<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.alertboot.com/blog/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>AlertBoot Endpoint Security : full disk encryption</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx</link><description>Tags: full disk encryption</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Build: 20611.960)</generator><item><title>UK BYOD Security: 82% Of Biz Unaware Of Existing Data Protection Expenditures</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/05/15/uk-byod-security-82-of-biz-unaware-of-existing-data-protection-expenditures.aspx</link><pubDate>Wed, 15 May 2013 12:24:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2597</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2597</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/05/15/uk-byod-security-82-of-biz-unaware-of-existing-data-protection-expenditures.aspx#comments</comments><description>&lt;blockquote&gt;The UK Information Commissioner&amp;#39;s Office (ICO) ordered a report to find the extent of English businesses&amp;#39; knowledge on the European Commission&amp;#39;s data protection reforms. Among other things, the updates to the privacy laws further encourage (indirectly) the use of &lt;a href="http://www.alertboot.com/" title="mobile device data security and encryption" target="_blank"&gt;data protection software&lt;/a&gt;, like AlertBoot&amp;#39;s Mobile Security for smartphones and tablets, as well as introducing novel ideas such as the &amp;quot;right to be forgotten.&amp;quot;&lt;/blockquote&gt;&lt;h3&gt;Bad News&lt;/h3&gt;&lt;blockquote&gt;The survey&amp;#39;s results are not very encouraging.&amp;nbsp; For example, it turns out that 82% of businesses did not know how much they spend on data protection.&amp;nbsp; Observed &lt;i&gt;information-age.com&lt;/i&gt;,&lt;br /&gt;&lt;blockquote&gt;it is not surprising, then, that 87% could not estimate what the impact of the reforms would be.&lt;br /&gt;&lt;br /&gt;Respondents were asked to describe the reforms as they understand them. Four out of ten had an inaccurate understanding of all ten reforms, and not one fully understands every one.&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;h3&gt;An Easier Way?&amp;nbsp; A Totally Transparent Cost Structure&lt;/h3&gt;&lt;blockquote&gt;I don&amp;#39;t know about &amp;quot;the inaccurate understanding of all ten reforms,&amp;quot; but I can understand why most businesses don&amp;#39;t have a good idea on their data protection budget.&amp;nbsp; &lt;i&gt;&lt;b&gt;The answer is that it&amp;#39;s not easy figuring out what it actually costs&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;Consider just one example of data security: &lt;a href="http://www.alertboot.com/disk_encryption/full_disk_encryption.aspx" title="laptop full disk encryption software" target="_blank"&gt;laptop computer encryption&lt;/a&gt; and &lt;a href="http://www.alertboot.com/disk_encryption/mobile_security_byod_mdm.aspx" title="MDM for smartphones and tablets" target="_blank"&gt;mobile device security for smartphones and tablets&lt;/a&gt;.&amp;nbsp; Under the traditional model you have:&lt;br /&gt;&lt;ul&gt;
&lt;li&gt;&lt;b&gt;License purchases.&amp;nbsp; &lt;/b&gt;Depending on the approach, a company may have to purchase the licenses in pre-arranged blocks, say at least 100 licenses, and 50 additional license blocks after that.&amp;nbsp; If you need 105 licenses, you have to purchase 150.&amp;nbsp; The remaining 45 are sometimes called &amp;quot;shelfware&amp;quot; because that&amp;#39;s where they end up; maybe you&amp;#39;ll them all, maybe you won&amp;#39;t.&lt;br /&gt;&lt;br /&gt;Because computers are tracked (e.g., to install updates or new software), you have a good idea of how many machines are on your network.&amp;nbsp; But the cost of the data security is actually greater than that because of shelfware as well as computers than are not plugged to the network.&amp;nbsp; Unless you have meticulous records, chances are your estimates will be lower than reality.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Bring Your Own Management Server.&amp;nbsp; &lt;/b&gt;In other words, you have to provide the infrastructure for managing, deploying, and installing the licenses you just purchased.&amp;nbsp; Of course, you could do it without central management.&amp;nbsp; But if you have more than, say, 50 computers to manage (again, to install updates or new software or whatever), a management server saves time and money.&amp;nbsp; But only if you plunk down money.&amp;nbsp; The problem is that you may add, retire, or repurpose servers as necessary or as opportunity permits.&lt;br /&gt;&lt;br /&gt;And, by doing so, you also change the equations for what you&amp;#39;re spending in terms of electricity, peripherals (like LAN cables and whatnot), etc.&amp;nbsp; In the end, these add up to a substantial figure.&amp;nbsp; But, with things moving in and out, you&amp;#39;re never quite sure what the figure is.&amp;nbsp; For example, a management server for full disk encryption is repurposed as a printer server...did you update your accounting spreadsheets as well?&lt;br /&gt; &lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Data Center.&amp;nbsp; &lt;/b&gt;Many companies make use of data centers to ensure reliability and uptime of core operations.&amp;nbsp; The data security portion probably holds a fraction of the space allocated in a data center.&amp;nbsp; So what are its costs, exactly?&amp;nbsp; You know you&amp;#39;re paying saying, $5,000 per month, but how much of that is assigned to the data protection portion?&amp;nbsp; Good luck finding out.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Employees.&amp;nbsp; &lt;/b&gt;Maybe the company has an IT department.&amp;nbsp; And maybe the IT department&amp;#39;s personnel are doing double (or triple) duty as coders, troubleshooters, software installers, hardware installers, and who knows what else.&amp;nbsp; How much of their time is spent on data security stuff?&amp;nbsp; Or maybe they&amp;#39;ve got people dedicated to doing password resets for people who forgot their passwords and are locked out of their computers.&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;As you can see, trying to figure out how much data security costs is fraught with blind spots.&lt;br /&gt;&lt;br /&gt;Of course, it doesn&amp;#39;t necessarily have to be this way.&amp;nbsp; AlertBoot&amp;#39;s security suite for endpoints – AlertBoot Mobile Security for BYOD and AlertBoot Full Disk Encryption for laptop hard drives – are a model of cost transparency: a flat annual price without any predefined license purchases: you can obtain as many (or as little) licenses as you need.&lt;br /&gt;&lt;br /&gt;This is possible because the solution is cloud-based, hosted on AlertBoot&amp;#39;s data centers.&amp;nbsp; This means any hardware and software issues are left up to AlertBoot.&amp;nbsp; Furthermore, the company provides support and password recovery services 24/7, ensuring that the IT department is focused on more important matters.&lt;br /&gt;&lt;br /&gt;Because all of this is included in AlertBoot&amp;#39;s offerings, calculating data security costs are also very easy.&lt;/p&gt;&lt;/blockquote&gt;&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://www.information-age.com/it-management/risk-and-compliance/123457048/uk-businesses-don-t-understand-eu-data-reforms--ico-finds" target="_blank"&gt;http://www.information-age.com/it-management/risk-and-compliance/123457048/uk-businesses-don-t-understand-eu-data-reforms--ico-finds&lt;/a&gt;&lt;br /&gt;
&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2597" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security/default.aspx">laptop security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software/default.aspx">encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security+breach/default.aspx">endpoint security breach</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hdd+encryption+software/default.aspx">hdd encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+hdd+encryption/default.aspx">laptop hdd encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+law/default.aspx">encryption law</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software+provider/default.aspx">encryption software provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+provider/default.aspx">laptop encryption provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+service+provider/default.aspx">encryption service provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/UK/default.aspx">UK</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+encryption/default.aspx">Android encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+encryption/default.aspx">iPhone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+security/default.aspx">Android security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+protection/default.aspx">Android protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+security/default.aspx">tablet security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+encryption/default.aspx">tablet encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+protection/default.aspx">iPhone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+protection/default.aspx">tablet protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+protection/default.aspx">smartphone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+security/default.aspx">smartphone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+encryption/default.aspx">smartphone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/bring-your-own-device/default.aspx">bring-your-own-device</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization/default.aspx">consumerization</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization+of+IT/default.aspx">consumerization of IT</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+security/default.aspx">iPad security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+encryption/default.aspx">iPad encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+protection/default.aspx">iPad protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/MDM/default.aspx">MDM</category></item><item><title>Data Backup Encryption: Kmart (Inadvertently) Suffers Data Breach At Gun Point</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/29/data-backup-encryption-kmart-inadvertently-suffers-data-breach-at-gun-point.aspx</link><pubDate>Mon, 29 Apr 2013 13:31:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2591</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2591</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/29/data-backup-encryption-kmart-inadvertently-suffers-data-breach-at-gun-point.aspx#comments</comments><description>&lt;blockquote&gt;Do you backup your data?&amp;nbsp; Excellent!&amp;nbsp; Do you use &lt;a href="http://www.alertboot.com/" title="full disk encryption software as a cloud service" target="_blank"&gt;encryption software&lt;/a&gt; to protect its contents?&amp;nbsp; Not doing so means that you&amp;#39;ve joined the &amp;quot;Data Breach Club,&amp;quot; where the chances of a data breach are not an &amp;quot;if&amp;quot; but &amp;quot;when.&amp;quot;&amp;nbsp; Take Kmart as an example, which had a data breach because a thief robbed one of its store at gunpoint.&lt;/blockquote&gt;
&lt;h3&gt;Nobody Expects their Data Backup to be Stolen&lt;/h3&gt;
&lt;blockquote&gt;When I first heard that Kmart had to publicize a data breach because of HIPAA regulations, it hit me like a bag of surrealistic bricks (Kmart and HIPAA/HITECH?).&amp;nbsp; But, I remembered that many Kmart locations also include a pharmacy.&amp;nbsp; The story, as &lt;i&gt;storefrontbacktalk.com &lt;/i&gt;describes it, is as follows:&lt;br /&gt;&lt;br /&gt;On March 17, an armed robbery took place at a Little Rock, Arkansas Kmart.&amp;nbsp; The assault took about an hour after closing time, and the perpetrator pointed a gun to the assistant store manager and forced him to open the store safe.&amp;nbsp; The thief wiped it clean, which included $6,000 in cash and a backup disk.&lt;br /&gt;&lt;br /&gt;The backup disk contained &amp;quot;full names, addresses, dates of birth, prescription numbers, prescribers, insurance cardholder IDs and drug names for some 788 customers&amp;quot; and, in certain cases, SSNs as well (well, more than a few.&amp;nbsp; The spokesperson noted it was a &amp;quot;few hundred customers.&amp;quot;&lt;br /&gt;&lt;br /&gt;It was expressly pointed out that &lt;a href="http://www.alertboot.com/disk_encryption/disk_encryption_product_tour.aspx" title="BYOD laptop disk encryption" target="_blank"&gt;disk encryption&lt;/a&gt; was not used, nor &lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2008/05/20/full-disk-encryption-is-much-more-powerful-than-password-protection.aspx" title="difference between passwords and encryption when it comes to protection" target="_blank"&gt;its enfeebled cousin, password-protection&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Aside from the obvious mistakes, the spokesperson made two additional observations: (1) that accessing the customers&amp;#39; information &amp;quot;is slim to none, because you would need to know what software package&amp;quot; was used, and (2) that they were quick in contacting customers because they did so in about a month, as opposed to the 60 days that they&amp;#39;re given.&lt;/blockquote&gt;
&lt;h3&gt;Data Breach Possibility, Slim to None: Only If You Used Encryption&lt;/h3&gt;
&lt;blockquote&gt;The observation that accessing customers&amp;#39; information is slim to none is debatable at best.&amp;nbsp; It is slim to none because chances are the thief is not going to look.&amp;nbsp; Generally, when a laptop gets stolen, it&amp;#39;s wiped and reformatted for sale (at least, that&amp;#39;s the reigning consensus).&amp;nbsp; One assumes the same would hold for disk drives used as backups.&lt;br /&gt;&lt;br /&gt;Then again, we must remember that this disk drive was inside a safe.&amp;nbsp; That already suggests that something valuable is stored in it.&amp;nbsp; Under the circumstances, what are the chances that the thief will ignore the suggestion that it&amp;#39;s worth his while to see what&amp;#39;s in it?&lt;br /&gt;&lt;br /&gt;And, if he does, then the odds of a data breach are not really slim to none: freely available software from the internet can be used to scan a disks contents for particular information, like Social Security numbers (either as a pattern of 000-00-0000 or as a string of 9 numbers).&lt;br /&gt;&lt;br /&gt;Only in the event that encryption is used can one confidently declare that particular breach is nearly riskless.&lt;/blockquote&gt;
&lt;h3&gt;HIPAA Data Breaches and Unreasonable Delays: You (Don&amp;#39;t Really) Have 60 Days to Report It&lt;/h3&gt;
&lt;blockquote&gt;One of the more misinformed statements I&amp;#39;ve read is the following:&lt;blockquote&gt;Asked why the delay [a little over one month], Sears spokesperson Shannelle Armstrong-Fowler pointed out that the chain moved much more quickly than the law requires. &amp;quot;Under HIPAA guidelines, 60 days are available for a health care entity to investigate and report on a potential breach. We completed our investigation and notified customers in approximately thirty days,&amp;quot; she said.&lt;/blockquote&gt;This is entirely correct as well as partially true (what, you say?&amp;nbsp; That sounds like a contradiction?&amp;nbsp; Read on).&amp;nbsp; As the Department of Health and Human Services (HHS) has pointed out in various publications, a breached entity must contact affected patients within 60 calendar days.&amp;nbsp; However, it has noted that the HIPAA covered-entity must also contact patients as soon as possible.&amp;nbsp; In a previous post (&lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2011/07/05/data-encryption-software-does-hipaa-hitech-really-give-you-60-days-for-patient-notification.aspx" title="HIPAA / HITECH Breach Report 60 days" target="_blank"&gt;Does HIPAA / HITCH Really Give You 60 Days For Patient Notification?&lt;/a&gt;), I wrote the following:&lt;blockquote&gt;It behooves administrators for a HIPAA-covered entity to take a good look at the HHS&amp;#39;s opinions on the matter of data breaches and notifications.&amp;nbsp; The 60-day limit is an &amp;quot;upper limit&amp;quot; and covered entities are expected to contact patients ASAP.&lt;/blockquote&gt;and supported the argument by noting the following passages from the &lt;a href="http://www.gpo.gov/fdsys/pkg/FR-2009-08-24/pdf/E9-20169.pdf" target="_blank"&gt;Federal Register&lt;/a&gt;:&lt;blockquote&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;quot;...if a covered entity &lt;b&gt;learns of an impermissible use or disclosure but unreasonably allows the investigation to lag&lt;/b&gt; for 30 days, this would constitute an unreasonable delay.&amp;quot;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;quot;...if a covered entity has &lt;b&gt;compiled the information necessary to provide notification to individuals on day 10 but waits until day 60 to send the notifications&lt;/b&gt;, it would constitute an unreasonable delay despite the fact that the covered entity has provided notification within 60 days.&amp;quot;&lt;/blockquote&gt;If the HHS Office of Civil Rights (OCR) were to conduct an audit and were to find that Kmart had unnecessary delayed contacting patients, it could mean severe legal repercussions for the wholesaler.&amp;nbsp; Under HIPAA, 60 days is not really 60 days.&lt;br /&gt;&lt;br /&gt;I&amp;#39;m no PR expert, but it seems to me that the spokeswoman should have focused on stating that they had to conduct an investigation, couldn&amp;#39;t finish it any sooner, and notified its customers as soon as possible.&lt;br /&gt;&lt;br /&gt;Of course, when you consider that the stolen disk affected 788 Kmart customers, one wonders whether they couldn&amp;#39;t have been notified any sooner, and whether 30 days was really necessary.&amp;nbsp; I&amp;#39;ve certainly seen situations where even more people were affected and notification letters were sent in a couple of weeks.&lt;br /&gt;&lt;br /&gt;On the other hand, I&amp;#39;ve seen the inverse as well.&amp;nbsp; The trick, it seems, is to design your systems with the possibility that a data breach will occur.&amp;nbsp; By doing so, processes for a quick recovery are implemented.&lt;br /&gt;&lt;br /&gt;For example, the reporting engine in AlertBoot Mobile Security allows one to &lt;a href="http://www.alertboot.com/disk_encryption/encryption_compliance_auditing_and_reporting.aspx" title="encryption audit reports and compliance reports" target="_blank"&gt;easily generate mobile security audit and incident reports&lt;/a&gt;.&amp;nbsp; It&amp;#39;s used by many of our clients to prove compliance with laws and regulations in the event a mobile device (like a smartphone or a tablet) or a laptop computer is lost or stolen.&lt;/blockquote&gt;
&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://www.natlawreview.com/article/data-breach-gunpoint" target="_blank"&gt;http://www.natlawreview.com/article/data-breach-gunpoint&lt;/a&gt;&lt;br /&gt;&lt;a href="http://storefrontbacktalk.com/securityfraud/data-breach-at-gunpoint-kmart-armed-robber-walks-away-with-sensitive-pharmacy-records" target="_blank"&gt;http://storefrontbacktalk.com/securityfraud/data-breach-at-gunpoint-kmart-armed-robber-walks-away-with-sensitive-pharmacy-records&lt;/a&gt;&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2591" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+encryption/default.aspx">data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/device+encryption/default.aspx">device encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/HIPAA/default.aspx">HIPAA</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/law/default.aspx">law</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/security/default.aspx">security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+drive+encryption/default.aspx">hard drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+theft+prevention/default.aspx">data theft prevention</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/cryptography+software/default.aspx">cryptography software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/information+security/default.aspx">information security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/secure+digital+assets/default.aspx">secure digital assets</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security/default.aspx">endpoint security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/usb+drive+encryption/default.aspx">usb drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/prevent+data+leakage/default.aspx">prevent data leakage</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+at+rest+encryption/default.aspx">data at rest encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/drive+encryption/default.aspx">drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software/default.aspx">encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/identity+theft/default.aspx">identity theft</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/password+protection/default.aspx">password protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/disk+encryption/default.aspx">disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/backup+tape+encryption+software/default.aspx">backup tape encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security+breach/default.aspx">endpoint security breach</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/computer+encryption+software/default.aspx">computer encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hdd+encryption+software/default.aspx">hdd encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/securing+corporate+laptops/default.aspx">securing corporate laptops</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+law/default.aspx">encryption law</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/usb+device+security/default.aspx">usb device security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/usb+device+protection/default.aspx">usb device protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software+provider/default.aspx">encryption software provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security+provider/default.aspx">data security provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+service+provider/default.aspx">encryption service provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/breach+notification/default.aspx">breach notification</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+standard/default.aspx">encryption standard</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/media+encryption+and+protection/default.aspx">media encryption and protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+information+encryption/default.aspx">personal information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/medical+data+encryption/default.aspx">medical data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/patient+data+encryption/default.aspx">patient data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+in+motion+encryption/default.aspx">data in motion encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hospital+encryption/default.aspx">hospital encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/MDM/default.aspx">MDM</category></item><item><title>Personal Data Breach: Consumer Churn Rate Directly Tied To Infosec Events Is Significant</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/22/personal-data-breach-customer-churn-rate-directly-tied-to-infosec-events-is-significant.aspx</link><pubDate>Mon, 22 Apr 2013 08:46:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2588</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2588</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/22/personal-data-breach-customer-churn-rate-directly-tied-to-infosec-events-is-significant.aspx#comments</comments><description>&lt;blockquote&gt;A global study has revealed that personal data breaches lead to sizable numbers of customers to turn their back on companies.&amp;nbsp; This might not be news, but perhaps the figures are: 23% of the respondents affirmatively answered that they have stopped doing business companies that failed to properly safeguard their data.&amp;nbsp; All the more reason why a company should up the security ante by using some kind of &lt;a href="http://www.alertboot.com/" title="Managed cloud-based smartphone and tablet BYOD protection" target="_blank"&gt;data protection solution&lt;/a&gt; like AlertBoot (especially in this age of BYOD).&lt;/blockquote&gt;
&lt;h3&gt;We Will vs. We Have&lt;/h3&gt;
&lt;blockquote&gt;News of this study comes courtesy of &lt;i&gt;databreaches.net&lt;/i&gt;.&amp;nbsp; As the author at the site noted, there is a tremendous difference between what people claim they will do vs. what they actually end up doing.&amp;nbsp; To account for this discrepancy, the authors of a study by the Economist Intelligence Unit asked the following (my own paraphrase):
&lt;blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Would you stop doing business with an organization that breached your data?&lt;/li&gt;

&lt;li&gt;Have you actually suffered from a data breach, and if so, did you stop doing business with the company that experienced the data breach?&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;To the former, 32% of the respondents answered in the affirmative.&amp;nbsp; To the latter, 38% answered in the affirmative.&lt;br /&gt;&lt;br /&gt;This is a very curious outcome.&amp;nbsp; Generally speaking, the latter tends to be lower than the former.&amp;nbsp; That is, there are always more people that say they will do something, in contrast to those who actually do something.&amp;nbsp; Hark back to New Year resolutions, for example: you&amp;#39;ll always have more people who &lt;i&gt;promise &lt;/i&gt;to lose weight, or to read more, or to procrastinate less; how many keep that promise, though?&lt;br /&gt;&lt;br /&gt;What does this unexpected finding mean?&amp;nbsp; Off the top of my head, it seems to indicate that it&amp;#39;s only after they&amp;#39;ve become victims of a data breach that people realize the severity of the situation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3&gt;Spillover Effect&lt;/h3&gt;
&lt;blockquote&gt;Not only that, it turns out that there are further ramifications:&lt;blockquote&gt;the EIU research also found that 46% of respondents that had suffered a data breach had advised friends and family to be careful of sharing data with the organization.&lt;/blockquote&gt;Many companies look to get their products to &amp;quot;go viral&amp;quot; or make it spread via word of mouth, knowing that recommendations from friends, family, and acquaintances carry more weight than any marketing campaign some guys in an office can create.&lt;br /&gt;&lt;br /&gt;Imagine, then, the disastrous effects the above could have on a company.
&lt;/blockquote&gt;
&lt;h3&gt;Nip It in the Bud because It&amp;#39;s a Drop in the Bucket&lt;/h3&gt;
&lt;blockquote&gt;An ounce of prevention is worth a pound of cure; so goes the old saying.&amp;nbsp; Nowadays, I&amp;#39;m under the impression that the value of the cure is much, much higher.&lt;br /&gt;&lt;br /&gt;Consider all the things that could go wrong by not employing, say, a &lt;a href="http://www.alertboot.com/disk_encryption/mobile_security_byod_mdm.aspx" title="smartphone at work security" target="_blank"&gt;BYOD security solution&lt;/a&gt; like AlertBoot Mobile Security.&amp;nbsp; Assume that you can get the service for $100 per year, per device (it&amp;#39;s actually much more cost effective, but I like easy numbers to work with).&lt;br /&gt;&lt;br /&gt;Also, assume you&amp;#39;ve got 100 employees who opt to bring in their smartphones and tablets to use at work.&amp;nbsp; This means you&amp;#39;d be spending $100,000 per year on what appears to be a bottomless pit.&amp;nbsp; After all, it&amp;#39;s not as if security threats are going away any time soon.&amp;nbsp; One hundred large ones sound like a big number.&lt;br /&gt;&lt;br /&gt;But what about the flipside of the coin?
&lt;blockquote&gt;
&lt;ul&gt;
&lt;li&gt;There&amp;#39;s the approximate one-third of your customers that will not be doing business with you in the foreseeable future.&amp;nbsp; What does that translate to in lost revenue?&lt;/li&gt;

&lt;li&gt;Your marketing will see a drop in ROI as you work harder to bring in new clients to replace the ones you&amp;#39;ve lost.&amp;nbsp; That&amp;#39;s money you didn&amp;#39;t need to spend if you had proper security, on an activity whose efficiency is debatable.&lt;/li&gt;

&lt;li&gt;Depending on which sector your business is in (finance, healthcare, e.g.), you might have to incur the costs of an audit, internal as well as external (by the government, such as an audit by HIPAA/OCR).&amp;nbsp; These easily run into the five figures, &lt;i&gt;at least&lt;/i&gt;.&lt;/li&gt;

&lt;li&gt;Reaching out to &amp;quot;breachees&amp;quot;.&amp;nbsp; Most state and federal laws that oversee personal data laws require that first-class mail (or equivalent) be used.&amp;nbsp; If the breach involves 200,000 people and you can mail each letter for $0.25, that&amp;#39;s $50,000 you&amp;#39;re spending to shoot yourself in the foot.&amp;nbsp; That cost doesn&amp;#39;t include the loss of productivity as your employees are working to help you shoot yourself in the foot.&lt;/li&gt;

&lt;li&gt;Why do I keep writing that &amp;quot;you&amp;#39;re shooting yourself in the foot&amp;quot;?&amp;nbsp; Because around 33% of the people you&amp;#39;re reaching out to will probably turn their backs on you, per the survey.&lt;/li&gt;

&lt;li&gt;Lawsuits.&amp;nbsp; &amp;#39;Nough said.&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;No doubt there is more to the flipside of the coin; I&amp;#39;ve just run out of time to list them all.&amp;nbsp; What would all of this cost?&amp;nbsp; Depends on the size of the breach, but it could very well be in the millions of dollars.&lt;br /&gt;&lt;br /&gt;For example, &lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2010/01/26/cost-of-a-medical-data-breach-7-million-and-counting-at-bcbs-tennessee.aspx" target="_blank"&gt;BCBS of Tennessee saw its data breach costs soar to $7 million&lt;/a&gt; when 220,000 patients were affected by a data breach.&amp;nbsp; By the end of the whole ordeal, they had &lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2010/07/16/data-encryption-story-follow-up-bcbs-of-tennessee-saga-comes-to-a-close.aspx" target="_blank"&gt;spent nearly $10 million&lt;/a&gt; for contacting members affected, investigating the theft, and offering free credit protection&amp;quot;.&lt;br /&gt;&lt;br /&gt;And this is before the fine that OCR levied on them for breaching HIPAA (technically, BCBS settled for $1.5 million, which is the maximum penalty that OCR can assess), or the reputational damage they took.&lt;br /&gt;&lt;br /&gt;Or the security solutions they ended up adding into their risk prevention portfolio.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://www.databreaches.net/?p=27398" target="_blank"&gt;http://www.databreaches.net/?p=27398&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.net-security.org/secworld.php?id=14779" target="_blank"&gt;http://www.net-security.org/secworld.php?id=14779&lt;/a&gt;&lt;br /&gt;
&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2588" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/theft/default.aspx">theft</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security/default.aspx">data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+theft+prevention/default.aspx">data theft prevention</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encrypted+data/default.aspx">encrypted data</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/information+security/default.aspx">information security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/secure+digital+assets/default.aspx">secure digital assets</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security/default.aspx">endpoint security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security/default.aspx">laptop security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/prevent+data+leakage/default.aspx">prevent data leakage</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+at+rest+encryption/default.aspx">data at rest encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+safe/default.aspx">laptop safe</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software/default.aspx">encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/identity+theft/default.aspx">identity theft</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+solution/default.aspx">laptop encryption solution</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security+breach/default.aspx">endpoint security breach</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security+software/default.aspx">laptop security software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+laptop+encryption/default.aspx">personal laptop encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hdd+encryption+software/default.aspx">hdd encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+hdd+encryption/default.aspx">laptop hdd encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/securing+corporate+laptops/default.aspx">securing corporate laptops</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/cost+of+computer+security+breach/default.aspx">cost of computer security breach</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/cost+of+endpoint+security+breaches/default.aspx">cost of endpoint security breaches</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/cost+of+lost+laptops/default.aspx">cost of lost laptops</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/persistent+encryption/default.aspx">persistent encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software+provider/default.aspx">encryption software provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security+provider/default.aspx">data security provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+service+provider/default.aspx">encryption service provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Australia+encryption/default.aspx">Australia encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/portable+drive+encryption/default.aspx">portable drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+information+encryption/default.aspx">personal information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/patient+data+encryption/default.aspx">patient data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/bank+data+encryption/default.aspx">bank data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/financial+information+encryption/default.aspx">financial information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hospital+encryption/default.aspx">hospital encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/UK/default.aspx">UK</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+encryption/default.aspx">Android encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+encryption/default.aspx">iPhone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+security/default.aspx">Android security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+protection/default.aspx">Android protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+security/default.aspx">tablet security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+encryption/default.aspx">tablet encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+security/default.aspx">iPhone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+protection/default.aspx">iPhone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+protection/default.aspx">tablet protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+protection/default.aspx">smartphone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+security/default.aspx">smartphone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+encryption/default.aspx">smartphone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/bring-your-own-device/default.aspx">bring-your-own-device</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization/default.aspx">consumerization</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization+of+IT/default.aspx">consumerization of IT</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/BYOD/default.aspx">BYOD</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+security/default.aspx">iPad security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+encryption/default.aspx">iPad encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+protection/default.aspx">iPad protection</category></item><item><title>Smartphone And Tablet BYOD Security: Because Physical Attacks Cannot Be Discounted</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/12/smartphone-and-tablet-byod-security-because-physical-attacks-cannot-be-discounted.aspx</link><pubDate>Fri, 12 Apr 2013 12:47:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2584</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2584</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/04/12/smartphone-and-tablet-byod-security-because-physical-attacks-cannot-be-discounted.aspx#comments</comments><description>&lt;blockquote&gt;Many websites reported earlier in the week that Vudu, a video-streaming company that&amp;#39;s owned by Walmart, reported a data breach.&amp;nbsp; Furthermore, Vudu recommended that users of the service reset their passwords, especially if their passwords are reused on other online sites.&amp;nbsp; These are usually the words of a company that was hacked online, such as with a SQL injection attack.&lt;br /&gt;&lt;br /&gt;With Vudu, however, it&amp;#39;s different: burglars broke into the Santa Clara, California-based company on March 24, 2013 and stole computer hard drives.&amp;nbsp; The data breach was limited by practicing adequate security, although the hard drives were not protected with the likes of &lt;a href="http://www.alertboot.com/" title="managed laptop disk encryption and BYOD security" target="_blank"&gt;full disk encryption&lt;/a&gt; such as AlertBoot.&amp;nbsp; This goes to show the need for proper data security on all devices, including smartphones, tablets, and laptops.&amp;nbsp; The threat is not just virtual.&lt;br /&gt;&lt;/blockquote&gt;
&lt;h3&gt;Customer Data Compromised&lt;/h3&gt;
&lt;blockquote&gt;Vudu revealed that the stolen drives contained the following information: customer names, email addresses, physical mailing addresses, Vudu account activity, dates of birth, the last four digits of credit cards, and &amp;quot;encrypted passwords.&amp;quot;&lt;br /&gt;&lt;br /&gt;Despite all the things that Vudu did correctly, it fell flat in one area: it didn&amp;#39;t notify clients until two weeks after the break-in.&amp;nbsp; In their &lt;a href="http://www.vudu.com/password_faq.html" target="_blank"&gt;FAQ&lt;/a&gt;, Vudu clarifies that they needed to &amp;quot;reconstruct the information&amp;quot; and that &amp;quot;law enforcement requested that [Vudu] delay notification.&amp;quot;&lt;br /&gt;&lt;br /&gt;I include quotes for &amp;quot;encrypted passwords&amp;quot; because they&amp;#39;re probably not encrypted as much as they are &lt;i&gt;hashed&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;What&amp;#39;s the difference, you may ask?&lt;/blockquote&gt;&lt;h3&gt;Encrypted Passwords Generally Not Encrypted&lt;/h3&gt;&lt;blockquote&gt;Generally, &amp;quot;encrypted passwords&amp;quot; are not really encrypted.&amp;nbsp; If they were, they wouldn&amp;#39;t be easy to guess or figure out.&amp;nbsp; Indeed, it&amp;#39;s the reason why devices like iPhones, iPads, and Android smartphones all use &lt;a href="http://www.alertboot.com/disk_encryption/disk_encryption_product_tour.aspx" title="cloud-based smartphone disk encryption" target="_blank"&gt;disk encryption&lt;/a&gt;.&amp;nbsp; The use of encryption makes it virtually impossible to gain unauthorized access to the data in the devices (and, thus, is one of the core aspects of AlertBoot&amp;#39;s &lt;a href="http://www.alertboot.com/disk_encryption/mobile_security_byod_mdm.aspx" title="smartphone MDM as a service" target="_blank"&gt;mobile device management and security solution&lt;/a&gt;, although users of AlertBoot can manage many different aspects associated with mobile security to suit their needs).&lt;br /&gt;&lt;br /&gt;Whereas the implication here, with Vudu strongly urging password changes, is that the passwords could be guessed, meaning that the passwords were hashed.&amp;nbsp; A &amp;quot;hash&amp;quot; is when a password is passed through an algorithm and comes out looking nothing like its input.&amp;nbsp; Sounds like encryption, except for two things:&lt;br /&gt;


&lt;ul&gt;
&lt;li&gt;You can&amp;#39;t convert a hash back to its original input (with encryption, you can).&lt;/li&gt;

&lt;li&gt;There&amp;#39;s a 1-to-1 correlation between the input and the hashed output.&amp;nbsp; So, if the password is &amp;quot;blue&amp;quot; and the hashed output is &amp;quot;920jf3no23nfoiwjfc9sjvasjd293r2,&amp;quot; then the hashed output will always be &amp;quot;920jf3no23nfoiwjfc9sjvasjd293r2&amp;quot; for &amp;quot;blue&amp;quot; with no exceptions.&lt;br /&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You don&amp;#39;t need a ridiculous amount of foresight to see how this could be an Achilles heel: all you need to crack the security is to prepare a list of inputs and outputs, and compare hashed passwords to this list.&amp;nbsp; This is why if you&amp;#39;re hashing passwords you also need &lt;i&gt;salt &lt;/i&gt;them: include random characters so that the output becomes different.&lt;br /&gt;&lt;br /&gt;For example, &amp;quot;blue,&amp;quot; &amp;quot;blue1,&amp;quot; and &amp;quot;blue11&amp;quot; will all lead to extremely different outputs.&amp;nbsp; Make your salt unique and keep it a secret and, the theory goes, your passwords will be safe.&amp;nbsp; Not a bad theory, but the real world has a way of throwing a wrench in the works.&lt;br /&gt;&lt;br /&gt;The problem is that different users often use the same password.&amp;nbsp; You&amp;#39;ve seen the lists of words that shouldn&amp;#39;t be employed as passwords because they&amp;#39;re so commonly used: &amp;quot;password,&amp;quot; &amp;quot;God,&amp;quot; &amp;quot;12345,&amp;quot; and &amp;quot;love&amp;quot;, among others.&amp;nbsp; Not only can you count on these popular passwords to show up on hashed password lists, if you total them up, they tend to be in the top 20.&lt;br /&gt;&lt;br /&gt;For example, let&amp;#39;s say that you&amp;#39;re trying to identify two hashed passwords, &lt;i&gt;&lt;b&gt;8nuv89ybt7rc32rp9824&lt;/b&gt;&lt;/i&gt; and &lt;i&gt;&lt;b&gt;AF23o9fasDSf0sjwfe&lt;/b&gt;&lt;/i&gt;.&amp;nbsp; You know one of them is &amp;quot;love&amp;quot; and the other is &amp;quot;theQu1ck8&amp;quot; but you don&amp;#39;t know which one is which.&amp;nbsp; But, &lt;i&gt;&lt;b&gt;8nuv89ybt7rc32rp9824&lt;/b&gt;&lt;/i&gt; shows up 500 times and &lt;i&gt;&lt;b&gt;AF23o9fasDSf0sjwfe&lt;/b&gt;&lt;/i&gt; shows up once.&amp;nbsp; Obviously the former corresponds to &amp;quot;love.&amp;quot;&lt;/p&gt;&lt;/blockquote&gt;&lt;h3&gt;Encryption: Nothing Compares&lt;/h3&gt;&lt;blockquote&gt;Unlike hashes, encryption uses unique &amp;quot;encryption keys&amp;quot; to convert data.&amp;nbsp; What are the odds of two encryption keys being identical? Lower than the odds of your body spontaneously combusting &lt;i&gt;right now&lt;/i&gt;.&amp;nbsp; The only way to &amp;quot;guess&amp;quot; an encryption key is brute force it; that is, go through every single one of them until you find it.&amp;nbsp; According to some calculations, the universe will be a cold, homogeneous mush devoid of entropy before that happens.&lt;br /&gt;&lt;br /&gt;That&amp;#39;s some pretty powerful stuff.&amp;nbsp; You don&amp;#39;t want to be caught without backing up individual encryption keys, then, or finding out that you can&amp;#39;t find the right one to unlock a device.&amp;nbsp; Encryption key management is one of the most harrowing aspects of ensuring good data security, (and is infinitely made easier via the use of AlertBoot).
&lt;/blockquote&gt;
&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://www.vudu.com/pressroom.html" target="_blank"&gt;http://www.vudu.com/pressroom.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.bbc.co.uk/news/technology-22092059" target="_blank"&gt;http://www.bbc.co.uk/news/technology-22092059&lt;/a&gt;&lt;br /&gt;&lt;a href="http://techcrunch.com/2013/04/09/vudu-headquarters-robbed-hard-drives-with-private-customer-data-stolen/" target="_blank"&gt;http://techcrunch.com/2013/04/09/vudu-headquarters-robbed-hard-drives-with-private-customer-data-stolen/&lt;/a&gt;&lt;br /&gt;

&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2584" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/device+encryption/default.aspx">device encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security/default.aspx">data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+drive+encryption/default.aspx">hard drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+theft+prevention/default.aspx">data theft prevention</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/information+security/default.aspx">information security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security/default.aspx">endpoint security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/prevent+data+leakage/default.aspx">prevent data leakage</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+safe/default.aspx">laptop safe</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software/default.aspx">encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/password+protection/default.aspx">password protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security+software/default.aspx">laptop security software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software+provider/default.aspx">encryption software provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+service+provider/default.aspx">encryption service provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/breach+notification/default.aspx">breach notification</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+information+encryption/default.aspx">personal information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+security/default.aspx">tablet security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+encryption/default.aspx">tablet encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+protection/default.aspx">tablet protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+protection/default.aspx">smartphone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+security/default.aspx">smartphone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+encryption/default.aspx">smartphone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/bring-your-own-device/default.aspx">bring-your-own-device</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization/default.aspx">consumerization</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization+of+IT/default.aspx">consumerization of IT</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/BYOD/default.aspx">BYOD</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/MDM/default.aspx">MDM</category></item><item><title>BYOD, US Borders, Laptops, and Smartphones: Fourth Amendment Rights Coming Back Home At US Borders</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/03/11/byod-us-borders-laptops-and-smartphones-fourth-amendment-rights-coming-back-home-at-us-borders.aspx</link><pubDate>Mon, 11 Mar 2013 12:26:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2574</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2574</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/03/11/byod-us-borders-laptops-and-smartphones-fourth-amendment-rights-coming-back-home-at-us-borders.aspx#comments</comments><description>&lt;blockquote&gt;We live in an era where BYOD – Bring Your Own Device – is transitioning from niche technical jargon to everyday reality, and people are beginning to use MDM and other &lt;a href="http://www.alertboot.com/" title="MDM as a service" target="_blank"&gt;mobile security solutions&lt;/a&gt; to counter the pitfalls of BYOD.&amp;nbsp; But there are places where mobile security is not welcome.&amp;nbsp; For example, the use of data security tools like &lt;a href="http://www.alertboot.com/disk_encryption/mobile_security_byod_mdm.aspx" title="smartphone and laptop encryption as a service" target="_blank"&gt;encryption software&lt;/a&gt; is enough to raise suspicion and delay you (or stop you) at the US border.&amp;nbsp; The implication is that you&amp;#39;re a suspicious individual because a password is necessary to access your device.&amp;nbsp; &lt;i&gt;What are you hiding there buddy, hm?&lt;/i&gt; appears to be the central question by the Department of Homeland Security.&lt;br /&gt;&lt;br /&gt;From now on, the answer could very well be &amp;quot;that&amp;#39;s none of your business... unless you have reasonable suspicion&amp;quot; thanks to a watershed decision by the 9th U.S. Circuit Court of Appeals in San Francisco, California.&amp;nbsp; This is the end of the &lt;a href="http://en.wikipedia.org/wiki/Border_search_exception" target="_blank"&gt;border search exception&lt;/a&gt; doctrine, that there are exceptions to the&amp;nbsp; Fourth Amendment at US borders, as we&amp;#39;ve known it for the last ten years.&amp;nbsp; From now on, US Customs and Border Protection (CBP) agents can&amp;#39;t dig too deep into your digital possessions without a reasonable cause.&lt;/blockquote&gt;
&lt;h3&gt;Kiddie Porn at the Center of the Case&lt;/h3&gt;
&lt;blockquote&gt;Last Friday, the 9th U.S. Circuit Court of Appeals ruled, according to &lt;i&gt;wired.com&lt;/i&gt;, &amp;quot;that U.S. border agents do not have carte blanche authority to search the cellphones, tablets and laptops of travelers entering the country.&amp;quot;&amp;nbsp; The key word there is &amp;quot;carte blanche.&amp;quot;&amp;nbsp; US border agents can still go through your laptop.&amp;nbsp; If they want to do more than do a cursory examination, however, they must have a tenable reason.&lt;br /&gt;&lt;br /&gt;The ruling was divided, although not controversially so: of the 11 judges, 3 dissented from the majority opinion (which is 82 pages long.&amp;nbsp; &lt;a href="http://cdn.ca9.uscourts.gov/datastore/opinions/2013/03/08/09-10139.pdf" target="_blank"&gt;Happy reading&lt;/a&gt;).&lt;br /&gt;&lt;br /&gt;The ruling was a result of an arrest at the US-Mexico border.&amp;nbsp; In a nutshell, a man by the name of Cotterman was singled out for inspection based on a &amp;quot;fifteen-year-old conviction for child molestation.&amp;quot;&amp;nbsp; Although there was nothing incriminating on his, and his family&amp;#39;s, two laptop computers and three digital cameras (and presumably their non-digital belongings), CBP sent the laptop to a forensic examination facility.&amp;nbsp; Deleted child pornography in a variety of media was discovered, including 23 password-protected files that were cracked open to reveal images of Cotterman molesting a girl.&amp;nbsp; The court ruled that this in-depth digital examination requires probable cause, and that it was met in Cotterman (the dissenting opinion, in my opinion, makes a pretty strong case that probable cause was not met).&lt;/blockquote&gt;
&lt;h3&gt;Password-Protection and Encryption is NOT Grounds for Suspicion&lt;/h3&gt;
&lt;blockquote&gt;In the summary to &lt;i&gt;US v. Cotterman&lt;/i&gt;, the court noted the following (my emphasis):&lt;br /&gt;&lt;blockquote&gt;The en banc court wrote that &lt;b&gt;password protection of files, which is ubiquitous among many law-abiding citizens, will not in isolation give rise to reasonable suspicion&lt;/b&gt;, but that password protection may be considered in the totality of the circumstances where, as here, there are other indicia of criminal activity. The en banc court wrote that the existence of password-protected files is also relevant to assessing the reasonableness of the scope and duration of the search of the defendant&amp;#39;s computer.&lt;br /&gt;&lt;/blockquote&gt;Within the body itself, it was commented on the presence of password-protection as a suspicious factor:&lt;br /&gt;&lt;blockquote&gt;the government adds another [reasonable suspicion] – the existence of password-protected files on Cotterman&amp;#39;s computer. We are reluctant to place much weight on this factor because it is commonplace for business travelers, casual computer users, students and others to password protect their files. Law enforcement &amp;quot;cannot rely solely on factors that would apply to many law-abiding citizens,&amp;quot; &lt;i&gt;Berber-Tinoco&lt;/i&gt;, 510 F.3d at 1087, and password protection is ubiquitous. National standards require that users of mobile electronic devices password protect their files.... Computer users are routinely advised – and in some cases, required by employers – to protect their files when traveling overseas.&lt;br /&gt;&lt;/blockquote&gt;The majority opinion goes on to note that password protection alone, in isolation, &amp;quot;will not give rise to reasonable suspicion&amp;quot; and that &amp;quot;to contribute to reasonable suspicion, encryption or password protection of files must have some relationship to the suspected criminal activity.&amp;quot;&lt;br /&gt;&lt;br /&gt;The court also made a comment on &lt;a href="http://www.alertboot.com/disk_encryption/full_disk_encryption.aspx" title="DAR encryption laptops" target="_blank"&gt;full disk encryption&lt;/a&gt;:&lt;br /&gt;&lt;blockquote&gt;We do not suggest that password protecting an entire device – as opposed to files within a device – can be a factor supporting a reasonable suspicion determination. Using a password on a device is a basic means of ensuring that the device cannot be accessed by another in the event it is lost or stolen.&lt;br /&gt;&lt;/blockquote&gt;Well, technically, it appears to be a comment on password-protection, but let&amp;#39;s face it, if you&amp;#39;re looking for a means that ensures that a device remains inaccessible when lost or stolen, &lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2009/06/17/data-encryption-and-password-protection-why-the-latter-fails.aspx" title="password protection and encryption difference" target="_blank"&gt;it&amp;#39;s encryption that you want, not password protection&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;And, last but not least, the use of passwords has been described as a &amp;quot;basic privacy right,&amp;quot; although I&amp;#39;ve got to wonder whether I&amp;#39;m quoting out of context.&amp;nbsp; In the dissenting opinion (my emphasis):&lt;br /&gt;&lt;blockquote&gt;Perhaps the most concerning aspect of the majority&amp;#39;s opinion, especially given its stated stance on privacy rights at the border, is its readiness to strip former sex offenders and others convicted of past crimes (and who are, theoretically, entitled to be presumption of innocence) of even &lt;b&gt;the most basic of privacy rights, such as the right to password-protect their electronic devices&lt;/b&gt;....&amp;nbsp; Indeed, as the majority acknowledges, making legal files difficult to access makes &amp;quot;perfect sense&amp;quot; for anyone.&lt;br /&gt;&lt;/blockquote&gt;Who&amp;#39;d have thunk it?&amp;nbsp; Encryption is a type of basic right.&lt;br /&gt;&lt;br /&gt;The case is interesting in many ways.&amp;nbsp; You can find thoughtful, intelligent coverage at &lt;i&gt;arstechnica.com&lt;/i&gt;, &lt;i&gt;wired.com&lt;/i&gt;, and &lt;i&gt;techdirt.com&lt;/i&gt;, among other online media.&lt;/blockquote&gt;
&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://cdn.ca9.uscourts.gov/datastore/opinions/2013/03/08/09-10139.pdf" target="_blank"&gt;http://cdn.ca9.uscourts.gov/datastore/opinions/2013/03/08/09-10139.pdf&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.wired.com/threatlevel/2013/03/gadget-border-searches/" target="_blank"&gt;http://www.wired.com/threatlevel/2013/03/gadget-border-searches/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://arstechnica.com/tech-policy/2013/03/appeals-court-raises-standard-for-laptop-searches-at-us-border/" target="_blank"&gt;http://arstechnica.com/tech-policy/2013/03/appeals-court-raises-standard-for-laptop-searches-at-us-border/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.techdirt.com/articles/20130308/13380622263/9th-circuit-appeals-court-4th-amendment-applies-border-also-password-protected-files-shouldnt-arouse-suspicion.shtml" target="_blank"&gt;http://www.techdirt.com/articles/20130308/13380622263/9th-circuit-appeals-court-4th-amendment-applies-border-also-password-protected-files-shouldnt-arouse-suspicion.shtml&lt;/a&gt;&lt;br /&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2574" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption/default.aspx">laptop encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security/default.aspx">data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+drive+encryption/default.aspx">hard drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security/default.aspx">laptop security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+at+rest+encryption/default.aspx">data at rest encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/disk+encryption/default.aspx">disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+solution/default.aspx">laptop encryption solution</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security+software/default.aspx">laptop security software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+data+security/default.aspx">laptop data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hdd+encryption+software/default.aspx">hdd encryption software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+law/default.aspx">encryption law</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+software+provider/default.aspx">encryption software provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+provider/default.aspx">laptop encryption provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security+provider/default.aspx">data security provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+service+provider/default.aspx">encryption service provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/media+encryption+and+protection/default.aspx">media encryption and protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+information+encryption/default.aspx">personal information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/best+encryption/default.aspx">best encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+in+motion+encryption/default.aspx">data in motion encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+encryption/default.aspx">Android encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+encryption/default.aspx">iPhone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+security/default.aspx">Android security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/Android+protection/default.aspx">Android protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+security/default.aspx">tablet security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+encryption/default.aspx">tablet encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+security/default.aspx">iPhone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+protection/default.aspx">iPhone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+protection/default.aspx">tablet protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+protection/default.aspx">smartphone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+security/default.aspx">smartphone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+encryption/default.aspx">smartphone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/bring-your-own-device/default.aspx">bring-your-own-device</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization/default.aspx">consumerization</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/consumerization+of+IT/default.aspx">consumerization of IT</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/BYOD/default.aspx">BYOD</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+security/default.aspx">iPad security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+encryption/default.aspx">iPad encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+protection/default.aspx">iPad protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/MDM/default.aspx">MDM</category></item><item><title>Deleting Solid State Drives: Cleaning SSDs Almost Impossible, So Use Encryption</title><link>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/02/19/deleting-solid-state-drives-cleaning-ssds-almost-impossible-so-use-encryption.aspx</link><pubDate>Tue, 19 Feb 2013 11:16:00 GMT</pubDate><guid isPermaLink="false">485e638a-55cc-4ff1-8cd4-ec0169d28c96:2569</guid><dc:creator>sang_lee</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://www.alertboot.com/blog/blogs/endpoint_security/rsscomments.aspx?PostID=2569</wfw:commentRss><comments>http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/02/19/deleting-solid-state-drives-cleaning-ssds-almost-impossible-so-use-encryption.aspx#comments</comments><description>&lt;blockquote&gt;According to the National Association of Information Destruction (NAID), solid state drives (SSD) used in ultrabooks, tablets, smartphones, and other devices are proving to be a headache when it comes to end-of-life operations.&amp;nbsp; Namely, the usual methods of deleting digital data – so that hardware may be discarded safely – are proving to be ineffective when it comes to flash-based storage media.&amp;nbsp; This shouldn&amp;#39;t be news, however, at least not to NAID.&lt;br /&gt;&lt;br /&gt;The solution to the above difficulty is at least 2 years old: place &lt;a href="http://www.alertboot.com/" title="managed full disk encryption" target="_blank"&gt;laptop disk encryption&lt;/a&gt; at the heart of your data destruction strategy.&lt;/blockquote&gt;&lt;h3&gt;SSDs an Unknown Quantity&lt;/h3&gt;&lt;blockquote&gt;According to a NAID conference that was held in Sydney, Australia, NAID chief Bob Johnson noted that:&lt;br /&gt;&lt;blockquote&gt;SSDs are an unknown quantity when it comes to being sterilised for disposal at the end of their working lives.&lt;br /&gt;&lt;br /&gt;&amp;quot;There is currently work being done at the University of California, San Diego, about the best ways to make sure these solid state drives are clean before they&amp;#39;re disposed of,&amp;quot; he said. &amp;quot;Unfortunately the information out there at the moment is very squirrelly.&amp;quot;&lt;br /&gt;&lt;/blockquote&gt;I&amp;#39;m not sure what information Johnson&amp;#39;s referring to, but I&amp;#39;ve known for at least two years that the best way to ensure that information is properly wiped is to encrypt it and lose the encryption key:&lt;br /&gt;&lt;blockquote&gt;The researchers propose an approach called SAFE (Scramble and Finally Erase) that sanitizes the stored key:&lt;br /&gt;&lt;br /&gt;The technique, called Scramble and Finally Erase (SAFE), stores encrypted data in the drive and uses a two step process for sanitization. First, it destroys the key. Then, SAFE erases every physical page in the SSD. After this step, veriﬁcation is a simple matter of dismantling the drive and verifying that the flash chips are actually erased.&lt;br /&gt;&lt;br /&gt;Encryption is at the heart of this technique, you&amp;#39;ll notice, with attention given to the key&amp;#39;s destruction.&lt;br /&gt;&lt;/blockquote&gt;The above is from a post I wrote in 2011 on why &lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2011/02/17/media-sanitization-for-ssds-need-extra-care-perhaps-encryption-will-serve-for-now.aspx" title="the deletion of SSDs and flash drives" target="_blank"&gt;media sanitation requires encryption&lt;/a&gt;, and is based on research done by a team at the University of California, San Diego.&lt;br /&gt;&lt;br /&gt;If that looks like &lt;i&gt;déjà vu &lt;/i&gt;to you, it&amp;#39;s because it&amp;#39;s the same San Diego team that Johnson is referring to.&lt;/blockquote&gt;&lt;h3&gt;Encryption Sometimes CANNOT be the Solution for SSD&lt;/h3&gt;&lt;blockquote&gt;And now that I&amp;#39;ve revealed how &lt;a href="http://www.alertboot.com/disk_encryption/central_encryption_software_management.aspx" title="managed laptop disk encryption service as a software" target="_blank"&gt;encryption software&lt;/a&gt; is the only way to secure devices during their EOL, here&amp;#39;s a kick to the head: under certain circumstances, encryption is not an option from a policy perspective.&amp;nbsp; For example, under HIPAA.&lt;br /&gt;&lt;br /&gt;HIPAA is a set of rules, overseen by the Department of Health and Human Services (HHS), that governs healthcare companies and their business associates.&amp;nbsp; While the use of encryption is strongly encouraged to protect patient data (indeed, the director for the Office for Civil Rights at the HHS was quoted as saying &amp;quot;&lt;a href="http://www.alertboot.com/blog/blogs/endpoint_security/archive/2013/01/29/disk-encryption-and-hipaa-hitech-final-rule-a-match-made-in-heaven.aspx" title="HIPAA HITECH HHS and encryption" target="_blank"&gt;we love encryption&lt;/a&gt;, and those who use encryption love it, too&amp;quot;), there is one area where encryption is not to be used as a tool when it comes to medical data: &lt;i&gt;&lt;b&gt;when a device is being disposed of&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;When a computer, external drive, flashdrive, or other data storage device that used to store health data is to be discarded – be it in a landfill or via a donation – the information on it has to be scrubbed.&amp;nbsp; The usual methods include overwriting every sector of the storage device; degaussing it by placing the medium in a magnetic field; or physical destroying it, all of them procedures approved by NIST.&amp;nbsp; Encryption, on the other hand, is not considered to be a reliable method of destroying data because it is designed to &amp;quot;recover&amp;quot; data when the correct key is applied.&lt;br /&gt;&lt;br /&gt;This is problematic as organizations start to embrace BYOD, bring your own device.&amp;nbsp; One wonders how the HHS will react as more and more devices that use SSDs – like smartphones and tablets – make their way into hospitals and other businesses that handle protected health information.&amp;nbsp; Degaussing will not work, since SSDs don&amp;#39;t store data in a magnetic medium.&amp;nbsp; Overwriting does not work due to SSDs&amp;#39; internal workings.&amp;nbsp; Destroying devices would work but is wasteful when they might still be useful to some.&lt;br /&gt;&lt;br /&gt;Plus, I&amp;#39;ve got to assume that the owners of these devices would be quite against destroying their phones and tablets.&lt;br /&gt;&lt;br /&gt;It seems that an exception will have to be made for flash-based devices, or that the use of encryption to &amp;quot;destroy&amp;quot; data will be accepted as a norm.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Related Articles and Sites:&lt;br /&gt;&lt;a href="http://www.itnews.com.au/News/333677,solid-state-drives-pose-data-security-risk.aspx" target="_blank"&gt;http://www.itnews.com.au/News/333677,solid-state-drives-pose-data-security-risk.aspx&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;img src="http://www.alertboot.com/blog/aggbug.aspx?PostID=2569" width="1" height="1"&gt;</description><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/full+disk+encryption/default.aspx">full disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/HIPAA/default.aspx">HIPAA</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption/default.aspx">laptop encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security/default.aspx">data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+drive+encryption/default.aspx">hard drive encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/information+security/default.aspx">information security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/whole+disk+encryption/default.aspx">whole disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/secure+digital+assets/default.aspx">secure digital assets</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security/default.aspx">laptop security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/prevent+data+leakage/default.aspx">prevent data leakage</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+safe/default.aspx">laptop safe</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/identity+theft/default.aspx">identity theft</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hard+disk+encryption/default.aspx">hard disk encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+solution/default.aspx">laptop encryption solution</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/endpoint+security+breach/default.aspx">endpoint security breach</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+security+software/default.aspx">laptop security software</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+data+security/default.aspx">laptop data security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+hdd+encryption/default.aspx">laptop hdd encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/securing+corporate+laptops/default.aspx">securing corporate laptops</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/laptop+encryption+provider/default.aspx">laptop encryption provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/data+security+provider/default.aspx">data security provider</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/encryption+standard/default.aspx">encryption standard</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/personal+information+encryption/default.aspx">personal information encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/medical+data+encryption/default.aspx">medical data encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/hospital+encryption/default.aspx">hospital encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+encryption/default.aspx">iPhone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+security/default.aspx">tablet security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+encryption/default.aspx">tablet encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+security/default.aspx">iPhone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPhone+protection/default.aspx">iPhone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/tablet+protection/default.aspx">tablet protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+protection/default.aspx">smartphone protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+security/default.aspx">smartphone security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/smartphone+encryption/default.aspx">smartphone encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+security/default.aspx">iPad security</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+encryption/default.aspx">iPad encryption</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/iPad+protection/default.aspx">iPad protection</category><category domain="http://www.alertboot.com/blog/blogs/endpoint_security/archive/tags/MDM/default.aspx">MDM</category></item></channel></rss>