Now that weve passed the midpoint in 2020, one thing in the cybersecurity world has become crystal clear: The need for better security within public clouds must be addressed by enterprises once and for all, and that entails cryptography.
No question, enterprises large and small have realized the benefits of rapidly deployable, reasonably priced and extremely scalable public computing infrastructure. According to Forbes, the global cloud computing market will reach $411 billion this year.
But what about the security? Is it up to snuff?
Not really, even though some public cloud purveyors offer some encryption as an option and sometimes by default. This step is hardly foolproof, however, and that should come as no surprise. After all, data in the cloud is stored with a third-party provider and accessed over the internet. This means visibility and control over that dataincluding its securityis limited.
Fact is, cloud service providers treat cloud security risks as a shared responsibility. The good news is that some cloud companies allow clients to encrypt their data before sending it to the cloud, and its becoming increasingly clear that thisor possibly the additional option of adopting a few other proven, state-of-the-art fixes for cloud securityis the preferred route for truly security-conscious enterprises.
That enhanced data encryption in the cloud makes sense began circulating roughly two-and-a-half years ago, when technology and cloud giant Accenture confirmed that it inadvertently left a gigantic store of private data access across four unsecured cloud servers. This exposed highly sensitive passwords and secret decryption keys that could have inflicted considerable damage on the company and its customers.
Since then, misconfigured cloud settings have caused multiple incidents of data exposures in the Amazon Web Services cloud. In addition, a misconfiguration error in Microsofts Azure cloud exposed 250 million technical support accounts. Meanwhile, MVISION Cloud, a unit of McAfee, analyzed the encryption controls offered by more than 12,000 providers and found yet more shortcomings. While 82percent of cloud service providers encrypt data in transit between the user and the cloud service, not even 10percent of cloud providers encrypt data once its stored, MVISION found.
According to CloudPassage, a software-as-a-service purveyor that provides security for private, public and hybrid clouds, one of the worst mistakes made by public cloud companies is having easily hacked administrative credentialsessentially the keys to the kingdom. As it turns out, attackers can execute a breach with a badly configured set of privileged credentialsa common occurrence, unfortunately, when a cloud company cuts corners in a rush to market.
Other mistakes among public crowd companies include exposed data assets, weak network access control and poor event logging, which impedes efforts to detect, contain and analyze compromises in the cloud.
On the bright side, there are companies today that help enterprises adopt cloud encryption. Oneborn out of research done at MITis cybersecurity company PreVeil, whose end-to-end encryption could redefine cloud-based cybersecurity in a way that doesnt interfere with workflows while still enabling popular cloud-based machine-learning applications.
Another company with a different approach to the same end goal is Zscaler, which offers a Secure Web Gateway in the cloud via software-as-a service. No hardware is required. Zscaler decentralizes cybersecurity protection, allowing data to flow back and forth from a public cloud rather than redirecting it to clients own physical data centers.
Another form of cryptography enhances the breadth of the science by offering fresh analytical capabilities as well as securityhomomorphic encryption (HE). HE is attracting more attention from select technology companies such as IBM, Microsoft and Google, and startups such as Enveil, and slowly growing. HE makes it possible to analyze or manipulate encrypted data without revealing the data to anyone, offering huge potential in areas with sensitive personal data such as in financial services or healthcareareas in which the privacy of a person is paramount.
The biggest barrier to widespread adoption of HE is that it is still very slow and so not yet practical for many applications. Nonetheless, company researchers are working diligently to speed up the process by decreasing the required computational overhead.
Microsoft, for example, has created SEAL, a set of encryption libraries that allow computations to be performed directly on encrypted data. SEAL is partnering with companies to build end-to-end encrypted data storage and computation services. Googleanother tech giant that has moved into the fieldlast year unveiled an open-source cryptographic tool similarly focused on analyzing data in its encrypted form with only the insights derived from the analysis visible, not the underlying data itself.
An even more futuristic development that cryptography-minded folks should be aware ofalthough in this case, in a blatantly negative senseis quantum computing, based on the principles of quantum physics.
At least a decade away, ultra-fast quantum computers could perform calculations exponentially faster than classic computersin the wrong hands potentially enabling the destruction of the encryption protecting their data. Fortunately, there is also some good news on this front. The National Institute of Standards and Technology is already pushing researchers to analyze potential problems in this post-quantum era. Meanwhile, IBM has already successfully demonstrated a quantum-proof encryption method it developed.
For now, here are six security tips for companies moving to public or even multi-cloud environments and concerned about cryptography and related security disciplines.
+ Get the basics right.Establish a strategy for multi-cloud encryption and the management of cryptography keys before expanding to more advanced crypto technologies.
+ Leverage encryption as part of your broader IT security efforts.Companies that dont have effective data classification and/or a prioritization program in place tend to struggle with data encryption. Data classification policies and tools facilitate the separation of valuable information that may be targeted from less valuable information.
+ Build in crypto agility.This refers to the capacity for an information security system to adopt an alternative to the original encryption method without significant change to system infrastructure. Be ready to replace or retire your deployed cryptography as needed.
+ Ensure that only authorized users can access data.This is critical to prevent tampering by anyone inside or outside the organization. Audit access controls regularly to ensure their validity.
+ Develop robust plans for business continuity and disaster recovery of crypto keys.Inventory keys and cryptographic libraries so you can recover your data alongside your protection mechanisms.
+ Make sure your cryptography is integrated intothe DevSecOps world.Ensure that DevOps teams choose crypto libraries that follow secure coding practices.
In the final analysis, encryption is tough stuff, but extremely important in the world of security. Companies that embrace it and incorporate it properly are taking an additional big step to protect their data and their reputation in a world inundated by embarrassing, hurtful and costly cyber-breaches.
Now that cloud computing has introduced encryption widely, security-minded companies are under growing pressure to keep the ball rolling and help move on to next steps.
Read the original here:
- The Quantum Computer Revolution Is Closer Than You May Think - National Review [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Time Crystals Could be the Key to the First Quantum Computer - TrendinTech [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- quantum computing - WIRED UK [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Chinese scientists build world's first quantum computing machine - India Today [Last Updated On: May 3rd, 2017] [Originally Added On: May 3rd, 2017]
- Here's How We Can Achieve Mass-Produced Quantum Computers - ScienceAlert [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- D-Wave partners with U of T to move quantum computing along - Financial Post [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Team develops first blockchain that can't be hacked by quantum computer - Siliconrepublic.com [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Telstra just wants a quantum computer to offer as-a-service - ZDNet [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Research collaborative pursues advanced quantum computing - Phys.Org [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Quantum Computing Market Forecast 2017-2022 | Market ... [Last Updated On: June 6th, 2017] [Originally Added On: June 6th, 2017]
- Quantum Computing Is Real, and D-Wave Just Open ... - WIRED [Last Updated On: June 7th, 2017] [Originally Added On: June 7th, 2017]
- FinDEVr London: Preparing for the Dark Side of Quantum Computing - GlobeNewswire (press release) [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Purdue, Microsoft to Collaborate on Quantum Computer - Photonics.com [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Scientists May Have Found a Way to Combat Quantum Computer Blockchain Hacking - Futurism [Last Updated On: June 9th, 2017] [Originally Added On: June 9th, 2017]
- Microsoft and Purdue work on scalable topological quantum computer - Next Big Future [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- HYPRES Expands Efforts in Quantum Computing with Launch of European Subsidiary SeeQC - Business Wire (press release) [Last Updated On: June 12th, 2017] [Originally Added On: June 12th, 2017]
- From the Abacus to Supercomputers to Quantum Computers - Duke Today [Last Updated On: June 13th, 2017] [Originally Added On: June 13th, 2017]
- Accenture, Biogen, 1QBit Launch Quantum Computing App to ... - HIT Consultant [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- The US and China "Quantum Computing Arms Race" Will Change Long-Held Dynamics in Commerce, Intelligence ... - PR Newswire (press release) [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- Quantum Computing Technologies markets will reach $10.7 billion by 2024 - PR Newswire (press release) [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- A Hybrid of Quantum Computing and Machine Learning Is Spawning New Ventures - IEEE Spectrum [Last Updated On: June 14th, 2017] [Originally Added On: June 14th, 2017]
- KPN CISO details Quantum computing attack dangers - Mobile World Live [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Get ahead in quantum computing AND attract Goldman Sachs - eFinancialCareers [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Accenture, 1QBit partner for drug discovery through quantum ... - ZDNet [Last Updated On: June 16th, 2017] [Originally Added On: June 16th, 2017]
- Toward optical quantum computing - MIT News [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Quantum computing, the machines of tomorrow | The Japan Times - The Japan Times [Last Updated On: June 17th, 2017] [Originally Added On: June 17th, 2017]
- Its time to decide how quantum computing will help your ... [Last Updated On: June 18th, 2017] [Originally Added On: June 18th, 2017]
- Israel Enters Quantum Computer Race, Placing Encryption at Ever-Greater Risk - Sputnik International [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Prototype device enables photon-photon interactions at room ... - Phys.Org [Last Updated On: June 20th, 2017] [Originally Added On: June 20th, 2017]
- Dow and 1QBit Announce Collaboration Agreement on Quantum Computing - Business Wire (press release) [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Imperfect crystals may be perfect storage method for quantum computing - Digital Trends [Last Updated On: June 21st, 2017] [Originally Added On: June 21st, 2017]
- Dow Chemical, 1QBit Ink Quantum Computing Development Deal - Zacks.com [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- Google on track for quantum computer breakthrough by end of 2017 - New Scientist [Last Updated On: June 22nd, 2017] [Originally Added On: June 22nd, 2017]
- USC to lead project to build super-speedy quantum computers - USC News [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- The Quantum Computer Factory That's Taking on Google and IBM ... - WIRED [Last Updated On: June 24th, 2017] [Originally Added On: June 24th, 2017]
- The weird science of quantum computing, communications and encryption - C4ISR & Networks [Last Updated On: June 27th, 2017] [Originally Added On: June 27th, 2017]
- Multi-coloured photons in 100 dimensions may make quantum ... - Cosmos [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Global Quantum Computing Market Growth at a CAGR of 35.12 ... - PR Newswire (press release) [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Qudits: The Real Future of Quantum Computing? - IEEE Spectrum - IEEE Spectrum [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- New method could enable more stable and scalable quantum ... - Phys.Org [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Quantum computers are about to get real | Science News - Science News Magazine [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Quantum Computing - Scientific American [Last Updated On: June 30th, 2017] [Originally Added On: June 30th, 2017]
- Australia's ambitious plan to win the quantum race - ZDNet [Last Updated On: July 3rd, 2017] [Originally Added On: July 3rd, 2017]
- How quantum mechanics can change computing - The Conversation - The Conversation US [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- UNSW joins with government and business to keep quantum computing technology in Australia - The Australian Financial Review [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- UNSW launches Australia's first hardware quantum computing company with investments from federal and NSW ... - OpenGov Asia [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- Finns chill out quantum computers with qubit refrigerator to cut out errors - ZDNet [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- Hype and cash are muddying public understanding of quantum ... - The Conversation AU [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- IEEE Approves Standards Project for Quantum Computing ... - insideHPC [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- Silicon Quantum Computing launched to commercialise UNSW ... - ZDNet [Last Updated On: August 24th, 2017] [Originally Added On: August 24th, 2017]
- The Era of Quantum Computing Is Here. Outlook: Cloudy ... [Last Updated On: January 30th, 2018] [Originally Added On: January 30th, 2018]
- The Era of Quantum Computing Is Here. Outlook: Cloudy | WIRED [Last Updated On: February 6th, 2018] [Originally Added On: February 6th, 2018]
- Quantum computing in the NISQ era and beyond [Last Updated On: February 6th, 2018] [Originally Added On: February 6th, 2018]
- What is quantum computing? - Definition from WhatIs.com [Last Updated On: February 6th, 2018] [Originally Added On: February 6th, 2018]
- Quantum computers - WIRED UK [Last Updated On: February 19th, 2018] [Originally Added On: February 19th, 2018]
- Is Quantum Computing an Existential Threat to Blockchain ... [Last Updated On: February 21st, 2018] [Originally Added On: February 21st, 2018]
- What is Quantum Computing? Webopedia Definition [Last Updated On: March 25th, 2018] [Originally Added On: March 25th, 2018]
- Quantum Computing Explained - WIRED UK [Last Updated On: April 15th, 2018] [Originally Added On: April 15th, 2018]
- Quantum computing: A simple introduction - Explain that Stuff [Last Updated On: June 2nd, 2018] [Originally Added On: June 2nd, 2018]
- What are quantum computers and how do they work? WIRED ... [Last Updated On: June 22nd, 2018] [Originally Added On: June 22nd, 2018]
- How Quantum Computers Work [Last Updated On: July 22nd, 2018] [Originally Added On: July 22nd, 2018]
- The reality of quantum computing could be just three years ... [Last Updated On: September 12th, 2018] [Originally Added On: September 12th, 2018]
- The 3 Types of Quantum Computers and Their Applications [Last Updated On: November 24th, 2018] [Originally Added On: November 24th, 2018]
- Quantum Computing - VLAB [Last Updated On: January 27th, 2019] [Originally Added On: January 27th, 2019]
- Quantum Computing | Centre for Quantum Computation and ... [Last Updated On: January 27th, 2019] [Originally Added On: January 27th, 2019]
- Microsofts quantum computing network takes a giant leap ... [Last Updated On: March 7th, 2019] [Originally Added On: March 7th, 2019]
- IBM hits quantum computing milestone, may see 'Quantum ... [Last Updated On: March 7th, 2019] [Originally Added On: March 7th, 2019]
- Quantum technology - Wikipedia [Last Updated On: March 13th, 2019] [Originally Added On: March 13th, 2019]
- Quantum Computing | D-Wave Systems [Last Updated On: April 18th, 2019] [Originally Added On: April 18th, 2019]
- Microsoft will open-source parts of Q#, the programming ... [Last Updated On: May 7th, 2019] [Originally Added On: May 7th, 2019]
- What Is Quantum Computing? The Complete WIRED Guide | WIRED [Last Updated On: May 8th, 2019] [Originally Added On: May 8th, 2019]
- The five pillars of Edge Computing -- and what is Edge computing anyway? - Information Age [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Moore's Law Is Dying. This Brain-Inspired Analogue Chip Is a Glimpse of What's Next - Singularity Hub [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Experts Gather at Fermilab for International Workshop on Cryogenic Electronics for Quantum Systems - Quantaneo, the Quantum Computing Source [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Princeton announces initiative to propel innovations in quantum science and technology - Princeton University [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Detecting Environmental 'Noise' That Can Damage The Quantum State of Qubits - In Compliance [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Quantum Computing beginning talks with clients on its quantum asset allocation application - Proactive Investors USA & Canada [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- What is quantum computing? The next era of computational evolution, explained - Digital Trends [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- IT sees the Emergence of Quantum Computing as a Looming Threat to Keeping Valuable Information Confidential - Quantaneo, the Quantum Computing Source [Last Updated On: October 23rd, 2019] [Originally Added On: October 23rd, 2019]
- More wrong answers get quantum computers to find the right one - Futurity: Research News [Last Updated On: October 23rd, 2019] [Originally Added On: October 23rd, 2019]