Showing posts with label ohanae. Show all posts
Showing posts with label ohanae. Show all posts

Tuesday, September 13, 2016

U.S. officials investigating hacking into more state election systems


Witnessing the many destructive cyberattacks, it is now clear that nobody is safe. 


U.S. officials are expanding their investigation into the hacking of state election systems as officials believe more states beyond just Arizona and Illinois were affected, a government official has confirmed to CBS News. The U.S. believes that people working for the Russian government are behind the hack of internal emails at the Democratic National Committee, officials confirmed to CBS News.

Enterprise social networks could potentially replace email if implemented correctly


Salesforce Chatter has radically evolved to meet the increasing demands of enterprise collaboration. Chatter has delivers significant benefits for enterprise including increased productivity, engagement, visibility and responsiveness.

Contextual communications
Discussions grouped by Account, Opportunity or any other record give greater depth of understanding.

Sharing in groups
Create centers of excellence that are easily accessible for information and questions.

Sharing files
Unlike email, links to files are updated when a file is modified so you always get the latest version, categorized for easy searching.

Gauge feedback
Use polls to quickly gauge demand or get feedback from your user-base.

Prioritizing topics
 Understand what the pressing issues are with popular discussed topics bubbling to the top.

Influencers
Know who is really influencing the organization by understanding the influencers.

Communities
Involve your customers in conversations, leveraging groups and communities allowing for quick response to critical questions.

Leveraging the feed
Create a task, create a case… Salesforce’s vision is that users will be able to do everything from the feed.

Include Chatter Free users
Even users without a Salesforce license cane benefit from Chatter … for free!

Comply with regulations, maintain confidentiality, share with confidence


Companies need one platform to connect everything. The Salesforce App Cloud is trusted by customers worldwide to keep their most critical data secure. While the Salesforce App Cloud provides enterprise-grade security for content at rest, those protections stop the moment files are shared, emailed, or downloaded from the cloud. That’s where Ohanae steps in to protect your files anywhere they travel, giving you full visibility, control, and assisting your compliance with mandatory government regulations.

Ohanae is fully integrated into the Salesforce App Cloud. Ohanae delivers compliance management for files through secure file sharing in a whole new way. Ohanae protects passwords and data from any type of file, on all popular devices and in the cloud, and securely shares that with anyone. Ohanae is unique because it allows security to travel with shared files. This gives organizations full visibility and control over all communications.


Compliance Management for Files


Wednesday, June 15, 2016

Extending the Boundary of the World’s Most Trusted Enterprise Cloud

Ohanae empowers companies to share files securely with anyone in a whole new way



Trust is Our #1 Value

Companies need one platform to connect everything.  Ohanae is fully integrated into the Salesforce platform.  The Salesforce platform is trusted by customers worldwide to keep their most critical data secure.  While the Salesforce platform provides enterprise-grade security for content at rest, those protections stop the moment files are shared, emailed, or downloaded from the cloud.  That’s where Ohanae steps in to protect your files anywhere they travel, giving you full visibility, control, and assisting your compliance with mandatory government regulations.  With Ohanae, your business can be more productive and agile, and deliver new levels of trust.


Secure content beyond Salesforce, in mobile devices, email, social, and file shares

Organizations share information.  The reality today is that files are usually stored and shared in cleartext, unencrypted, with no visibility and no control.  The majority of users lack access to, or ignore encryption capabilities, as they create and share their files. With Ohanae, whether your employees are emailing sensitive attachments, passing around financial models on easily-lost USB flash drives, or are using unsanctioned cloud storage tools, you can be confident that all internal and external collaborations are secure.

Secure File Sharing with Anyone in a Whole New Way

Ohanae secures file sharing service for Salesforce Chatter enterprise social network, Salesforce Files and file synchronization & sharing tools (Box, Dropbox, Google Drive, OneDrive), and email attachments to make the sharing of files and passwords safer, faster, and more private.  Ohanae is unique because it allows security to travel with shared files. This gives organizations full visibility and control over all communications. Once a document is protected, even if it is copied on a USB flash drive, stored on your laptop or on your mobile phone, stored in any cloud provider’s storage of your choice, the document carries the same protection. Ohanae goes further than typical encryption technology by adding policies and yet, Ohanae never has access to the data.


Ohanae for Salesforce Summer ’16 Release

  • Secures the flow of protected files resident on all user’s devices, as well as those in the cloud. Ohanae encrypts all important file types, then lets these files be used by everyone in a user’s collaboration group (not just within the user’s organization).  In short, users can now securely share any content with anyone, whether they are inside the group, or not. Outsiders can sign up for a free Ohanae Personal account. This offer lets the users external to the organization consume and produce protected content on a single device of their choice (Personal Premium subscriptions are also available @ $2 per user/month with multiple devices support).
  • Logical role-based access control (Company, Role, Group, User) based on Salesforce Identity with additional universal rights management powers such as document tracking, revocation, and limited-time access support.  
  • The easy to use mobile sharing app can be downloaded from popular app stores (Apple App Store, Google Play, and Windows Store).  The desktop sharing app (Windows Desktop, and Mac OS) is designed for experienced users who require added functionalities.    An Ohanae for Salesforce managed package can be downloaded today from the Salesforce AppExchange.
  • Enterprises can designate specific folders within Salesforce Files, Box, Dropbox, Google Drive, OneDrive and automatically extend extra protection and data control to documents placed in those folders. Then, as those files are shared, downloaded, or emailed, Ohanae’s protection follows the files wherever they go. For businesses who are highly collaborative externally, this is a great way to ensure protection of content that extends beyond the usual shadow-IT file synchronization and sharing tools.
  • Trust is achieved when security is paired with visibility and control. When files are emailed outside of an organization, or downloaded from a shared link, enterprise protections are often lost.  By protecting files with Ohanae, you always retain the ability to see exactly where that file has traveled, who has accessed it, even when   an unauthorized access is attempted.
  • Ohanae permits you to instantly revoke access to files and devices:  It’s like having a recall button that actually works.

To experience how you can empower your company to share its files securely with anyone in a whole new way, try out Ohanae for Salesforce, it’s available on the AppExchange today.

Friday, August 21, 2015

Secure File Sharing in a Whole New Way

Now Everyone Gets to See Ashley Madison Data

Cyberattack. Your network is compromised. Hackers behind the Ashley Madison breach, the popular online dating website aimed at people hoping to cheat on their spouses, have dumped 9.7 gigabytes worth of stolen user account and payment information online. The hack includes corporate financial documents along with maps of Avid Life Media’s internal network. Trusted corporate networks no longer exist once the perimeter security is broken. Security tools such as firewalls, IPS systems, access controls, no longer protect your data. Mobile, cloud, IoT and APIs are creating a massive complexity that is rendering traditional modes of security ineffective. As your users, their devices, and applications move outside the safe and cozy confines of the corporate network, the old paradigm fails and a new approach is needed for secure collaboration and file sharing.

Moving to the Cloud

Each business has different needs and every business will reap distinct benefits from cloud solutions. Many CIOs hesitate to fully embrace a cloud-first approach. Their hesitation stems in part from an anxiety embracing a wide range of privacy and security related issues. Businesses want to retain control of their data and they want that data to be kept secure and private, all while maintaining transparency and assuring compliance.

The Need for Platform Encryption

Security and trust are major factors in every company’s evaluation of public cloud services such as the Salesforce Customer Success Platform. Companies will only use cloud providers who they greatly trust. They seek assurances that the privacy of their information and files will be highly protected; that their data will be used only in a way that is consistent with their expectations. Salesforce customers in particular are choosing which business functions to run on the Salesforce1 Platform, what applications they can build to extend those functions, and what data they need to store there to enable those functions. Customers increasingly use the Salesforce1 Platform to build applications that require PII and other sensitive, confidential, or proprietary data. Given the sensitive data stored on the Salesforce1 Platform, smart customers demand additional layers of protection beyond the standard security measures such as authentication, single sign-on, access controls, and activity monitoring as to when and how they protect their data.

Together We Deliver a Trusted Cloud

Besides platform encryption, private and shared files from enterprise social networks, file syncing and sharing, email attachments, network drives, physical USB flash drives, all these need file security with integrated access control as a last line of defense. Even if your network has been compromised by an advanced threat or by an insider and files have been leaked, your enterprise maintains visibility over those files, and ensures they are under your control. You may securely share files with anyone and retain complete tracking to see who accesses your files.

The Secure File Sharing Platform

Ohanae delivers secure file sharing in a whole new way. Unlike lesser solutions, Ohanae takes a two-prong approach to secure both your passwords and files through zero knowledge encryption. Ohanae’s unique system allows security to travel with shared files preserving the organization’s full visibility and control. Our patent-pending technology ensures passwords are not stored anywhere and are dynamically created and erased locally on your device. Ohanae is the secure file sharing platform for enterprise social networking, file syncing & sharing, making the sharing of files and passwords safer, faster, and more private. Ohanae allows users to easily create, share, and keep files in the cloud, yet permitting a secure and simple access from any device. The Ohanae solution is easy to install and use without any disruption to normal workflows. Users can download the Ohanae app from all the popular app stores. It’s easy, it’s powerful, and it’s here now!

Saturday, January 3, 2015

Corporate America, you've been hacked

Sony Cyberattack, First a Nuisance, Swiftly Grew Into a Firestorm. More than 100 terabytes of internal files and films had been stolen, internal data centers had been wiped clean, and 75 percent of the servers had been destroyed. The F.B.I. found that the hackers had used digital techniques to steal the credentials and passwords from a systems administrator who had maximum access to Sony’s computer systems. Once in control of the gateways, theft of the information was relatively easy.

As we bear witness to the destructive cyberattacks on Sony Pictures, it becomes clear that nobody is safe, we are entering an entirely new era of “cyber-vandalism”.  Those who do not implement cloud data protection will be the next ripe targets. Those who do not change their approach to cloud data protection will lose. The Sony hack has taught us so much. It’s taught us to send corporate email as if everyone is reading those emails. It’s taught us that people in Hollywood are just as mean as people in any other industry, with equally fragile reputation.   Bottom line: This hack is estimated to cost Sony $100 million after all is said and done, and jeopardizes executive careers.

Trust No One…Encrypt Everything

Cloud-First, Mobile-First era requires businesses to adopt the discipline of Trust No One, Encrypt Everything! The Sony hack could have been mitigated if these stolen files had been uniquely encrypted, with only the authorized users (internal/external) in the shared list (embedded in the document header) able to decrypt the files; and, most importantly, if the decryption could only be carried out from an authorized computer or mobile device.

Assume you’re Always under Attack

Enterprise IT is heavily relying on security features provided by cloud vendors but most of the SaaS vendors do not make security a first priority, and so they fail to provide sufficient data governance, data privacy, data sovereignty, and built-in compliance. CIOs and CISOs have realized that maintaining enterprise-grade security in cloud application usage is a shared responsibility, as traditional infrastructure security technologies that are based on the idea of perimeter defense have become obsolete. The perimeter is dead; mobile devices wounded it and the cloud finished it off. Applications today are mobile, so security must be built to move with them.

Ohanae develops security tools to facilitate secure document collaboration using enterprise social platforms, and file sync and share tools that are based on the core assumption that it is impossible to tell good from bad. Our security models focus on eliminating attack vectors, and move away from the never-ending battle of separating “good” from “bad”.

Secure Document Collaboration for Salesforce Users

Ohanae offers near boundless innovations for these new approaches by securing your files in Salesforce cloud, along with your Salesforce credentials. Unlike anyone else, Ohanae takes this two-prong approach to fully secure your data through zero knowledge encryption resulting in:
  • Easy to use secure file sharing via Chatter and Communities, Salesforce Files guest link, Skype, iMessage, email attachment, and USB flash drive.
  • Assurance that sensitive files in the Salesforce Files are encrypted and only you have the encryption key.
  • Access to unique complex passwords without the need to remember them.
  • Full-fledged logging in compliance with government regulations. Ohanae monitors your private and shared files uploaded/synced to the Salesforce cloud.

How it Works?

In cases of document sharing, files are encrypted using unique encryption keys which are associated with specific recipients. This allows other Salesforce users to receive encrypted files from you without their knowing any of your critical security data, while maintaining the same level of data security.

For private files in Salesforce Files, Ohanae transparently encrypts files using a highly secure key that is generated on each use and not stored on the device or in the cloud. This encryption prevents access to documents by unauthorized users who might compromise your cloud storage account.

Finally, the password management function ensures that your Salesforce credentials are unique. These unique, highly secure passwords are dynamically created and then erased locally from your desktop or mobile devices. They are never stored on either the device or in the cloud.

Pricing and Supported Platforms

Now available for download, Ohanae is free for single device use. Multi-device business use (up to 8 devices) costs $2 per user/month. Enterprise use costs $3 per user/month with a centralized management capability from an intuitive web interface. Ohanae supports Android, iOS, Windows Phone, Windows Store App, Windows Desktop and Macintosh, Chrome, Safari, Internet Explorer, and Firefox.

Thursday, August 21, 2014

Ohanae Goes to College

The Whitehat Society, a special interest group dedicated to issues around cyber security at Singapore Management University, recently organized an Ohanae use case competition. Participation was fantastic, with numerous innovative entries submitted for the “Trust No One” essay competition. Lim Yi Shen and Lim Jun Yan claimed the top awards – each winning a Microsoft Surface 2, complete with a sleek keyboard and sleeve.


Meet the Winners




I am a freelance designer and am working on various Kickstarter projects. Ohanae helps me in my work with its device-centric combined solution for both login and data protection that helps my team collaborate better. With Ohanae, I can conveniently keep using the wide range of cloud service providers, like Dropbox, Google Drive, OneDrive, and Box, without the fear of having my credentials, and hence data, compromised by malicious users. Ohanae also helps me protect my intellectual property rights against plagiarism by maintaining control of my files with information segregation done as simply as clicking to encrypt and decrypt.” – Lim Yi Sheng




As a student, I use multiple devices like phone, laptop and tablet, and need to manage numerous accounts. Ohanae keeps my data out of reach from anybody but me, allowing me to fully utilize the convenience and flexibility of popular cloud service providers for personal and work-related storage. I realized Ohanae Cloud Privacy Protection’s simplicity and comprehensive coverage of local and cloud storage, on all major OSes during my internship in a large scale company, as it struggled to protect its private corporate information. Indeed, in a world when you can trust no one, a thoughtful all-rounded defence by Ohanae is your best bet.” – Lim Jun Yan

Tuesday, July 29, 2014

Mobile, BYOD, and the Enterprise

The consumerization of the mobile and bring-your-own-device trends continues to gain exponential momentum in 2014. According to an infographic published this week in Information Week, 90% of employees use mobile phones at work, and 35% use personal tablets at work. Furthermore, employees use an average of 21 different apps at work. Although email remains the most often used, document-centric apps, including file sharing are now used by more than one in every five employees.

InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.

At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.

Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.

With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.

Wednesday, July 23, 2014

Two Factor Authentication Strength

Recent articles have suggested that password strength in some situations is not important. For instance, a recent Network World article asserted that the weakest and most well known password “123456” could have a place in an overall password strategy.

Another area where weak passwords are sometimes advocated is in combination with a two factor authentication (2FA) scheme. Two factor authentication combines two different pieces of information in order to establish access for a user. Typically, the two pieces come from two of the categories: something the user knows, something the user has, and something the user is. In most common, widely used schemes, the two factors are something the user knows (either a password or a PIN) and something the user has (a magnetic card, a secure token, or a specific device).

Adding a second factor certainly increases the security of a system. One could argue that you could decrease the first factor to offset that gain if the original system was secure enough. Taken to the extreme, if the second factor was stronger than the first, you could make the first trivially easy and still be better off. In that case, you would essentially be using a single factor system, just with the stronger factor.

Those are the keys to determining how much relaxation of one factor you can accommodate by adding a second factor: how strong is the second factor, how resilient is the system, and how independent are the two factors? How important is increasing the overall security of the system?

The classic two factor authentication system - a bank card and associated PIN works well. Both factors are strong. The card requires theft of a physical item to compromise it. The PIN (although only a 4-6 digit code) is usually strong because there is a lack of automated methodologies for attacking the PIN — it requires manually entering codes over and over at a banking machine. Furthermore, limitations on the number of wrong entries in a time period prevent effective brute forcing of the PIN. Systems are typically resilient — because there are not other attack modes beyond actual use of the card.

However, the card system can be compromised by poor choices. For instance, selecting trivial PINs like 1234, 0000, or other easily determined information makes it so that theft of the card is the only real attack required. Trivial PINs turn the two factor system in one factor, where possession of the card is the only block. Similarly, writing the PIN on the card so that the two factors are no longer independent (by compromising the card, you gain the PIN) also negates the benefits of the two factor system.

The final question is how important is increasing the overall security of the system. At Ohanae, we feel that passwords should always be strong, secure, and unique. If you need a password, then you want the best — whether it’s to secure less important websites, or as one piece of a multi-factor authentication scheme. Password compromise inevitably leads to information that can make secondary identity attacks easier and more successful. Your identity, accounts, and data integrity rest on preventing all attacks, and a weak password can be the proverbial weakest link that unravels the strongest chain of protection.

Ohanae’s cloud privacy protection solution gives users on all their devices the ability to quickly and easily use strong, secure, unique passwords on each website and application they use.

Monday, June 9, 2014

Singapore IDA Recommends Complex, Secure Passwords

Last week’s news about unauthorized password resets in the SingPass system (see the story here) reinforced the main cautions around passwords. Jacqueline Poh, Managing Director of Singapore’s Infocomm Development Authority recommended that all individuals use strong complex passwords with a variety of characters, including letters and numbers. The IDA went on to recommend other security best practices, including clearing browser caches after use, and changing passwords on a regular basis.

Ohanae software helps protect passwords against compromise. Ohanae users may select long passwords with upper case letters, lower case letters, numbers, and special characters and can be easily changed on a regular basis. Furthermore, Ohanae generates unique passwords for each site or application. Since Ohanae generates these passwords on use, they are never stored on any device, and users are spared the challenge of remembering many complex passwords. Finally, Ohanae implements browser cache and history clearing on laptop and desktop devices.

Ohanae’s Cloud Privacy Protection offering provides password security, but also provides secure encryption of files on device, in transit, and in the cloud as well as secure file sharing. This three-fold offering provides strong protection of both data and logins in the cloud, and is available now for Macintosh, Windows, Android and iOS.

Tuesday, June 3, 2014

Ohanae supports Reset The Net

On June 5, 2014, individuals and organizations around the world will rally to support Fight For Freedom’s “Reset the Net” initiative. This effort suggests that users adopt tools that provide end-to-end encryption as one mechanism to counter mass surveillance efforts by government agencies.

Government entities like the United States’ National Security Agency (NSA) cast a wide net in their surveillance efforts. As country and world citizens, we all benefit from the legitimate success of these agencies — when they counter criminal or terrorist elements that intend harm to us. However, it’s important to find the right tradeoff between privacy and protection — a challenging question that the framers of US Constitution wrestled with over 200 years ago when writing the Fourth Amendment. Fight for Freedom advocates end-to-end encryption as a mechanism to counter passive, widespread, un-targeted surveillance and preserve personal privacy, while allowing government agencies to continue the targeted surveillance of specific individuals or organizations that pose a threat to their citizens.

But, government agencies are not the only entities in the unprotected seas of the internet. Russian hacker Evgeniy Bogachev was identified Monday as the leader of a vast group of internet criminals that compromised hundreds of thousands of computers, leading to over $100 million in identified losses to date.

A recent United States federal lawsuit against a popular cloud and email provider asserted that email sent through the cloud provider’s servers had been scanned and indexed in order to provide targeted ads. Indeed, the privacy policies of all the major cloud providers usually contain language that allows the provider to “use” data uploaded to their services to generate derivative services.

The end-to-end encryption recommendations of the Fight for Freedom’s Reset the Net are important because they help individuals and companies ensure that their data is ONLY used for approved purposes. It helps us set a fair and reasonable bar for the tradeoff between privacy and legitimately beneficial services (in the case of government agencies and service providers). And it protects us without compromise for dangerous, criminal elements that inhabit the Internet in abundance.

Ohanae is proud to support the Reset the Net initiative with Ohanae's cloud privacy protection software. Our software provides end-to-end encryption for data at rest locally, during transmission to cloud storage, and at rest in the cloud. It prevents unauthorized use by ANYONE except the owner at all points. Ohanae also provides secure file sharing for similar protection when you need to collaborate with others, and secure password management to protect against damaging account compromises.

Ohanae software is free for the first device, and available on iOS, Android, Windows, and Mac OS. Through referral bonuses, up to five complimentary years of premium service may be easily earned. Please navigate to http://www.ohanae.com to learn more about Ohanae and get started today!

Sunday, June 1, 2014

TrueCrypt - What Now?

TrueCrypt, a package that supported on-the-fly encryption of file data through encrypted virtual disks, partitions, and entire file systems, was discontinued by its anonymous development team on May 28, 2014.

TrueCrypt served a definite need in the market place allowing sophisticated security-minded users to encrypt data locally. By moving TrueCrypt containers onto cloud providers like Dropbox and Box, TrueCrypt’s protective capabilities could be extended to the cloud. Although the anonymous fashion in which it was developed prevented standard certification that applies for most commercially developed software, a crowd-sourced effort to audit the software was in progress, and the encryption package had a public history of successful mitigation of attacks by sophisticated law enforcement agencies.

With its announcement, the TrueCrypt Foundation has suggested that equivalent filesystem encryption capabilities may be found natively in the operating systems for Windows (BitLocker) and MacOS (FileVault). However, these solutions do not fully replace the on-the-fly type encryption that TrueCrypt provided for users storing data off their local system, in the cloud.

For storage in the cloud, users can take advantage of Cloud Privacy Protection offerings. Ohanae Inc. is proud to offer previous TrueCrypt users an integrated solution for local storage and cloud based storage, with keys that are controlled (generated and used locally) by the end user. The Ohanae solution provides security for data at rest locally, in transit to cloud providers, and at rest in the cloud.

Migration from TrueCrypt to Ohanae is simple — with drag and drop or copy/paste functionality to move files from TrueCrypt containers into Ohanae Secure Drives. Ohanae pricing is attractive — with free use for single device users, and special referral bonuses to gain premium support for up to five years.

For further information, and to start securing your data locally and in the cloud with Ohanae, please refer to http://www.ohanae.com. For information on Ohanae’s referral program, please see http://www.ohanae.com/referral.

Thursday, April 17, 2014

Heartbleed and Cloud Privacy Protection

Cloud Privacy Protection software is fundamentally about protecting your data and logins in the cloud. The recently disclosed Heartbleed SSL vulnerability affected hundreds of thousands of websites, allowing attackers to gain access to user passwords on those sites.

As web site providers have patched their servers, removing the heartbleed vulnerability, affected users could safely change their password. This prevented further use if the password was compromised.

How Cloud Privacy Protection Helps

Although heartbleed was unique in its reach, bugs and vulnerabilities in authentication processes, worms, and viruses have a lengthy history. It’s reasonable to expect that further compromises may happen in the future. However, there are some steps that you can take to protect your private cloud data today.

A fully implemented Cloud Privacy Protection system shields data loss, protects against wide spread login loss, and mitigates the resolution if an exposure does occur.

Protect the Data

First, data should be protected by keys and passwords that are distinct from user login credentials. This ensures that data at rest (stored in the cloud) and data in transit (while being sent to the cloud or to your local devices) cannot be accessed simply through compromise of your login credentials.  By utilizing a zero knowledge system,  file encryption keys are never transmitted or stored on the cloud provider. This prevents file data from disclosure even if the cloud storage provider is fully compromised.

Limit the Exposure

Second, use individual passwords for each web site. This guarantees that a security compromise like heartbleed, that allowed retrieval of user credentials on an affected website, is limited to only that website. If the same password is reused for multiple websites, then a successful breach of one can be turned into a breach of all.

Ease the Pain

Finally, using a Cloud Privacy Protection system, once the initial exposure has passed, reissue passwords – while keeping them strong and unique to each website. This ensures that potential future login breaches are prevented.

Ohanae Can Help

Ohanae’s flagship offering provides full cloud privacy protection in a zero knowledge, multi-factor local authentication system. Ohanae encrypts data files (for storage or sharing) using keys which are never transmitted to other servers. Additionally, Ohanae provides strong password management with unique passwords for each application and website. Access to these passwords is through Ohanae’s patent-pending, local, multi-factor authentication system.

Sunday, September 8, 2013

Trust No One

The fundamental fabric of the Internet has been destroyed.

The U.S. National Security Agency (NSA) and intelligence agencies in allied countries have found ways to circumvent the encryption used on the Internet, according to stories published by the New York Times and the Guardian.

According to the reports, NSA and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies. In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it is incredibly destructive for the NSA to add flaws to such critical infrastructure. The NSA seems to be operating on the assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners.

It appears that any possible way that the NSA might have bypassed encryption was almost certainly due to faulty, incomplete or invalid key management processes or simple human error, rather than through the cryptography itself. The new revelations raise major concerns from Internet users over who they can trust. We should assume that all big companies are now in cahoots with the NSA and cannot be trusted. You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer.

Businesses are acutely sensitive to government information requests because they are also beholden to privacy laws, such as HIPAA and the Gramm-Leach-Bliley Act. So, in highly regulated industries, such as financial services and healthcare, businesses must strike a balance between government oversight and consumer privacy. They feel they cannot comply with local privacy laws and have their data subject to the Patriot Act.

The U.S. Electronic Communications Privacy Act of 1986 came along in the early days of the Internet. The act did not require government investigators to obtain a search warrant for requesting access to emails and messages that are stored in online repositories. In 2001, the Patriot Act further added to the authority of the federal government to search records under its "Library Records" provision, offering a wide range of personal material into which the government could delve.

At Ohanae, we believe that ultimate security and compliance boils down to being able to protect data and logins. Trying to control the device (especially BYOD), in many cases, is neither necessary nor sufficient. At the end of the day, if you have the ability to protect the data and make sure that your data is not leaking, you do not have to touch the rest of the device.

Ohanae® Cloud Privacy Protection is a patent pending technology for securing data and logins without requiring storage of any associated credentials by the user either locally or in the cloud. Users’ data is transparently encrypted in the cloud and locally on their devices, and passwords cannot be guessed, phished, or stolen with Ohanae’s sophisticated endpoint protection mechanism.