Xtra users thought encryption calls a scam

Telecom's Xtra customers may face another week of chaos.

Tens of thousands of Xtra users who use email clients such like Microsoft Outlook and Android will find it impossible to send or receive emails from Monday, until they change security settings on their accounts.

Telecom has been contacting Xtra customers by phone and email over the past month, asking them to implement SSL (secure socket layer) encryption on their devices.

However, it appears some Xtra users believed the calls from Telecom were a scam.

About a third of Xtra users access emails using programmes such as Outlook, rather than webmail.

Telecom retail boss Chris Quin said there was "still a way to go" to persuade them all to make the settings change.

Telecom had decided to block customers' access to Xtra from late Monday if they hadn't made the change. Its customers didn't want the company to "muck around" with their online security, Quin said.

Spokeswoman Lucy Fullarton said all Xtra users would still be able to send and receive email through webmail. Email clients would be unblocked as soon as customers implemented SSL encryption.

Telecom outsourced Xtra to Yahoo in 2007 and more than 100,000 accounts have been compromised and hijacked in a series of cyber attacks over the past two years.

Yahoo has so far failed to explain the cause.

Read the original post:
Xtra users thought encryption calls a scam

Why Client-Side Encryption Is Critical For Cloud Privacy

Why Client-Side Encryption Is Critical For Cloud Privacy Posted by Rick Harvey March 12, 2014

The old tale "The Emperors New Clothes" can be applied to the current state of cloud security. Like the gullible emperor, people rely on cloud services to live their online lives and are too trusting in what companies try to sell. Big cloud companies often market fancy-sounding security and encryption features -- like the invisible fabric the emperor could not see but was made to believe was there.

These cloud providers tout the most secure or NSA-proof services, but leave out the most vital detail: encryption is only one thread in the security and privacy fabric. The only way to close the loop on data privacy is to take a look at where keys are stored.

One cloud storage provider touts its server-side encryption as freeing customers from the hassle and risk of managing their own encryption and decryption keys. In reality, this leaves the users information vulnerable to snoops. When you arent managing your own keys, you dont have control over your data.

Essentially, letting a company manage your encryption keys is handing over your protection, or clothes, like the emperor wearing the invisible wardrobe. Your data is left vulnerable to outside attacks and elements because the server or company dictates what happens to your data.

Today, many cloud service providers deliberately provide server-side security to maintain control. But server-side security requires trying to defend everywhere user data is stored: every disk, every server, every link, every router, and every database. Security is only as good as the weakest link, so it only takes one tiny mistake, vulnerability or mishandling for there to be a data breach; the Snapchat hack earlier this year is an example of what can happen.

This focus on infrastructure security is fundamentally weak. Pieces of security dont add up to overall security. Individual bits might be strong (e.g., SSL for links, disk encryption for storage), but the space between the bits might be vulnerable (i.e., data coming off links or off disks is unencrypted). Hackers dont attack individual components; instead, they attack tiny vulnerabilities between components, processes, or human control.

For cloud users to control everything client-side, they must make a paradigm shift from infrastructure protection to data-centric protection (where the encryption keys are held client-side rather than server-side). Client-side encryption is just like putting data in a tamper-proof box: The contents will remain protected regardless of who handles it, how the box is transported or where it is stored. The data is protected anywhere, everywhere and remains individually encrypted until the user with the key unlocks it.

[Read about an industry effort to develop a framework that provides secure connectivity from any device to cloud applications in "Cloud Security Alliance Launches Secure Network Effort."]

Client-side cryptography allows users to protect their own data with individual, per-file encryption and protect access to that data with user-controlled keys. Note that the encryption, decryption and key management are all done on the end users computer or device, meaning the data in the cloud only exists in its encrypted state. This level of encryptions makes the data safe from all the usual cloud risks, including hacking, rogue administrators, accidents, complicit service providers, and snooping governments.

See original here:
Why Client-Side Encryption Is Critical For Cloud Privacy

Snowden: How to protect yourself from mass surveillance

Austin, Texas (dpa) Encryption is still effective at thwarting surveillance, and internet users can protect their privacy with a variety of easy-to-use tools, fugitive US intelligence contractor Edward Snowden said Monday.

The bottom line and I repeated this again and again is that encryption does work, said Snowden, speaking to the South by Southwest Interactive conference by live videolink from Russia. We need to think about encryption not as this sort of arcane black art but sort of a basic protection. Its the defence against the dark arts in the digital realm.

Snowden advised users to take two major steps to safeguard their digital privacy: encrypt their physical devices to protect them in case theyre seized, and use network encryption to cover their online tracks.

Disk encryption can be achieved using multiple commercially available tools, both software and hardware-based. They encrypt all the data on a device and prevent unauthorized access.

Network encryption involves a number of technologies such as the SSL cryptographic protocols, which are designed to provide secure communications via the use of session keys to encrypt data flowing between the parties.

Snowden recommended the browser plug-ins NoScript (http://dpaq.de/22gas) to block active exploitation attempts in the browser, and Ghostery (http://dpaq.de/zOoR4) to block ads and tracking cookies.

Another essential privacy tool is the use of the so-called mixed routing network TOR (http://dpaq.de/ZcKOI), an anonymity network that routes traffic through a vast system of relays to hide a users location and usage from anyone conducting network surveillance or traffic analysis.

If you take those basic steps, you encrypt your hardware and you encrypt your network communications, youre far, far more hardened than the average user, and it becomes very difficult for any sort of a mass surveillance to be applied to you, Snowden said.

Youll still be vulnerable to targeted surveillance, he added. If theres a warrant against you, if the NSAs after you, theyre still going to get you. But mass surveillance, this untargeted, collect-it-all approach, youll be much safer.

Read the original:
Snowden: How to protect yourself from mass surveillance

Encryption makes you an NSA target expert warns

Chris Davies

Following Edward Snowden's call for internet users to encrypt everything as a matter of course is likely to make you an even bigger target for the NSA, activist journalist Glenn Greenwald has warned, arguing that the stance inside the spying agency is that those protecting their data are inherently suspicious. "If you want to hide what you're saying from them" Greenwald said during a video appearance at SXSW this week, "it must mean that what you're saying is a bad thing," the former Guardian writer said the National Security Agency's assumptions.

Snowden had put out a call for the tech-savvy attendees of SXSW to factor in end-to-end encryption as the default, not as an option, for software and services, pointing out that such a strategy would remove the low-hanging fruit from the NSA in terms of monitoring. Snowden had appeared on a panel of his own, also attending virtually via a video call.

Rather than being able to tap straight into the mass of internet traffic, gathering huge quantities of innocent user-data along the way, the security Agency would be forced to target specific computers of persons-of-interest, the former security contractor turned whistleblower argued.

Failing that, Snowden pointed out that internet users themselves should take privacy into their own hands, encrypting hard-drives, installing tracker-blocking plugins for browsers, and running their web activities through Tor.

Doing that, however, will likely raise your profile with the NSA, Greenwald warned during his panel, VentureBeat reports, however. One of three journalists to get the raw files leaked by Snowden, he says his impression from sifting through the masses of information is that the NSA views any attempt at secrecy as suspicious.

"They view the use of encryption ... as evidence that you're suspicious and can actually target you if you use it" he said.

According to Greenwald, the general perception of how tricky encryption and other basic security techniques are has meant that the relative few who go through with turning it on are more obvious in the mass of data the NSA gathers. That can make them the first to be targeted.

Meanwhile, secured devices like the Blackphone launched at Mobile World Congress last month, or Boeing's similar Black handset, are available but remain niche and generally misunderstood.

Of course, there are legal ways that government agencies can gain access to an individual's data, but encryption by default does at least offer some degree of reassurance that files are safe from mass trawling of internet traffic. The NSA has tried to crack systems like Tor, but so far the re-routing approach has proved resilient to attempts to tap into it, experts say.

Originally posted here:
Encryption makes you an NSA target expert warns

Ciphers in Java,symmetric encryption example with padding,initaivector,modes ECB,CBC – Video


Ciphers in Java,symmetric encryption example with padding,initaivector,modes ECB,CBC
Ciphers in Java five confidentiality modes of operation for symmetric key block cipher algorithms The Electronic Codebook Mode (ECB) The Cipher Block Chainin...

By: Zariga Tongy

Read more:
Ciphers in Java,symmetric encryption example with padding,initaivector,modes ECB,CBC - Video