Showing posts with label cloud. Show all posts
Showing posts with label cloud. Show all posts
Friday, August 21, 2015
Tuesday, September 2, 2014
It Could Happen to You
The recent, high profile compromise of several celebrities’ iCloud personal photo archives (see Jennifer Lawrence naked photos spark fear of mass celebrity hacking) reminds us of the inherent vulnerability of all cloud storage. Popular media now asks if Apple’s iCloud service is safe (see Is Apple's iCloud safe after leak of Jennifer Lawrence and other celebrities' nude photos), but the question should be even broader.
With massive consumer use of general file storage solutions like Dropbox, consumers should worry about compromise of these stores. The type of compromise that Jennifer Lawrence and other celebrities experienced could happen on any cloud storage provider — Dropbox, Box, Amazon Cloud Drive, Google Drive, Microsoft OneDrive, and, of course, iCloud.
As a first step, consumers must secure their access to cloud assets with strong, secure passwords which they change often. This minimizes the risk of an attacker directly accessing the consumer account using their legitimate credentials, and ensures that an attack which compromises one account can not spill over into other accounts.
However, mere password security is not enough as the celebrity iCloud compromise has shown. In this case, the compromise resulted from a flaw in Apple’s Find My iPhone feature, and did not require direct access to user credentials. In order to prevent this kind of compromise, consumers should use encryption to prevent access even when the attacker has possession of the data.
Cloud privacy protection tenants argue for both securing the access to the data (credentials) and the data itself (encryption). This allows users to store and share data in a world where they can’t trust anyone with safety, security, and without fear. Cloud data storage has revolutionized our ability to access data from anywhere, on any device, and it’s important to not let cyber criminals take that freedom from us.
Ohanae can help. Ohanae software, once installed on your mobile and computing devices, provides complete cloud privacy protection with three important features. First, passwords are managed allowing every site to have a unique, complex password, and facilitating password changing on a regular, short schedule. Second, data — both in transit to the cloud storage provider, and at rest in their data centers is encrypted. This encryption allows for access only by you on your registered devices! Finally, Ohanae provides secure filesharing. When you need to share data with others, all the protections of cloud privacy protection can move right along with the data. Ohanae does this all without storing any keys or passwords anywhere (locally or in the cloud) — ensuring that there is no single point of compromise which would reveal your data to prying eyes.
There’s nothing wrong with storing your sensitive data in the cloud — just make sure to use Cloud Privacy Protection to safeguard yourself!
With massive consumer use of general file storage solutions like Dropbox, consumers should worry about compromise of these stores. The type of compromise that Jennifer Lawrence and other celebrities experienced could happen on any cloud storage provider — Dropbox, Box, Amazon Cloud Drive, Google Drive, Microsoft OneDrive, and, of course, iCloud.
As a first step, consumers must secure their access to cloud assets with strong, secure passwords which they change often. This minimizes the risk of an attacker directly accessing the consumer account using their legitimate credentials, and ensures that an attack which compromises one account can not spill over into other accounts.
However, mere password security is not enough as the celebrity iCloud compromise has shown. In this case, the compromise resulted from a flaw in Apple’s Find My iPhone feature, and did not require direct access to user credentials. In order to prevent this kind of compromise, consumers should use encryption to prevent access even when the attacker has possession of the data.
Cloud privacy protection tenants argue for both securing the access to the data (credentials) and the data itself (encryption). This allows users to store and share data in a world where they can’t trust anyone with safety, security, and without fear. Cloud data storage has revolutionized our ability to access data from anywhere, on any device, and it’s important to not let cyber criminals take that freedom from us.
Ohanae can help. Ohanae software, once installed on your mobile and computing devices, provides complete cloud privacy protection with three important features. First, passwords are managed allowing every site to have a unique, complex password, and facilitating password changing on a regular, short schedule. Second, data — both in transit to the cloud storage provider, and at rest in their data centers is encrypted. This encryption allows for access only by you on your registered devices! Finally, Ohanae provides secure filesharing. When you need to share data with others, all the protections of cloud privacy protection can move right along with the data. Ohanae does this all without storing any keys or passwords anywhere (locally or in the cloud) — ensuring that there is no single point of compromise which would reveal your data to prying eyes.
There’s nothing wrong with storing your sensitive data in the cloud — just make sure to use Cloud Privacy Protection to safeguard yourself!
Wednesday, August 6, 2014
Unique Passwords for Internet Accounts
With the widely publicized compromise of 1.2 billion user accounts from almost a half a million different websites, one very popular question is what can the average internet user do to protect themselves.
The common recommendations are straightforward:
The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.
Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.
The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.
Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.
Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.
With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.
We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!
The common recommendations are straightforward:
- Use long, strong, and complex passwords
- Use different passwords for every website
- Change your passwords often, at least every six months
- Avoid storing sensitive information (passwords, social security numbers, or other identity information) online
The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.
Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.
The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.
Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.
Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.
With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.
We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!
Labels:
authentication,
best practices,
cloud,
cloud privacy,
cloud privacy protection,
compromise,
credentials,
password,
password manager,
passwords,
privacy,
privacy protection,
russian,
secure passwords,
security,
theft
Tuesday, July 29, 2014
Mobile, BYOD, and the Enterprise
The consumerization of the mobile and bring-your-own-device trends continues to gain exponential momentum in 2014. According to an infographic published this week in Information Week, 90% of employees use mobile phones at work, and 35% use personal tablets at work. Furthermore, employees use an average of 21 different apps at work. Although email remains the most often used, document-centric apps, including file sharing are now used by more than one in every five employees.
InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.
At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.
Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.
With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.
InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.
At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.
Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.
With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.
Sunday, June 1, 2014
TrueCrypt - What Now?
TrueCrypt, a package that supported on-the-fly encryption of file data through encrypted virtual disks, partitions, and entire file systems, was discontinued by its anonymous development team on May 28, 2014.
TrueCrypt served a definite need in the market place allowing sophisticated security-minded users to encrypt data locally. By moving TrueCrypt containers onto cloud providers like Dropbox and Box, TrueCrypt’s protective capabilities could be extended to the cloud. Although the anonymous fashion in which it was developed prevented standard certification that applies for most commercially developed software, a crowd-sourced effort to audit the software was in progress, and the encryption package had a public history of successful mitigation of attacks by sophisticated law enforcement agencies.
With its announcement, the TrueCrypt Foundation has suggested that equivalent filesystem encryption capabilities may be found natively in the operating systems for Windows (BitLocker) and MacOS (FileVault). However, these solutions do not fully replace the on-the-fly type encryption that TrueCrypt provided for users storing data off their local system, in the cloud.
For storage in the cloud, users can take advantage of Cloud Privacy Protection offerings. Ohanae Inc. is proud to offer previous TrueCrypt users an integrated solution for local storage and cloud based storage, with keys that are controlled (generated and used locally) by the end user. The Ohanae solution provides security for data at rest locally, in transit to cloud providers, and at rest in the cloud.
Migration from TrueCrypt to Ohanae is simple — with drag and drop or copy/paste functionality to move files from TrueCrypt containers into Ohanae Secure Drives. Ohanae pricing is attractive — with free use for single device users, and special referral bonuses to gain premium support for up to five years.
For further information, and to start securing your data locally and in the cloud with Ohanae, please refer to http://www.ohanae.com. For information on Ohanae’s referral program, please see http://www.ohanae.com/referral.
TrueCrypt served a definite need in the market place allowing sophisticated security-minded users to encrypt data locally. By moving TrueCrypt containers onto cloud providers like Dropbox and Box, TrueCrypt’s protective capabilities could be extended to the cloud. Although the anonymous fashion in which it was developed prevented standard certification that applies for most commercially developed software, a crowd-sourced effort to audit the software was in progress, and the encryption package had a public history of successful mitigation of attacks by sophisticated law enforcement agencies.
With its announcement, the TrueCrypt Foundation has suggested that equivalent filesystem encryption capabilities may be found natively in the operating systems for Windows (BitLocker) and MacOS (FileVault). However, these solutions do not fully replace the on-the-fly type encryption that TrueCrypt provided for users storing data off their local system, in the cloud.
For storage in the cloud, users can take advantage of Cloud Privacy Protection offerings. Ohanae Inc. is proud to offer previous TrueCrypt users an integrated solution for local storage and cloud based storage, with keys that are controlled (generated and used locally) by the end user. The Ohanae solution provides security for data at rest locally, in transit to cloud providers, and at rest in the cloud.
Migration from TrueCrypt to Ohanae is simple — with drag and drop or copy/paste functionality to move files from TrueCrypt containers into Ohanae Secure Drives. Ohanae pricing is attractive — with free use for single device users, and special referral bonuses to gain premium support for up to five years.
For further information, and to start securing your data locally and in the cloud with Ohanae, please refer to http://www.ohanae.com. For information on Ohanae’s referral program, please see http://www.ohanae.com/referral.
Thursday, April 17, 2014
Heartbleed and Cloud Privacy Protection
Cloud Privacy Protection software is fundamentally about protecting your data and logins in the cloud. The recently disclosed Heartbleed SSL vulnerability affected hundreds of thousands of websites, allowing attackers to gain access to user passwords on those sites.
As web site providers have patched their servers, removing the heartbleed vulnerability, affected users could safely change their password. This prevented further use if the password was compromised.
How Cloud Privacy Protection Helps
Although heartbleed was unique in its reach, bugs and vulnerabilities in authentication processes, worms, and viruses have a lengthy history. It’s reasonable to expect that further compromises may happen in the future. However, there are some steps that you can take to protect your private cloud data today.
A fully implemented Cloud Privacy Protection system shields data loss, protects against wide spread login loss, and mitigates the resolution if an exposure does occur.
Protect the Data
First, data should be protected by keys and passwords that are distinct from user login credentials. This ensures that data at rest (stored in the cloud) and data in transit (while being sent to the cloud or to your local devices) cannot be accessed simply through compromise of your login credentials. By utilizing a zero knowledge system, file encryption keys are never transmitted or stored on the cloud provider. This prevents file data from disclosure even if the cloud storage provider is fully compromised.
Limit the Exposure
Second, use individual passwords for each web site. This guarantees that a security compromise like heartbleed, that allowed retrieval of user credentials on an affected website, is limited to only that website. If the same password is reused for multiple websites, then a successful breach of one can be turned into a breach of all.
Ease the Pain
Finally, using a Cloud Privacy Protection system, once the initial exposure has passed, reissue passwords – while keeping them strong and unique to each website. This ensures that potential future login breaches are prevented.
Ohanae Can Help
Ohanae’s flagship offering provides full cloud privacy protection in a zero knowledge, multi-factor local authentication system. Ohanae encrypts data files (for storage or sharing) using keys which are never transmitted to other servers. Additionally, Ohanae provides strong password management with unique passwords for each application and website. Access to these passwords is through Ohanae’s patent-pending, local, multi-factor authentication system.
Sunday, September 8, 2013
Trust No One
The fundamental fabric of the Internet has been destroyed.
The U.S. National Security Agency (NSA) and intelligence agencies in allied countries have found ways to circumvent the encryption used on the Internet, according to stories published by the New York Times and the Guardian.
According to the reports, NSA and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies. In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it is incredibly destructive for the NSA to add flaws to such critical infrastructure. The NSA seems to be operating on the assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners.
It appears that any possible way that the NSA might have bypassed encryption was almost certainly due to faulty, incomplete or invalid key management processes or simple human error, rather than through the cryptography itself. The new revelations raise major concerns from Internet users over who they can trust. We should assume that all big companies are now in cahoots with the NSA and cannot be trusted. You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer.
Businesses are acutely sensitive to government information requests because they are also beholden to privacy laws, such as HIPAA and the Gramm-Leach-Bliley Act. So, in highly regulated industries, such as financial services and healthcare, businesses must strike a balance between government oversight and consumer privacy. They feel they cannot comply with local privacy laws and have their data subject to the Patriot Act.
The U.S. Electronic Communications Privacy Act of 1986 came along in the early days of the Internet. The act did not require government investigators to obtain a search warrant for requesting access to emails and messages that are stored in online repositories. In 2001, the Patriot Act further added to the authority of the federal government to search records under its "Library Records" provision, offering a wide range of personal material into which the government could delve.
At Ohanae, we believe that ultimate security and compliance boils down to being able to protect data and logins. Trying to control the device (especially BYOD), in many cases, is neither necessary nor sufficient. At the end of the day, if you have the ability to protect the data and make sure that your data is not leaking, you do not have to touch the rest of the device.
Ohanae® Cloud Privacy Protection is a patent pending technology for securing data and logins without requiring storage of any associated credentials by the user either locally or in the cloud. Users’ data is transparently encrypted in the cloud and locally on their devices, and passwords cannot be guessed, phished, or stolen with Ohanae’s sophisticated endpoint protection mechanism.
The U.S. National Security Agency (NSA) and intelligence agencies in allied countries have found ways to circumvent the encryption used on the Internet, according to stories published by the New York Times and the Guardian.
According to the reports, NSA and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies. In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it is incredibly destructive for the NSA to add flaws to such critical infrastructure. The NSA seems to be operating on the assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners.
It appears that any possible way that the NSA might have bypassed encryption was almost certainly due to faulty, incomplete or invalid key management processes or simple human error, rather than through the cryptography itself. The new revelations raise major concerns from Internet users over who they can trust. We should assume that all big companies are now in cahoots with the NSA and cannot be trusted. You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer.
Businesses are acutely sensitive to government information requests because they are also beholden to privacy laws, such as HIPAA and the Gramm-Leach-Bliley Act. So, in highly regulated industries, such as financial services and healthcare, businesses must strike a balance between government oversight and consumer privacy. They feel they cannot comply with local privacy laws and have their data subject to the Patriot Act.
The U.S. Electronic Communications Privacy Act of 1986 came along in the early days of the Internet. The act did not require government investigators to obtain a search warrant for requesting access to emails and messages that are stored in online repositories. In 2001, the Patriot Act further added to the authority of the federal government to search records under its "Library Records" provision, offering a wide range of personal material into which the government could delve.
At Ohanae, we believe that ultimate security and compliance boils down to being able to protect data and logins. Trying to control the device (especially BYOD), in many cases, is neither necessary nor sufficient. At the end of the day, if you have the ability to protect the data and make sure that your data is not leaking, you do not have to touch the rest of the device.
Ohanae® Cloud Privacy Protection is a patent pending technology for securing data and logins without requiring storage of any associated credentials by the user either locally or in the cloud. Users’ data is transparently encrypted in the cloud and locally on their devices, and passwords cannot be guessed, phished, or stolen with Ohanae’s sophisticated endpoint protection mechanism.
Subscribe to:
Posts (Atom)