Data Storage: Who’s Got the Encryption Key?

Encryption is a very basic security measure. But there are some serious issues swirling around encryption, especially if you have handed off your data to a cloud provider.

Encrypting data in-transit is standard and many service providers (SP) will give you the option of encrypting data at-rest. Dont take at-rest encryption for granted because there is another step you must take. Ask yourself: when I direct my SP to encrypt my stored data, who decrypts? Who holds the keys to the kingdom?

It may be your cloud provider who holds your encryption key. Most of them will do their best to protect your data and keys. But its an uncertain world out there. Online thieves can steal the key, NSA can subpoena it, determined hackers can break it, and failing cloud businesses can take it down with them.

Lets take a closer look at these very real threats to encrypted online data storage.

Hackers. A well-organized hacking group attacked an ecommerce website, stealing customer information including credit card numbers. The website owner admitted the data loss but thought that customer data was safe because it was encrypted. Sadly for the company, it had stored encryption keys on the same server that held customer data. The sophisticated hackers stole the keys right along with the information and promptly decrypted and posted the data.

Government. The NSA regularly taps large service providers for customer data and if you store your data with them you are vulnerable. Even if your data is encrypted, if the SP has the key they can decrypt your data. And if they are threatened by a subpoena, they probably will.

You may decide to turn your data over to the NSA if they subpoena you, but the point is that this should be your choice. Not the NSAs and certainly not your service providers. Or what about the scenario where the NSA does subpoena you, you decide to decrypt and turn over your data to them and you dont have the encryption key. Imagine NSAs sense of humor at that response.

Internal intrusion. Never assume that your data is kept private from the service provider employees. Most of them are honest to a fault -- but not all of them are and your data is at risk if they control your encryption keys. And while youre at it, check to see that your provider carefully screens their employees and tracks their activities while at work. A tad big-brother-ish perhaps, but remember Edward Snowden? No matter what your opinion is on his activities, you probably do not want a Snowden of your very own.

Going Out of Business. Many online backup service providers operate on razor-thin profit margins and are close to failing or are actively looking to be acquired. If they have your encryption key you may or may not be able to get your data back when you need it. If they are the ones who own your encryption key, they may take your key and your encrypted data down with their ship.

Service providers are well aware of these issues around encryption keys. One common solution is storing their customers encryption keys separately from data, in a different physical server system or a different partition. This does work against outside intrusion but does not help much against internal employee mistakes or malice.

Original post:
Data Storage: Who's Got the Encryption Key?

Yahoo Bringing Better Encryption Technologies To The Table

April 3, 2014

Enid Burns for redOrbit.com Your Universe Online

Yahoo! is in the midst of a large-scale project to employ encryption technologies to protect its users and their data. The companys new Chief Information Security Officer, Alex Stamos, updated users on Tumblr.

Firstly, as of march 31 all traffic moving between Yahoo! data centers is fully encrypted. Yahoo! Mail has become more secure as browsing has been moved to HTTPS by default, as well as encryption of mail between Yahoo! servers and other mail providers that support the SMTPTLS standard. Browsing on Yahoo! also has HTTPS encryption enabled by default.

Yahoo! has also implemented a number of additional encryption and security measures.

We implemented the latest in security best-practices, including supporting TLS 1.2, Perfect Forward Secrecy and a 2048-bit RSA key for many of our global properties such as Homepage, Mail and Digital Magazines. We are currently working to bring all Yahoo sites up to this standard, wrote Stamos.

While Yahoo! still has measures to take in-house, it is working with vendors and companies it contracts to improve security at those points as well.

One of our biggest areas of focus in the coming months is to work with and encourage thousands of our partners across all of Yahoos hundreds of global properties to make sure that any data that is running on our network is secure. Our broader mission is to not only make Yahoo secure, but improve the security of the overall web ecosystem, Stamos wrote.

Once all measures are complete, Yahoo! will continue to work on security to keep up with encryption developments and stay ahead of hackers.

In addition to moving all of our properties to encryption by default, we will be implementing additional security measures such as HSTS, Perfect Forward Secrecy and Certificate Transparency over the coming months. This isnt a project where well ever check a box and be finished. Our fight to protect our users and their data is an on-going and critical effort. We will continue to work hard to deploy the best possible technology to combat attacks and surveillance that violate our users privacy, Stamos wrote.

See more here:
Yahoo Bringing Better Encryption Technologies To The Table

Yahoo turns on encryption between data centers

Yahoo said Wednesday it was encrypting traffic flowing between its data centers, several months after leaked documents revealed the government had been sniffing those links.

Traffic moving between Yahoo data centers is fully encrypted as of March 31, the company announced on its Tumblr blog. Last October, documents provided by former U.S. National Security Agency contractor Edward Snowden said the NSA had penetrated the main communications links that connect Yahoo and Googles data centers.

Though it comes after those revelations, the encrypted data links is in keeping with a previous promise by CEO Marissa Mayer to encrypt all information between its data centers by the end of March.

Yahoo said Wednesday that it had also turned on encryption for a range of other services. For one, encryption of mail between its servers and other mail providers that support the SMTPLS standard was enabled in the last month, the company said. Yahoo only just turned on encryption by default between users and its email service in January.

Yahoo said its homepage and all search queries that run on it and most other Yahoo properties now also have HTTPS encryption enabled by default.

But if users want an encrypted session for Yahoo News, Yahoo Sports, Yahoo Finance or Good Morning America on Yahoo, they must manually type https into the sites URL on their browsers, Yahoo said.

Yahoo has faced pressure to encrypt more of its services for years. In 2012, the Electronic Frontier Foundation and other privacy activists called on CEO Marissa Mayer to enable HTTPS encryption for the companys communications services. Yahoo began offering HTTPS encryption for mail in 2012, but on an opt-in basis.

Since then other companies like Google and Facebook have introduced more forms of encryption.

Last month, another leak of documents said that GCHQ, Britains surveillance agency, had captured webcam images from more than 1.8 million users of Yahoos Messenger product.

Yahoo said Wednesday that a new, encrypted version of Messenger would be rolled out in the coming months.

Read more:
Yahoo turns on encryption between data centers

Yahoo Faces Balancing Act Between Ads, Encryption

Yahoo is facing a challenge as it seeks to encrypt its vast network of websites and services to block hackers and government spooks: data security can clash with its business model.

The same is true for all Internet companies, but particularly so for Yahoo, the original search giant that has disappointed investors with weak revenue in recent quarters.

Yahoo on Wednesday announced new progress in previously announced efforts to beef up encryption, partly as a response to last years Edward Snowden leaks. The company now encrypts all traffic between its data centers and turned on encryption by default for the Yahoo homepage, said Alex Stamos, Yahoos new chief information security officer and a former security researcher who used to point out holes in commercial software.

Google made a similar announcement about mail traffic between its data centers last month.

But for now, there are limits as to how far Yahoo can take that encryption, Stamos said. Websites for Good Morning America on Yahoo, Yahoo News, Yahoo Sports and Yahoo Finance wont feature the encryption by default, for now, because the company still needs to bring advertisers on board, he said.

At issue is the fact that technology being used, called HTTPS, is an all-or-nothing proposition.

When a website uses HTTPS, it prevents outsiders from watching data people submit to the site or watch what articles they are reading. But if the site is going to use such encryption, it has to persuade every advertising network running ads on that page to do the same.

For large media companies that rely on lots of ad networks, that can take a lot of coordination.

Its a little harder than to just flip a switch, Stamos said. Its just a bigger project than I expected.

(Full disclosure: The Wall Street Journal doesnt use HTTPS encryption either.)

See the original post here:
Yahoo Faces Balancing Act Between Ads, Encryption

Cloud Security Strategy: Encryption Keys

A strong cloud security strategy is important for midsize firms to truly innovate with the cloud. One way of approaching that strategy is by using encryption keys. Midsize firms that have a better understanding of encryption can better protect their cloud data.

The Key

According to a recent article on Cloud Tech, there is an ever-changing world of regulatory and compliance requirements to achieve data privacy. Companies will always need improved ways of protecting cloud data, and encryption key technology is one possible solution. Cloud data encryption makes corporate data unreadable. Only a key can switch it back to readable form. Many cloud providers use this mathematical method to protect a firm's data from the growing threat of cybercrime.

The article points to a Gartner report that emphasizes a trend, familiar to midsize firms, that shows companies as having a limited amount of time and staff to dedicate to becoming experts in a given solution such as encryption. Too many cryptographic solutions offered by security vendors can lead to an increasing amount of complexity and misunderstandings and may even put more constraints on staff resources when deployed at midsize firms. As a result, companies are putting cloud data encryption completely in the hands of cloud services providers, and that leads to less control of their corporate data. Maintaining a level of control over encryption keys, however, can help IT professionals verify how information is shared.

Clouds and Control

Any firm can strike a good balance between encryption and the cloud. Midsize firms can retain control of their encryption keys while freely sending data to trusted cloud providers. The consumerization of IT and the rise of mobility and third-platform technologies are forcing IT professionals at midsize firms to think seriously about their cloud security strategy, and encryption keys are part of that process. IT professionals that work with their security teams and experienced cloud security vendors can ensure that the type and strength of encryption being used is well understood by all.

IT professionals at midsize firms must grapple with using limited time, resources and knowledge to truly understand the latest encryption offerings available. Cloud services partners can help apply various algorithms that are used for encryption, including hashing, private-key and public-key. Understanding algorithms and cryptography-based security is important for IT professionals to be comfortable with their cloud security solutions.

As security and compliance needs continue to change and evolve, firms are ultimately responsible for keeping their most sensitive data safe. Firms that utilize encryption keys can also maintain control of those keys to help hold on to cloud data. By working with trusted cloud computing vendors that understand their security concerns, IT professionals at midsize firms will be on their way to implementing the best solutions that work for them.

This post was written as part of the IBM for Midsize Business program, which provides midsize businesses with the tools, expertise and solutions they need to become engines of a smarter planet. Like us on Facebook. Follow us on Twitter.

Excerpt from:
Cloud Security Strategy: Encryption Keys