Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts

Friday, August 21, 2015

Secure File Sharing in a Whole New Way

Now Everyone Gets to See Ashley Madison Data

Cyberattack. Your network is compromised. Hackers behind the Ashley Madison breach, the popular online dating website aimed at people hoping to cheat on their spouses, have dumped 9.7 gigabytes worth of stolen user account and payment information online. The hack includes corporate financial documents along with maps of Avid Life Media’s internal network. Trusted corporate networks no longer exist once the perimeter security is broken. Security tools such as firewalls, IPS systems, access controls, no longer protect your data. Mobile, cloud, IoT and APIs are creating a massive complexity that is rendering traditional modes of security ineffective. As your users, their devices, and applications move outside the safe and cozy confines of the corporate network, the old paradigm fails and a new approach is needed for secure collaboration and file sharing.

Moving to the Cloud

Each business has different needs and every business will reap distinct benefits from cloud solutions. Many CIOs hesitate to fully embrace a cloud-first approach. Their hesitation stems in part from an anxiety embracing a wide range of privacy and security related issues. Businesses want to retain control of their data and they want that data to be kept secure and private, all while maintaining transparency and assuring compliance.

The Need for Platform Encryption

Security and trust are major factors in every company’s evaluation of public cloud services such as the Salesforce Customer Success Platform. Companies will only use cloud providers who they greatly trust. They seek assurances that the privacy of their information and files will be highly protected; that their data will be used only in a way that is consistent with their expectations. Salesforce customers in particular are choosing which business functions to run on the Salesforce1 Platform, what applications they can build to extend those functions, and what data they need to store there to enable those functions. Customers increasingly use the Salesforce1 Platform to build applications that require PII and other sensitive, confidential, or proprietary data. Given the sensitive data stored on the Salesforce1 Platform, smart customers demand additional layers of protection beyond the standard security measures such as authentication, single sign-on, access controls, and activity monitoring as to when and how they protect their data.

Together We Deliver a Trusted Cloud

Besides platform encryption, private and shared files from enterprise social networks, file syncing and sharing, email attachments, network drives, physical USB flash drives, all these need file security with integrated access control as a last line of defense. Even if your network has been compromised by an advanced threat or by an insider and files have been leaked, your enterprise maintains visibility over those files, and ensures they are under your control. You may securely share files with anyone and retain complete tracking to see who accesses your files.

The Secure File Sharing Platform

Ohanae delivers secure file sharing in a whole new way. Unlike lesser solutions, Ohanae takes a two-prong approach to secure both your passwords and files through zero knowledge encryption. Ohanae’s unique system allows security to travel with shared files preserving the organization’s full visibility and control. Our patent-pending technology ensures passwords are not stored anywhere and are dynamically created and erased locally on your device. Ohanae is the secure file sharing platform for enterprise social networking, file syncing & sharing, making the sharing of files and passwords safer, faster, and more private. Ohanae allows users to easily create, share, and keep files in the cloud, yet permitting a secure and simple access from any device. The Ohanae solution is easy to install and use without any disruption to normal workflows. Users can download the Ohanae app from all the popular app stores. It’s easy, it’s powerful, and it’s here now!

Tuesday, September 2, 2014

It Could Happen to You

The recent, high profile compromise of several celebrities’ iCloud personal photo archives (see Jennifer Lawrence naked photos spark fear of mass celebrity hacking) reminds us of the inherent vulnerability of all cloud storage. Popular media now asks if Apple’s iCloud service is safe (see Is Apple's iCloud safe after leak of Jennifer Lawrence and other celebrities' nude photos), but the question should be even broader.

With massive consumer use of general file storage solutions like Dropbox, consumers should worry about compromise of these stores. The type of compromise that Jennifer Lawrence and other celebrities experienced could happen on any cloud storage provider — Dropbox, Box, Amazon Cloud Drive, Google Drive, Microsoft OneDrive, and, of course, iCloud.

As a first step, consumers must secure their access to cloud assets with strong, secure passwords which they change often. This minimizes the risk of an attacker directly accessing the consumer account using their legitimate credentials, and ensures that an attack which compromises one account can not spill over into other accounts.

However, mere password security is not enough as the celebrity iCloud compromise has shown. In this case, the compromise resulted from a flaw in Apple’s Find My iPhone feature, and did not require direct access to user credentials. In order to prevent this kind of compromise, consumers should use encryption to prevent access even when the attacker has possession of the data.

Cloud privacy protection tenants argue for both securing the access to the data (credentials) and the data itself (encryption). This allows users to store and share data in a world where they can’t trust anyone with safety, security, and without fear. Cloud data storage has revolutionized our ability to access data from anywhere, on any device, and it’s important to not let cyber criminals take that freedom from us.

Ohanae can help. Ohanae software, once installed on your mobile and computing devices, provides complete cloud privacy protection with three important features. First, passwords are managed allowing every site to have a unique, complex password, and facilitating password changing on a regular, short schedule. Second, data — both in transit to the cloud storage provider, and at rest in their data centers is encrypted. This encryption allows for access only by you on your registered devices! Finally, Ohanae provides secure filesharing. When you need to share data with others, all the protections of cloud privacy protection can move right along with the data. Ohanae does this all without storing any keys or passwords anywhere (locally or in the cloud) — ensuring that there is no single point of compromise which would reveal your data to prying eyes.

There’s nothing wrong with storing your sensitive data in the cloud — just make sure to use Cloud Privacy Protection to safeguard yourself!

Wednesday, August 6, 2014

Unique Passwords for Internet Accounts

With the widely publicized compromise of 1.2 billion user accounts from almost a half a million different websites, one very popular question is what can the average internet user do to protect themselves.

The common recommendations are straightforward:
  • Use long, strong, and complex passwords
  • Use different passwords for every website
  • Change your passwords often, at least every six months
  • Avoid storing sensitive information (passwords, social security numbers, or other identity information) online
These are the same, proactive recommendations that have been made for several years in response to password and credential breaches. However, historically users have been lax. For instance, among users directly affected by a large password attack, one survey found more than 1/3 of those users did not change their password at all. In 2013, the passwords “123456”, “12345678”, “password”, “qwerty”, and “abc123” continued to be the five most common passwords, just as they were in 2012 (see 2013's report here), even after many large, significant, and well publicized password thefts.

The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.

Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.

The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.

Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.

Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.

With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.

We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!

Tuesday, July 29, 2014

Mobile, BYOD, and the Enterprise

The consumerization of the mobile and bring-your-own-device trends continues to gain exponential momentum in 2014. According to an infographic published this week in Information Week, 90% of employees use mobile phones at work, and 35% use personal tablets at work. Furthermore, employees use an average of 21 different apps at work. Although email remains the most often used, document-centric apps, including file sharing are now used by more than one in every five employees.

InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.

At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.

Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.

With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.

Sunday, June 1, 2014

TrueCrypt - What Now?

TrueCrypt, a package that supported on-the-fly encryption of file data through encrypted virtual disks, partitions, and entire file systems, was discontinued by its anonymous development team on May 28, 2014.

TrueCrypt served a definite need in the market place allowing sophisticated security-minded users to encrypt data locally. By moving TrueCrypt containers onto cloud providers like Dropbox and Box, TrueCrypt’s protective capabilities could be extended to the cloud. Although the anonymous fashion in which it was developed prevented standard certification that applies for most commercially developed software, a crowd-sourced effort to audit the software was in progress, and the encryption package had a public history of successful mitigation of attacks by sophisticated law enforcement agencies.

With its announcement, the TrueCrypt Foundation has suggested that equivalent filesystem encryption capabilities may be found natively in the operating systems for Windows (BitLocker) and MacOS (FileVault). However, these solutions do not fully replace the on-the-fly type encryption that TrueCrypt provided for users storing data off their local system, in the cloud.

For storage in the cloud, users can take advantage of Cloud Privacy Protection offerings. Ohanae Inc. is proud to offer previous TrueCrypt users an integrated solution for local storage and cloud based storage, with keys that are controlled (generated and used locally) by the end user. The Ohanae solution provides security for data at rest locally, in transit to cloud providers, and at rest in the cloud.

Migration from TrueCrypt to Ohanae is simple — with drag and drop or copy/paste functionality to move files from TrueCrypt containers into Ohanae Secure Drives. Ohanae pricing is attractive — with free use for single device users, and special referral bonuses to gain premium support for up to five years.

For further information, and to start securing your data locally and in the cloud with Ohanae, please refer to http://www.ohanae.com. For information on Ohanae’s referral program, please see http://www.ohanae.com/referral.

Thursday, April 17, 2014

Heartbleed and Cloud Privacy Protection

Cloud Privacy Protection software is fundamentally about protecting your data and logins in the cloud. The recently disclosed Heartbleed SSL vulnerability affected hundreds of thousands of websites, allowing attackers to gain access to user passwords on those sites.

As web site providers have patched their servers, removing the heartbleed vulnerability, affected users could safely change their password. This prevented further use if the password was compromised.

How Cloud Privacy Protection Helps

Although heartbleed was unique in its reach, bugs and vulnerabilities in authentication processes, worms, and viruses have a lengthy history. It’s reasonable to expect that further compromises may happen in the future. However, there are some steps that you can take to protect your private cloud data today.

A fully implemented Cloud Privacy Protection system shields data loss, protects against wide spread login loss, and mitigates the resolution if an exposure does occur.

Protect the Data

First, data should be protected by keys and passwords that are distinct from user login credentials. This ensures that data at rest (stored in the cloud) and data in transit (while being sent to the cloud or to your local devices) cannot be accessed simply through compromise of your login credentials.  By utilizing a zero knowledge system,  file encryption keys are never transmitted or stored on the cloud provider. This prevents file data from disclosure even if the cloud storage provider is fully compromised.

Limit the Exposure

Second, use individual passwords for each web site. This guarantees that a security compromise like heartbleed, that allowed retrieval of user credentials on an affected website, is limited to only that website. If the same password is reused for multiple websites, then a successful breach of one can be turned into a breach of all.

Ease the Pain

Finally, using a Cloud Privacy Protection system, once the initial exposure has passed, reissue passwords – while keeping them strong and unique to each website. This ensures that potential future login breaches are prevented.

Ohanae Can Help

Ohanae’s flagship offering provides full cloud privacy protection in a zero knowledge, multi-factor local authentication system. Ohanae encrypts data files (for storage or sharing) using keys which are never transmitted to other servers. Additionally, Ohanae provides strong password management with unique passwords for each application and website. Access to these passwords is through Ohanae’s patent-pending, local, multi-factor authentication system.

Sunday, September 8, 2013

Trust No One

The fundamental fabric of the Internet has been destroyed.

The U.S. National Security Agency (NSA) and intelligence agencies in allied countries have found ways to circumvent the encryption used on the Internet, according to stories published by the New York Times and the Guardian.

According to the reports, NSA and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies. In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it is incredibly destructive for the NSA to add flaws to such critical infrastructure. The NSA seems to be operating on the assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners.

It appears that any possible way that the NSA might have bypassed encryption was almost certainly due to faulty, incomplete or invalid key management processes or simple human error, rather than through the cryptography itself. The new revelations raise major concerns from Internet users over who they can trust. We should assume that all big companies are now in cahoots with the NSA and cannot be trusted. You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer.

Businesses are acutely sensitive to government information requests because they are also beholden to privacy laws, such as HIPAA and the Gramm-Leach-Bliley Act. So, in highly regulated industries, such as financial services and healthcare, businesses must strike a balance between government oversight and consumer privacy. They feel they cannot comply with local privacy laws and have their data subject to the Patriot Act.

The U.S. Electronic Communications Privacy Act of 1986 came along in the early days of the Internet. The act did not require government investigators to obtain a search warrant for requesting access to emails and messages that are stored in online repositories. In 2001, the Patriot Act further added to the authority of the federal government to search records under its "Library Records" provision, offering a wide range of personal material into which the government could delve.

At Ohanae, we believe that ultimate security and compliance boils down to being able to protect data and logins. Trying to control the device (especially BYOD), in many cases, is neither necessary nor sufficient. At the end of the day, if you have the ability to protect the data and make sure that your data is not leaking, you do not have to touch the rest of the device.

Ohanae® Cloud Privacy Protection is a patent pending technology for securing data and logins without requiring storage of any associated credentials by the user either locally or in the cloud. Users’ data is transparently encrypted in the cloud and locally on their devices, and passwords cannot be guessed, phished, or stolen with Ohanae’s sophisticated endpoint protection mechanism.