Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Monday, 9 September 2013

U.S. and U.K. spies crack BlackBerry BES encryption, report says

IDG News Service - The U.S. National Security Agency is able to read messages sent via a corporate BlackBerry Enterprise Server (BES), according to a report by German news magazine Der Spiegel. The purpose of this spying is economic or political, and not to counter terrorism, the magazine hints.

The report, published in English on Monday, cites internal documents leaked by former NSA contractor Edward Snowden.

Governments have long demanded that BlackBerry provide access to encrypted messages carried by its email and BlackBerry Messenger (BBM) services, to allow them to monitor for terrorist activity.

BlackBerry has complied in the case of its consumer-grade BlackBerry Internet Service (BIS), notably providing the Indian government with access to consumer messages. Indeed, Der Spiegel cited NSA documents claiming that since 2009, analysts have been able to see and read text messages sent from BlackBerrys, and to collect and process BIS mails.

However, the company has always maintained that it cannot provide access to messages sent through its offering for corporate customers, BES, saying the encryption keys are known only to the company operating the BES.

However, among the documents leaked by Snowden are some that indicate the NSA, and its U.K. counterpart, the Government Communications Headquarters (GCHQ), can access text messages and emails sent between BES users, Der Spiegel said.

The two agencies have been targeting messages sent via BlackBerry's platform since before May 2009, when they ran into temporary difficulties that U.K. analysts later traced to a change in BlackBerry's messaging protocol following its acquisition of a smaller company. By March 2010, they were once again able to access the information, Der Spiegel said, citing GCHQ documents marked "UK Secret."

The leaked documents seen by Der Spiegel contain no indications of large-scale spying on smartphone users, but "If the intelligence service defines a smartphone as a target, it will find a way to gain access to its information," the magazine reported.

Der Spiegel said that to acquire BES data involves a sustained effort on the part of the NSA's Office of Tailored Access Operations, a specialized hacking team based in Forte Meade, Maryland.

An NSA presentation entitled "Your target is using a BlackBerry? Now what?" seen by the magazine shows what can be achieved. It contained an image of a Mexican government email, the plain text of which appears in a slide under the title "Post Processed BES collection."

Such cases raise questions for other states. As the magazine noted, the German federal government recently awarded a contract to BlackBerry for secure communications between federal agencies.

Ironically, though, other documents show the NSA is concerned about the effects on national security of BlackBerry's declining popularity among U.S. government employees. Between August 2009 and May 2012, the "only certified government smartphone" saw its share of the U.S. government smartphone market fall from 77 percent to 50 percent, the documents said.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Sunday, 8 September 2013

Here's how to best secure your data now that the NSA can crack almost any encryption

The latest Snowden-supplied bombshell shook the technology world to its core on Thursday: The NSA can crack many of the encryption technologies in place today, using a mixture of backdoors baked into software at the government's behest, a $250 million per year budget to encourage commercial software vendors to make its security "exploitable," and sheer computer-cracking technological prowess.

To some extent, it's not surprising to hear that the U.S. spy agency is doing spy agency stuff but, given the recent surveillance revelations and the fact that other countries likely have similar capabilities, the news is certainly worrying. To make matters worse, it came just a day after Pew reported that 90 percent of Internet users have taken steps to avoid surveillance in some way.

[ Security expert Roger A. Grimes offers a guided tour of the latest threats and explains what you can do to stop them in "Fight Today's Malware," InfoWorld's Shop Talk video. | Keep up with key security issues with InfoWorld's Security Adviser blog and Security Central newsletter. ]

All is not lost, however. While the stunning reports failed to name exactly which companies and encryption technologies have been compromised by the NSA, you can minimize the chances that your encrypted communications will be cracked by the government -- or anyone else. Read on.

Embrace open source
Now that we know that corporations -- or at least individuals in corporations -- have worked with the NSA to build backdoors into encryption technology, privacy buffs should give commercial encryption technology (such as Microsoft's BitLocker) the hairy eye.

You're better off using tools that employ open-source or public-domain encryption methods, as they need to work with every vendor's software and, in the case of open-source encryption, can be scrutinized for potential security flaws.

With that in mind, here are some tools worth checking out:


View the original article here

Report: NSA defeats many encryption efforts

The U.S. National Security Agency has been circumventing many online encryption efforts through a combination of supercomputers, back doors built into technology products, court orders and other efforts, according to a new report from The New York Times and ProPublica.

The NSA has cracked much of the encryption that protects global commerce, banking, trade secrets and medical records, according to the report, which cites documents leaked by former NSA contractor Edward Snowden. The NSA has invested billions of dollars in efforts to defeat encryption since 2000, according to the report.

[ For a quick, smart take on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. ]

In addition to deploying supercomputers to crack encryption, the NSA has worked with U.S. and foreign technology companies to build entry points into their products, the report said. The agency spends more than $250 million a year on its Sigint Enabling Project, which engages the IT industry in an effort to get companies to make their commercial products "exploitable," the report said, citing documents from Snowden.

The report did not name companies that have cooperated with the NSA.

Representatives of the NSA and the U.S. Office of Director of National Intelligence didn't immediately respond to a request for comments on the news report.

In addition, British intelligence agency GCHQ, likely working with the NSA, has been attempting to hack into the protected traffic at Google, Yahoo, Facebook and Microsoft's Hotmail, the report said. GCHQ had developed "new access opportunities" into Google's system, according to a document from Snowden.

The NSA has also been working for years to weaken international encryption standards, the report said. NSA memos appear to confirm that the agency planted vulnerabilities in an encryption standard adopted in 2006 by the U.S. National Institute of Standards and Technology, the report said.

The NSA sees the ability to decrypt information a vital capacity, and the U.S. competes with China, Russia and other countries in that area, according to the documents referenced in the report.

Grant Gross covers technology and telecom policy in the U.S. government for The IDG News Service. Follow Grant on Twitter at GrantGross. Grant's e-mail address is grant_gross@idg.com.


View the original article here

Saturday, 7 September 2013

Encryption still best way to protect data -- despite NSA

Computerworld - Though the National Security Agency spends billions of dollars to crack encryption technologies, security experts maintain that properly implemented, encryption is still the best way to maintain online privacy.

The Guardian newspaper and other media outlets this week published stories based on internal internal NSA documents that explain how the spy agency bypasses encryption technologies by using backdoors, brute force attacks, lawful intercepts via court orders and partnerships with tech vendors.

The reports, based on documents leaked to reporters by former NSA-contract employee Edward Snowden, suggest that many encryption algorithms now widely used to protect online communications, banking and medical records and trade secrets have been cracked by the NSA and its British counterpart, the GCHQ.

Steve Weis, chief technology officer at PrivateCore and holder of a Ph.D in cryptography from MIT, said despite the NSA activities, the mathematics of cryptography remains very hard to crack.

He suggested that it's likely that the NSA managed to break through insecure and outdated implementations of some encryption technologies.

For example, the documents suggest that the NSA built a backdoor into an NIST approved encryption standard called Dual EC DRBG, which is used to generate random numbers. Weis noted that the Dual EC DRBG standard has been available for six years and has been rarely used since two Microsoft engineers discovered the NSA backdoor, Weis said.

It remains unclear whether NSA experts have the ability to crack more robust encryption technologies, he said. "So far, I've not seen anything to suggest than an algorithm like AES (Advanced Encryption Standard) has been broken," Weis said.

"When properly implemented, encryption provides essentially unbreakable security," said Dave Anderson, a senior director with Voltage Security, a provider of encryption technology.

"It's the sort of security that would take implausibly powerful supercomputers millions of years to crack. But if it's carelessly implemented, and the key management processes are not sound, this security can be reduced to the level where a hacker with a mid-market PC can crack in a few hours at most," he said an email to Computerworld.

Anderson said the NSA may have been able to take advantage of flaws in key management processes that support the encryption, rather than cracking the cryptography itself, he said. It's possible that the NSA can decrypt financial and shopping accounts, but it can happen only if the cryptography was improperly implemented through faulty, incomplete or invalid key management processes, he said.

Dave Jevans, founder and CTO of Marble Security, a maker of mobile security technology, said some of the concerns raised by the NSA documents are based on a misunderstanding of the facts.

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

Wednesday, 21 August 2013

VMware, Citrix and Microsoft virtual desktops get encryption security

Network World - AFORE Solutions today announced encryption software aimed at securing data in virtualized environments where Microsoft Windows applications are used, including virtualized desktop infrastructure deployments based on VMware, Citrix or Microsoft VDI.

AFORE's CypherX software can be used by either cloud providers on behalf of their customers or directly by the enterprise users in a private cloud deployment, according to the security firm's chairman and chief strategy officer, Jon Reeves. "This is intended for secure storage in the cloud," Reeves said about CypherX. "It sits between the application and the operating system itself in order to lock down applications. It encrypts all information flowing in and out, the file system, and the network or the clipboard."

7 IT security skills certifications on the rise

Using standard AES 256-bit encryption, CypherX works on A multiple hypervisors, including VMware vSphere, Microsoft Hyper-V and Xen and KVM. It supports multiple desktop virtualization platforms, including VMware's Horizon View, Citrix XenDesktop, and Microsoft's VDI.

CypherX has an App Lockdown feature that acts as a virtual container for applications, and so-called "CypherZones" can be set up to extend security between groups of protected applications. CypherX Manager, which can be integrated with Active Directory and RSA Data Protection Manager, is used to provide centralized control of security policy across virtual machines.

"You pick which applications need to be secured, say a hosted medical record, and it's set up as a trusted application and everything coming in or out is encrypted," Reeves says. CypherX allows the security manager to establish a control process in which only authorized users on validated machines can access an application certified as trusted. Reeves says CypherX in some regards can be compared to information rights management systems from Microsoft or Oracle in its functionality.

Ottawa, Canada-based AFORE's other product, CloudLink Secure VSA, is a virtual storage appliance used for encryption in VMware Vblock infrastructures.

Now in beta tests with a number of cloud providers, CypherX starts at $150 per seat, though less based on volume, and is expected to be generally available in the October timeframe.

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail: emessmer@nww.com

Read more about data center in Network World's Data Center section.

Reprinted with permission from NetworkWorld.com. Story copyright 2012 Network World, Inc. All rights reserved.

View the original article here