Unitrends Data Backup Webinar: Utilizing The Cloud, Deduplication, and Encryption – Video


Unitrends Data Backup Webinar: Utilizing The Cloud, Deduplication, and Encryption
This 45 minute webinar will help you understand the various approaches to outlining and implementing a new approach to your old backup plan, including how to...

By: Unitrends Inc.

Here is the original post:
Unitrends Data Backup Webinar: Utilizing The Cloud, Deduplication, and Encryption - Video

Townsend Security Releases Encryption Key Management Virtual Machine for Windows Azure

Olympia, WA (PRWEB) February 10, 2014

Townsend Security, a leading authority in data privacy solutions, today announced Alliance Key Manager for Windows Azure. Deployed as a virtual machine in Microsoft Corp.s Windows Azure, the solution relies on the same FIPS 140-2 compliant technology as the companys flagship Alliance Key Manager HSM.

This solution directly addresses security concerns that CISOs and Security Architects have regarding adopting the cloud. Key management is critical for effective encryption and data protection in ever-evolving virtual and cloud environments. By using Alliance Key Manager for Windows Azure, business leaders can now provably meet industry standards and best practices for protecting their sensitive data and business applications.

Available at no extra charge, Townsend Security includes ready-to-use security applications for Microsoft SQL Server Transparent Data Encryption (TDE) and Cell Level Encryption, Microsoft SharePoint encryption, Volume and folder encryption with TrueCrypt for Windows, and other applications. There are never extra fees for deploying client-side applications.

Encryption and key management have become a key strategic IT security issue. Protecting your encryption keys mitigates the risk of data breaches and cyber-attacks, as well as protects an organizations brand, reputation and credibility, said Patrick Townsend, CEO of Townsend Security. Through our relationship with Microsoft we can provide customers with the encryption and key management tools for Windows Azure.

In line with Microsofts longstanding and deep commitment to security, Windows Azure is designed to meet the highest security standards, said Sarah Fender, director, Windows Azure Product Marketing. Townsend Security builds on that security foundation, helping address enterprise customers need for data protection in the cloud. Townsend Securitys Alliance Key Manager for Windows Azure gives Windows Azure customers a comprehensive encryption key management solution to help safeguard data and meet compliance requirements.

Alliance Key Manager for Windows Azure at a glance:

Alliance Key Manager for Windows Azure is available for a free 30-day trial.

---

About Alliance Key Manager for Windows Azure Townsend Securitys Alliance Key Manager for Windows Azure allows enterprises to properly manage their encryption keys while meeting security requirements in less time and at a lower cost. Using the same FIPS 140-2 validated key management technology available in Townsend Securitys HSM and in use by over 3,000 customers worldwide, Alliance Key Manager for Windows Azure provides full life-cycle management of encryption keys for a wide variety of applications to help organizations meet PCI DSS, HIPAA, and PII compliance.

Read more:
Townsend Security Releases Encryption Key Management Virtual Machine for Windows Azure

Real Data Encryption Software is More Important than Ever …

The NSA story keeps breaking, with the latest revelation that the NSA paid RSA, a subsidiary of EMC, with a deep history in computer and internet security to implement and sell faulty encryption technology to its own clients. The December 2013 Reuters story has sent companies here and abroad scrambling to distance themselves from RSA and has seriously undermined consumer confidence in U.S.-based data encryption software providers at-large.

In September 2013, The New York Times released a statement from the NSA which confirmed that the agency was working to, break widely used Internet encryption technologies. That admission wasnt the kicker, but rather that the agency had resorted to buying the complicity of a company dedicated to protecting customer data security. Moreover, the story of RSAs involvement has a bright patina of irony to it in that in the 1990s the company successfully prevented NSA from embedding a sophisticated spying chip in all computing hardware.

The software used, Bsafe, was a landmark in data encryption, in that it was the first to successfully implement two-key encryption. In a secret deal with the NSA, RSA was paid $10 million to inculcate an algorithm - called Dual Eliptic Curve - that generates flawed, random numbers in its Bsafe technology, and, get this, call it the preferred option. This gave NSA a backdoor into the companys tokens.

The Cost of Giving It UP

The company denies direct complicity, alleging that they were duped, and advised its customers to stop using the corrupt algorithm (after the story leaked), but the damage is, as they say, done. The RSA sponsored cyber security-conference to be held in San Francisco this February continues to lose keynote speakers. Boeing lost a multi-billion dollar contract with Brazil, as a result of the NSAs spying. And across the cyber-sphere, analysts predict a tsunami backlash from European businesses with customers that expect their data to adhere to the EUs considerably greater regard for individual privacy.

A Firefox executive recently encouraged security researchers to regularly audit Firefoxs source code, which is open source, in the hopes that the global community will help catch and arrest attempts to insert surveillance code into its browser. If this sounds paranoid, its worth noting that a small email company named Lavabit recently revealed that the U.S. government had requested information on its customers and then silenced them with a gag order.

Blocking the Backdoor

Most data encryption providers work with the National Institute of Science and Technology (NIST), an agency which provides industry-leading guidance on data encryption security, to ensure their cryptographic engines are safe to the highest industry standards (i.e., FIPS validated), but recent revelations are putting a spotlight on the nature of the relationship between NIST and data encryption providers, in no small part because another revelation from former NSA contractor, Edward Snowden, suggest that random number generators used in a 2006 NIST standard contains a back door for the N.S.A.

Winmagic (a private Canadian company), looked into the implicated NIST standard (Dual EC DRBG) and determined it had not, which was a welcome relief to the company and its customers. That notwithstanding, speculation about the NSAs ability to hack into the data encryption industrys toughest fortresses, such as 256-bit AES encryption, run rampant. Fortunately, the degree of layered encryption this provides would require the kind of effort that could take years to complete. And now that data encryption companies are on to the NSAs latest backdoor trick, they are focusing their efforts on staying one step ahead of the curve.

Sources:

See the rest here:
Real Data Encryption Software is More Important than Ever ...

A Beginner’s Guide to Encryption: What It Is and How to …

S

You've probably heard the word "encryption" a million times before, but if you still aren't exactly sure what it is, we've got you covered. Here's a basic introduction to encryption, when you should use it, and how to set it up.

Encryption is a method of protecting data from people you don't want to see it. For example, when you use your credit card on Amazon, your computer encrypts that information so that others can't steal your personal data as its being transferred. Similarly, if you have a file on your computer you want to keep secret only for yourself, you can encrypt it so that no one can open that file without the password. It's great for everything from sending sensitive information to securing your email, keeping your cloud storage safe, and even hiding your entire operating system.

Encryption, at its core, is similar to those decoder rings you played with when you were younger. You have a message, you encode it using a secret cipher, and only other people with the cipher can read it. Anyone else just sees gibberish. Obviously, this is an incredibly simplified explanation. The encryption in your computer is far more complexand there are different types of encryption that use multiple "decoder rings"but that's the general idea.

There are also different levels of security when it comes to encryption. Some types, for example, are more secure but take longer to "decode." And few, if any, encryption methods are 100% foolproof. If you want a more thorough explainer on how encryption works, check out this article from the How-To Geek and this article from HowStuffWorks. They explain a few different kinds of encryption and how they keep you safe online.

First of all, a short answer: yes. Things can get stolen even if you don't share your computer. All someone needs is a few minutes in front of the keyboard to retrieve anything they want. A login password won't protect you, eitherbreaking into a password-protected computer is insanely easy.

So should you encrypt your sensitive files? Yes. But it's a bit more to it than that. You have two big choices when it comes to encryption: do you just encrypt the important stuff, or do you encrypt your entire drive? Each has pros and cons:

We generally recommend against average users encrypting their entire drive. Unless you have sensitive files all over your computer, or have other reasons for encrypting the entire thing, it's easier to encrypt the sensitive files and call it a day. Full disk encryption is more secure, but can also much more problematic if you don't put in the work to keep everything backed up safely (and then encrypt those backups as well).

That said, we'll show you how to do both in this guide. and what you do is up to you. We'll talk a bit more about each situation in their individual sections below.

Follow this link:
A Beginner's Guide to Encryption: What It Is and How to ...

Encryption – University of Illinois at Urbana–Champaign

ENCRYPTION

"If privacy is outlawed, only outlaws will have privacy. Intelligence agencies have access to good cryptographic technology. So do the big arms and drug traffickers. So do defense contractors, oil companies, and other corporate giants. But ordinary people and grassroots political organizations mostly have not had access to affordable military grade public-key cryptographic technology. Until now.

PGP empowers people to take their privacy into their own hands. There's a growing social need for it. That's why I wrote it.",

Phillip Zimmermann, author of encryption software program, PGP [1]

Introduction

Maintaining privacy in our personal communications is something everyone desires. Encryption is a means to achieve that privacy. It was invented for that very purpose. That makes encryption a good idea, right? But encryption, like most things, can be used for good or evil. And the debate over how to harness this powerful tool rages on as people on both sides see that there are no easy answers. .

What is encryption?

Read the original post:
Encryption - University of Illinois at Urbana–Champaign

Tumblr adds SSL encryption option, but not as the default

Tumblr now allows users to encrypt their connections with the microblogging service, but the feature is only offered as an option for nownot the default.

"You can now take extra precaution against hackers and snoops by enabling SSL security on your Tumblr Dashboard, Conrad Rushing, Tumblrs director of security engineering, said Monday in a blog post. Just head over to your Account Settings and flip the switch.

The adoption rate of HTTPSHTTP with SSL encryptionby online services has increased rapidly over the past several years, driven in part by significant growth in the mobile market.

Many users today access online services primarily from their smartphones and tablets and these devices are frequently connected to public, insecure and generally untrusted wireless networks. This exposes them to man-in-the-middle attacks where attackers intercept Internet traffic and extract sensitive details from it like session cookies, which then allow them to hijack online accounts.

In addition, documents leaked last year by former U.S. National Security Agency contractor Edward Snowden revealed that intelligence agencies are collecting data about Internet communications from unencrypted traffic as it passes through the global Internet infrastructure. Those revelations have increased awareness about online privacy among users.

The revelations about the NSAs mass data collection programs prompted a commitment from Yahoo to provide users with the option to encrypt their traffic with the companys services by the end of the first quarter of 2014. The company made HTTPS a default setting for its email service at the beginning of January.

Yahoo acquired Tumblr in June 2013, but the company continues to be operated independently.

In a time when many popular online services are rushing to make HTTPS the default setting, or have done so already, Tumblrs decision to offer the feature on an opt-in basis strikes some as a bit unusual.

"The addition of SSL is surely better than plain old HTTP and makes sense especially when the user accesses the service via a mobile application, said Bogdan Botezatu, a senior e-threat analyst at security vendor Bitdefender, Tuesday via email. However, SSL only makes sense if it is enabled by default, because the regular user wont likely alter the default account settings.

"We will eventually turn on this feature by default for all of our users, but to best handle the immense traffic produced by such an effort, we are beginning first by giving our users the ability to opt-in, said Katherine Barna, Tumblrs head of communications, via email.

Read more:
Tumblr adds SSL encryption option, but not as the default