Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

10/9/2013
05:47 PM
50%
50%

Legal Fears Put Mobile Backups In Spotlight

Users regularly put their most important mobile data in the cloud via with file-sharing and backups, but that's risky to the business

A decade ago, almost no one used online backup services to store their data in the cloud. Yet, as smartphones become ubiquitous, the need to synchronize data among multiple devices has boosted the use of cloud backups and put more personal and business data onto third-party servers.

While centralized storage and administration of data in the cloud is beneficial for users, large stores of data attract unwanted attention as well, and not just from cybercriminals and hackers. With the June revelations of the extent to which the U.S. National Security Agency (NSA) is collecting data on users, more businesses and people are concerned that their data may be accessed by a subpoena or search warrant.

In fact, legal access to such detailed data may be a greater threat than hackers, says Lee Tien, senior staff attorney with the Electronic Frontier Foundation (EFF).

"Our feeling for the major smartphone OSes -- we don't think there is a great threat from the classic bad guys," Tiensays. The companies that maintain the largest collection of online backups, Google and Apple, "tend to have pretty good security practices, but obviously, given what we know about NSA PRISM, we think we have to say that is a completely different story," he adds.

Today, almost all companies -- 94 percent -- have worries about employees mixing personal and business data on their mobile devices, according to a survey published by online-backup provider EVault in January. The problem will only get larger, with seven out of every 10 companies expecting the amount of data they manage to increase, the report states.

[Microsoft, Google, Facebook, and other tech firms have downplayed their participation in government spying programs, but U.S. and international companies should worry about access to their data in the cloud. See NSA Data Collection Worrisome For Global Firms.]

At the same time, mobile devices are also more attractive targets because of the variety of data that applications gather and store, says Troy Vennon, director of network-technology provider Juniper. While data from PCs can reveal a user's online activities, mobile-device data also exposes location, additional images, potential voice recordings, and business files that have been synched with the device.

"A lot of personal data is being gathered into applications where it probably shouldn't be, and that has the potential to end up in the cloud," Vennon says.

A minority, but still a significant number, of companies do appear to be worried about the threat of legal access to their data, according to security firms. While the NSA's access to data may not be a significant issue for U.S. companies, multinational firms have to worry about similar agencies in other countries accessing their data as well.

The extent to which governments have access to online data has caused general unease, says Raghu Kulkarni, CEO of cloud backup service IDrive. The company offers both private-key encrypted backups, where the data is encrypted at the user's device before being sent to the cloud, and the more common data protection service, where the data is secured by the service's encryption solution.

Although IDrive has seen a 25 to 30 percent increase in interest since revelations about the data-collection activities of the NSA were published in June, only about one-third of users opt to use the private-key service.

"There is a trade-off between ease of use and privacy," Kulkarni says. "If you lose the key, then the data is gone forever. So it always depends on the users' requirements."

Companies that want greater control of their data need to either use a backup service that allows private keys or back up their data locally, he says.

Yet the trend in employee-owned devices is also a problem: Most businesses cannot know how much of their data has been backed up along with an employee's data in the cloud, says Juniper's Vennon. Companies that want to protect their data on mobile devices will need to gain more control over it using a secure container and mobile device management (MDM) software that can limit where the data can go, he says.

"Without some pretty intricate mobile device management systems -- which have only been tinkered with in the past but which will be used pretty extensively from now on -- can [companies] keep that data from comingling with user data," Vennon says. "Once you containerize the data, split it into a personal profile and a work profile, then they have the ability to focus on those backups."

Government access to personal data stored in the cloud may remain a digital-rights issues, but because employees continue to use business data on their mobile devices, it's an issue that businesses will need to watch.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment:   It's a PEN test of our cloud security.
Current Issue
IT 2020: A Look Ahead
Are you ready for the critical changes that will occur in 2020? We've compiled editor insights from the best of our network (Dark Reading, Data Center Knowledge, InformationWeek, ITPro Today and Network Computing) to deliver to you a look at the trends, technologies, and threats that are emerging in the coming year. Download it today!
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5226
PUBLISHED: 2020-01-24
Cross-site scripting in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script allows error reports to be submitted and sent to the system administrator. Starting with SimpleSAMLphp 1.18.0, a new SimpleSAML\Utils\EMail class was introduced to handle sending emails, implemented as a wrapp...
CVE-2019-1517
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1518
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1519
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.
CVE-2019-1520
PUBLISHED: 2020-01-24
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2019. Notes: none.