Showing posts with label FDE. Show all posts
Showing posts with label FDE. Show all posts

Thursday, October 1, 2009

Josh Corman at IANS

Just attended an interesting keynote by Josh Corman at the IANS event in Boston this morning. Very though-provoking stuff - he also has an article about it in CIO magazine.

Being a good marketer, Josh trimmed down the 8 secrets to 7 (but wait!, one was free and he counted from zero, so we are back to 8 :)). I had previously discussed one of his takes in this blog.

The interesting part about listening to the discussion live, is Josh's emphasis on risk. He believes that we as security professionals have been so caught up with managing around compliance mandates, we have not stepped back to think about what risk we are mitigating.

Excellent point - especially when it relates to projects on hand. Would you do disk encryption based on the knowledge that 31% of all breach incidents are the result of lost and stolen laptops? Of course you would. However, would you rethink your decision if you also know that these lost laptops account for only 9% of all data lost? Hmmm does FDE only reduce risk by 9%?

That begs the question, what else reduces risk by a larger percentage? Interesting topic and subject for another post....

Thursday, September 3, 2009

WhoHooo! BitArmor recognized in the latest Magic Quadrant!

Apologize for getting a bit excited - BitArmor is named in the 2009 Gartner Magic Quadrant for Mobile Data Protection! The full report can be read from the Gartner website. Our release about this recognition can be read from our website.

In this blog, I usually talk about my thoughts on the industry, evolution of security etc and I don't blog much about our product and the company. However, this I do think is a good excuse to do so :) It is good to be recognized by leading security analysts as John Girard and Eric Ouellet!

The report highlights our unique information-centric security approach to protecting data. It also talks about our No-Breach Guarantee. And one phrase I like is "far advanced" - as a way to describe our technology. Nice!

Being information-centric in our approach to data protection makes us a bit different from the other vendors in the document - most of them protect mobile devices. Because of our Smart Tag technology, BitArmor is able to protect the data itself at all times - thus the protected data can move to a laptop, USB device, via email as attachments or via FTP. It can also move from a file share to a data center server to a backup tape and still remain protected. From this perspective, we are truly fulfilling the real "Mobile Data Protection". I think the naming of this Magic Quadrant report is a bit ahead of its times!

However, as it stands now, most people associate data protection with "mobile devices" - i.e. protecting the devices that the data rests on (laptops, USBs, phones etc). And possibly for good reason - there were no good enough or usable enough technologies that could truly protect the data itself and that too persistently. Until now, of course!

I do think the Mobile Data Protection Magic quadrant will evolve more towards a data or information-centric approach in the coming years. Looking forward to our footprint trending, nay jumping, up and to the right!

Wednesday, July 23, 2008

For your hacking pleasure - Cold Boot utilities released!

Interesting news over the weekend. Looks like one of the original researchers from the Princeton Cold Boot attack work, Jacob Applebaum, published all the utilities they used to break full disk encryption products.

We, at BitArmor, have talked a bit about cold boot and how we protect against it. Our CEO Patrick and a few of our senior engineers will be presenting at Black Hat on techniques to prevent this attack - check out his perspective as well from his Princeton days.

Tuesday, July 1, 2008

2% of all laptops sold every year are stolen from airports?

Interesting analogy from NetworkWorld on rising rates of laptop loss, but it works! Apparently laptop loss is giving IHOP a run for its money. From the article...

"Some of the largest and medium-sized U.S. airports report close to 637,000 laptops lost each year, according to the Ponemon Institute survey released Monday. Laptops are most commonly lost at security checkpoints, according to the survey."

Over 630K laptops lost each year just within airports! From IDC's Quarterly PC tracker (Dec 2007) we see that over 31M laptops were projected to be sold in 2007. This means that over 2% of all laptops sold in the US were lost or stolen from airports!

Hard to believe. Am I exaggerating or is this for real? Makes me think about how cold boot can be a weapon of choice for criminals to gain access to sensitive data.

Thursday, May 8, 2008

Jeez - State department laptops missing..

This is bad news - folks with some of the most sensitive information seem to be willy-nilly with their laptops. How can we expect plain old corporate folks to take protection seriously?

And this snippet takes the cake "...about 400 missing laptops belonging to the Anti-Terrorism Assistance Program ..."

I wonder how many of these were targeted and stolen... If so, is a cold boot attack more likely against these types of assets?

Friday, March 14, 2008

To sleep, power off or hibernate - cold boot and user behaviour..

Interesting weeks - the last couple. Lots of folks debating whether the cold boot risk is real - is it too esoteric? Who do we know lugs around cans of liquid nitrogen to bring DRAM to 0 degree Kelvin!?! Maybe the guy who makes the Terminator movies...

I must admit the video was cool to watch - frozen chips... And therefore, most of the focus seems to have gone in that direction - thinking that one needs to cool the chips to extract the memory contents. But in reality, one needs only a USB drive with code to peek into DRAM - no need to even cool the chips! And Mr McGrew already has a tool - check out his comments "I did this as a small side project..." Nice!

Got me thinking on another topic - would be cool to do a survey on this. How many of us who lug around our laptops, travelling the country, shut it down? I personally never do - I only shut down my laptop when it starts to behave a bit erratic and slow. Else, I keep it on and when I travel just shut the lid.

I prefer sleep since it awakes quickly, hibernation seems to take longer. And with FDE enabled systems, this becomes more interesting:
-More RAM, larger hibernation file
-Larger hibernation file -> longer time to encrypt, i.e. close
-Larger hibernation file-> much longer time to decrypt and open

Hmm... I see sleep or power off as the only viable options for most folks with FDE!!

Now how does that compute with the risk scenario from the cold boot attack.. If I were an IT pro in a large organization, I would take a serious look at the power modes my mobile users use on their laptops...

Thursday, February 21, 2008

Disk encryption not enough?

Just saw this come off the wire - from news.com on how disk encryption from Bitlocker and Apple's FileVault has been circumvented by a few researchers. If this is as simple as they make it sound, this is a bit worrisome. However, I am not ready to buy this fully, till I understand this a bit more.

For one, I was under the impression that Bitlocker protected against booting via an alternative OS (especially a system with a TPM chip on it) because it can perform bootup integrity checks. The article seems to claim this is one of the ways in... Hmm, not so sure...

Further questions:
Is this attack valid for all authentication scenarios such as TPM+Pin?
How easy is it to scan the RAM on a locked system?

There was another article recently in eWeek that talked about FDE not being sufficient protection. I personally think that we need defense against multiple scenarios - not sure if the defense-in-depth term can be used, but seems to fit the best...

Looking forward to understanding this a bit more...