internet versleutelen

Architecten willen groot deel internet versleutelen

zaterdag 24 augustus 2013, 18:18 door Redactie,
Een aantal voorname internetarchitecten heeft een plan bedacht om grootschalige surveillance op het internet door overheden en inlichtingendiensten tegen te gaan. Het gaat om leden van de Internet Engineering Task Force (IETF), een regulerende organisatie voor het internet die allerlei standaarden opstelt en ontwikkelt.
Als het aan de architecten ligt zal een groot deel van al het internetverkeer standaard worden versleuteld, net zoals nu het geval is als internetgebruikers een website via HTTPS bezoeken. Dat moet het lastiger voor overheidsdiensten maken om de inhoud van het internetverkeer af te tappen. Op dit moment versleutelt in verhouding nog altijd een klein deel van de websites op het internet het verkeer tussen bezoekers en de server.

Leven en dood

"Er heeft een grote verandering plaatsgevonden in hoe mensen de wereld zien" sinds klokkenluider Edward Snowden de omvang van het Amerikaanse surveillanceprogramma begin deze zomer openbaarde, aldus Mike Belse, een software engineer en IETF-lid, die meehielp bij het ontwikkelen van Google Chrome.
"Geen encryptie op het web vandaag de dag is een kwestie van leven en dood", zo laat hij tegenover de Financial Times weten. Naast de roep van het IETF om meer encryptie, vragen ook privacygroepen om fundamentele hervormingen van de wetten die op internet worden toegepast.

Aantasting privacy

"Online privacy wordt in een razend tempo door een deken van surveillance aangetast, en tenzij we direct hervormingen doorvoeren, zal de notie van vrije en veilige online communicatie naar de geschiedenisboeken worden verbannen", zo pleitte onlangs nog Tim Berners-Lee, de geestelijk vader van het web, in een brief.

https://www.security.nl/posting/361261/Architecten+willen+groot+deel+internet+versleutelen?channel=rss

The death of the cloud has been greatly exaggerated

    

data in clouds

    
Summary: After the revelations of NSA spying on internet data, analysts think the cloud market will take a hit. Here’s how to get the benefits of using the cloud, but protect your data.
There has been a lot of speculation about the impact of PRISM on data security and cloud computing; just this week alone two influential articles have been written quoting wildly different predictions on how much the revelations will cost cloud vendors, but there’s no denying that the ripples in the industry are starting to rock the boat.
The Information Technology and Innovation Forum (ITIF) recently announced that due to the fears over data privacy and security that PRISM has highlighted, the cloud computing industry stood to take a hit in the order of $36 billion by 2016. But Forrester Research has come out to say this estimate is too low and the impact could be far deeper to the tune of $180 billion.
prism-slide-7
Taking into account that by 2016, ITIF calculates the global cloud market to be worth $207 billion (Forrester estimates $270 billion by 2020) this is a staggering number to hit a maturing industry where a lot of enterprises have already invested. But now that investment is starting to crack. Only this week I learned from an analyst source that some 50-plus cloud service contracts have either been put on hold or cancelled altogether because of concerns around cloud security raised by PRISM.
These are localized issues to the U.S. presently, and foreign investment in U.S.-based cloud services are the ones taking the hit due to the American government having access to data that sits on U.S.-based servers. However, given the far-reaching implications of the NSA program and the alleged complicity of other governments in supplying data, it is safe to assume that the fear over cloud security will spread to other countries.
five starBut this isn’t the end of cloud by any means, and we can ignore the people crying “It’s the death of cloud,” the same way we ignored those that exaggerated the death of on-premise software. It is still possible to develop a cloud-based strategy that will ensure scalability without compromising security. Here are five key considerations for any cloud strategy going forward:
  1. Bring your own encryption – Secure third parties like Lavabit and Silent Circle have now closed their services because they cannot ensure privacy if the U.S. government asks them for information. In order to secure your data it is essential that you investigate your own options for in-house encryption and not rely on a third-party service outside the firewall to do it for you.
  2. Examine the cloud contract – This is often ignored and placed in the hands of the legal and procurement teams who may not fully appreciate the implications of the responsibilities under a cloud contract. For example, just who is responsible for your data should something go wrong ? Use a specialist lawyer who is well versed in cloud-related negotiations to ensure you don’t run afoul of the small print.
  3. Know where your servers are – Right now U.S.-based services are a prime concern for the enterprise, but it’s already been shown that other countries’ governments are involved in data sharing and data access. But this doesn’t stop you from knowing which countries have the more stringent data protection policies in place with financial penalties for misconduct. The UK and Germany for example have two of the strongest acts in place for this.
  4. Private, public, on-premise, or hybrid? – We’ve seen that moving everything to the public cloud is a no-no and that the death of on-premise deployments has been greatly exaggerated. The clear choice is to use a hybrid model. Hybrid works because of the combined benefits each bring individually:
    • Public for maximum flexibility and efficiency
    • Private for maximum control
    • On-premise for compliance and privacy
    What you choose to automate will be guided by your own data security requirements and ultimately will determine how much of the public cloud you will use, and what you keep private or on-premise.
  5. Don’t ignore the importance of cloud integration – Integration platforms provided through companies such as Software AG, Informatica and Mulesoft to connect software-as-a-service applications to the enterprise are the lynchpin in powering a hybrid cloud strategy. Don’t treat integration as an afterthought because the security of the connection to these services is as important as the service itself.
  6. There is no denying that the Snowden leaks have had a massive impact on the IT industry in general, and that cloud services are now under enterprise scrutiny, but with strategic and tactical decisions made with intelligence these ripples can be navigated easily.
    Theo Priestley is Vice President and Chief Evangelist at Software AG. You can follow him at @ITredux.