Follow Us

Encryption could make you more vulnerable, warn experts

Locking up your data is fine - until someone steals, loses or breaks the key.

The use of data encryption could make organisations vulnerable to new risks and threats, a panel of security experts warned today.

Many organisations are encrypting their stored data to relieve concerns over data theft or loss - for example, US mandatory disclosure laws on data breaches do not apply to encrypted data.

However, experts from IBM Internet Security Systems, Juniper, nCipher and elsewhere said that data encryption also brings new risks, in particular via attacks - deliberate or accidental - on the key management infrastructure.

The change comes particularly with the shift from encrypting data in transit to encrypting stored data - often in response to regulatory demands - said Richard Moulds, nCipher's product strategy EVP.

"Lot of organisations are new to encryption," he added. "Their only exposure to it has been with SSL, but that's just a session. When you shift to data at rest and encrypt your laptop, if you lose the key you trash your data - it's a self-inflicted denial-of-service attack.

"Organisations experienced with encryption are standing back and saying this is potentially a nightmare. It is potentially bringing your business to a grinding halt."

Encryption is also as big an interest for the bad guys as the good guys, warned Anton Grashion, European security strategist for Juniper. "As soon as you let the cat out of the bag, they'll be using it too," he said. "For example, it looks like a great opportunity to start attacking key infrastructures."

"It's a new class of DoS attack," agreed Moulds. "If you can go in and revoke a key and then demand a ransom, it's a fantastic way of attacking a business."

Another risk is that over-zealous use of encryption will damage an organisation's ability to legitimately share and use critical business data, noted Joshua Corman, principal security strategist for IBM ISS.

"One fear I have is that we're all going to hide all our information, but companies are information-driven, so we take tactical decision and stifle ability to collaborate," he said.

"Sometimes, the result of implementing security technology is actually a net increase in risk," added Richard Reiner, chief security and technology officer at Telus Security Solutions.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *