Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

6/16/2009
05:32 PM
50%
50%

Data-Encryption Critics Play A Dangerous Game

Is encryption "overrated" as a data-security tool? Only if your company has a death wish.

Is encryption "overrated" as a data-security tool? Only if your company has a death wish.Cleversafe is a commercial open-source vendor that employs a "dispersed storage" architecture to protect business data. Recently, a blog post appeared on the Cleversafe.org community site with a provocative headline: "3 Reasons Why Encryption Is Overrated."

The post's author builds his case with three key points:

- Advances in CPU power inevitably turn today's "uncrackable" encryption into tomorrow's mincemeat.

- Key management -- a serious challenge for bigger companies -- can turn a promising encryption solution into an operational nightmare.

- Disclosure laws still force companies to reveal data-loss incidents -- and accept the PR consequences -- whether or not the lost data is encrypted.

As the blog post acknowledges, Cleversafe offers an alternative data-security solution that disperses data across a global storage network. The dispersed data slices are too small to give an attacker useful information, and users without the proper credentials are unable to retrieve and reconstruct the dispersed data.

It's an interesting solution, and its open-source technology base makes it especially interesting to me. For now, however, let's focus on the issue at hand: Is encryption really "overrated" as a data-security tool?

In this case, I think the term "overrated" isn't just an exaggeration. It's downright dangerous.

The idea that any tool offers perfect security is a red herring. Every security tool balances usability against effectiveness. And every security tool will, sooner or later, present opportunities to a determined, skilled attacker.

Will an encryption tool like TrueCrypt offer foolproof, totally effective encryption? Don't count on it. What it will do is buy a company time -- years, in many cases -- before even the most determined attacker can bring the resources to bear to defeat strong encryption.

Key management is a legitimate issue. Yet many encryption tools feature key-escrow features designed specifically for larger companies. If key management is a concern, seek out these products and evaluate them accordingly.

Frankly, the third reason the Cleversafe blog post mentions is a cop-out. Encryption will protect a company's customers and quite possibly reduce its legal liability in case of a data-loss incident. Dealing with PR fallout is always an unpleasant experience, but it's a cakewalk compared to the prospect of admitting that your company allowed a laptop full of unprotected customer records or credit card numbers to disappear.

Encryption is "overrated" only if you think it's perfect -- a foolish assumption from the get-go. For everyone else, it's overrated only if your company's goal is to get out of business as quickly as possible.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Limited-Time Free Offers to Secure the Enterprise Amid COVID-19
Curtis Franklin Jr., Senior Editor at Dark Reading,  3/31/2020
COVID-19: Latest Security News & Commentary
Dark Reading Staff 4/3/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11586
PUBLISHED: 2020-04-06
An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XML DTD data.
CVE-2020-11587
PUBLISHED: 2020-04-06
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and get the content of ETL Processes running on the server.
CVE-2020-11589
PUBLISHED: 2020-04-06
An Insecure Direct Object Reference issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make a GET request to a certain URL and obtain information that should be provided to authenticated users only.
CVE-2020-11590
PUBLISHED: 2020-04-06
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an HTTP GET request to HealthPage.aspx and obtain the internal server name.
CVE-2020-11591
PUBLISHED: 2020-04-06
An issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request and obtain the full application path along with the customer name.