Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Wednesday, 6 April 2016

Good night Vienna for (client) confidentiality

There is a really strong moment in Jurassic Park when the character played by Jeff Goldblum delivers the line "they were so pre-occupied with whether they could they didn't stop to think if they should".

Whoever is the current (or maybe former by now) head of IT / Security at Panama law firm Mossak Fonseca must be wishing nostalgically for the days of typewriters and attractive people reaching for the bottom drawer of the metal filing cabinet.

According to reports the data breach which is by some measurements the largest ever at 2.6 TB of data with documents going back to the 1970's was achieved through a breach of the security on the email server leading to the download of its entire contents. Since 1970 was pre-digital the decision must have been taken to digitize hard documents and add them to the servers.

One might expect a massive download of this type to be picked up by network monitoring systems and therefore it seems likely that the external hackers had some internal assistance - but that is speculation. The alternative is that no network monitoring was occurring which might leave you wondering what the IT dept were up to (other than watching dodgy online content and surfing social media).

As none of the documents were encrypted once breach had occurred it was very much "good night Vienna"  both for the clients of Mossac Fonseca and the concept of confidentiality between lawyer and client.

As a broader issue medical records and all other digitally stored content that is not encrypted must now be considered semi-public.

While 3TB may seem large (maybe 10 million docs) portable storage for this can be bought off the shelf for about £115. Any unhappy person in any IT department can simply walk out the door with sensitive data.

The ethics around the actions of Edward Snowden and the hackers involved in the Mossak Fonseca case are not clear cut and unless you are an ends justifies the means merchant they will always be in a grey area.

The key thing to now accept is that the old adage from Benjamin Franklin rings true "Three people can keep a secret, if two of them are dead."




Monday, 18 January 2016

Back to the future

With the comeback of the turntable might the typewriter be hot on its heels ?

As security concerns regarding the Internet start to penetrate more deeply into people's thinking might very confidential documents be kept "off the grid" all together ?

Encryption algorithms are not 100% secure - but effective enough for most applications - leaving a space when total technical security is required and a device which cannot be networked cannot be hacked in the technical sense. This does not eliminate the human factor in security (the typist for example) but narrows the attack surface.

The type of language used in the security industry is also pretty hard to fathom sometimes  for the non expert which would make a return to a simple solution such as a type writer even more understandable when absolute confidentiality is required. If Snowden had tried to wander out with 50 box loads of paper files he might well have been spotted.

An example of this hard to penetrate language is below from the OWASP top 10 pro active controls for 2016 (all of which are very sensible if you can understand them);

1. Verify for Security Early and Often
2. Parameterize Queries
3. Encode Data
4. Validate All Inputs
5. Implement Identity and Authentication Controls
6. Implement Appropriate Access Controls
7. Protect Data
8. Implement Logging and Intrusion Detection
9. Leverage Security Frameworks and Libraries
10. Error and Exception Handling

Thursday, 17 December 2015

The liability aspect of handling personal data - 4% of turnover

It seems that Europe has had enough of companies processing personal data without appropriate consideration and safeguards in place.

Earlier this week wording was agreed for new data protection legislation which is expected to come into force in 2 years.

Key wording is that personal data must be "processed in a way that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures".

The agreed wording identifies the types of issues that companies might consider to meet this threshold;

1. Pseudonymisation / encryption of personal data
2. Ability to ensure ongoing confidentiality, integrity, availability and resilience
3. Data restoration post breach
4. Regular testing

The bottom line is that the profitability of data processing will drop as the costs of maintaining a secure digital environment are material and most businesses will face additional compliance costs. As a minimum companies who process personal data will require either in house or as a contractor an individual who can assess digital security risks sensibly and address problems (a data protection officer).

Amusingly the governments have secured broad exceptions to these rules even though they tend to make the greatest howlers in this area - see Edward Snowden.

On that note a clip from Catch 22...............


Thursday, 3 December 2015

Proposed EU Data Protection regulations grow some serious teeth in the Digital Age

It is amazing what people will do to get noticed as this young lady in Thailand demonstrates. At the other end of the scale the smooth law makers within the EU gently slide obligations towards us almost unnoticed.

The Digital Single Market and the associated Data Protection regulations are scheduled to come into force in December 2017 and bring with them a very different regime for managing personal data. Within the UK the Data Protection Act 1998 requires six core principles to be followed. One of these principles is that personal data is kept safe and secure.

The maximum fine under the DPA is £500,000 and therefore while this is a substantial sum it is possibly less than the cost of required data security for a large organisation such as Talk Talk (just for example).

Under the proposed new regime fines can be between 2% and 5% of turnover up to a maximum of £100 million. Using Talk Talk as an example with a turnover of £1.8 billion the maximum theoretical liability would be £90 million. Possibly worth addressing the SQL injection issues then ?

The guiding principle under the proposed new regime looks to be that companies or individuals handling personal data (which is pretty much anything) need to meet "reasonable expectations of data privacy" and liability follows if they do not.

The suggestion is made that encryption is one potential way to meet this requirement but this is not a given. If an encryption system is found to be flawed or have a back door it presumably does not meet this threshold ? Implementing one encryption system is tricky enough but having to change systems in a hurry is breakdown material if encryption is cracked.

Another aspect to the proposed legislation is the right to erasure. This immediately brings to mind the popular club music duo of Andy Bell and Vince Clarke but this was probably not the aim of the law makers involved. The serious point is that information will need to be actively managed so it does not remain for ever which will impose a layer of further cost.

Massive organisations such as Banks, Telcos and ISP's who hold personal data are looking at chunky liabilities and costs as are the the service providers who manage the data.

Within the SME community this will be even more challenging as the IT systems and suppliers often fit into the cheap and cheerful category and don't have much resource to direct at IP and Cyber protection and data management.

For about 15 years there has been a relaxed attitude to IP protection in the Digital Age but post Snowden, Sony Pictures and TalkTalk this is drawing to a close and regulation (with cost) is on its way.