Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Tuesday, September 13, 2016

U.S. officials investigating hacking into more state election systems


Witnessing the many destructive cyberattacks, it is now clear that nobody is safe. 


U.S. officials are expanding their investigation into the hacking of state election systems as officials believe more states beyond just Arizona and Illinois were affected, a government official has confirmed to CBS News. The U.S. believes that people working for the Russian government are behind the hack of internal emails at the Democratic National Committee, officials confirmed to CBS News.

Enterprise social networks could potentially replace email if implemented correctly


Salesforce Chatter has radically evolved to meet the increasing demands of enterprise collaboration. Chatter has delivers significant benefits for enterprise including increased productivity, engagement, visibility and responsiveness.

Contextual communications
Discussions grouped by Account, Opportunity or any other record give greater depth of understanding.

Sharing in groups
Create centers of excellence that are easily accessible for information and questions.

Sharing files
Unlike email, links to files are updated when a file is modified so you always get the latest version, categorized for easy searching.

Gauge feedback
Use polls to quickly gauge demand or get feedback from your user-base.

Prioritizing topics
 Understand what the pressing issues are with popular discussed topics bubbling to the top.

Influencers
Know who is really influencing the organization by understanding the influencers.

Communities
Involve your customers in conversations, leveraging groups and communities allowing for quick response to critical questions.

Leveraging the feed
Create a task, create a case… Salesforce’s vision is that users will be able to do everything from the feed.

Include Chatter Free users
Even users without a Salesforce license cane benefit from Chatter … for free!

Comply with regulations, maintain confidentiality, share with confidence


Companies need one platform to connect everything. The Salesforce App Cloud is trusted by customers worldwide to keep their most critical data secure. While the Salesforce App Cloud provides enterprise-grade security for content at rest, those protections stop the moment files are shared, emailed, or downloaded from the cloud. That’s where Ohanae steps in to protect your files anywhere they travel, giving you full visibility, control, and assisting your compliance with mandatory government regulations.

Ohanae is fully integrated into the Salesforce App Cloud. Ohanae delivers compliance management for files through secure file sharing in a whole new way. Ohanae protects passwords and data from any type of file, on all popular devices and in the cloud, and securely shares that with anyone. Ohanae is unique because it allows security to travel with shared files. This gives organizations full visibility and control over all communications.


Compliance Management for Files


Friday, August 21, 2015

Secure File Sharing in a Whole New Way

Now Everyone Gets to See Ashley Madison Data

Cyberattack. Your network is compromised. Hackers behind the Ashley Madison breach, the popular online dating website aimed at people hoping to cheat on their spouses, have dumped 9.7 gigabytes worth of stolen user account and payment information online. The hack includes corporate financial documents along with maps of Avid Life Media’s internal network. Trusted corporate networks no longer exist once the perimeter security is broken. Security tools such as firewalls, IPS systems, access controls, no longer protect your data. Mobile, cloud, IoT and APIs are creating a massive complexity that is rendering traditional modes of security ineffective. As your users, their devices, and applications move outside the safe and cozy confines of the corporate network, the old paradigm fails and a new approach is needed for secure collaboration and file sharing.

Moving to the Cloud

Each business has different needs and every business will reap distinct benefits from cloud solutions. Many CIOs hesitate to fully embrace a cloud-first approach. Their hesitation stems in part from an anxiety embracing a wide range of privacy and security related issues. Businesses want to retain control of their data and they want that data to be kept secure and private, all while maintaining transparency and assuring compliance.

The Need for Platform Encryption

Security and trust are major factors in every company’s evaluation of public cloud services such as the Salesforce Customer Success Platform. Companies will only use cloud providers who they greatly trust. They seek assurances that the privacy of their information and files will be highly protected; that their data will be used only in a way that is consistent with their expectations. Salesforce customers in particular are choosing which business functions to run on the Salesforce1 Platform, what applications they can build to extend those functions, and what data they need to store there to enable those functions. Customers increasingly use the Salesforce1 Platform to build applications that require PII and other sensitive, confidential, or proprietary data. Given the sensitive data stored on the Salesforce1 Platform, smart customers demand additional layers of protection beyond the standard security measures such as authentication, single sign-on, access controls, and activity monitoring as to when and how they protect their data.

Together We Deliver a Trusted Cloud

Besides platform encryption, private and shared files from enterprise social networks, file syncing and sharing, email attachments, network drives, physical USB flash drives, all these need file security with integrated access control as a last line of defense. Even if your network has been compromised by an advanced threat or by an insider and files have been leaked, your enterprise maintains visibility over those files, and ensures they are under your control. You may securely share files with anyone and retain complete tracking to see who accesses your files.

The Secure File Sharing Platform

Ohanae delivers secure file sharing in a whole new way. Unlike lesser solutions, Ohanae takes a two-prong approach to secure both your passwords and files through zero knowledge encryption. Ohanae’s unique system allows security to travel with shared files preserving the organization’s full visibility and control. Our patent-pending technology ensures passwords are not stored anywhere and are dynamically created and erased locally on your device. Ohanae is the secure file sharing platform for enterprise social networking, file syncing & sharing, making the sharing of files and passwords safer, faster, and more private. Ohanae allows users to easily create, share, and keep files in the cloud, yet permitting a secure and simple access from any device. The Ohanae solution is easy to install and use without any disruption to normal workflows. Users can download the Ohanae app from all the popular app stores. It’s easy, it’s powerful, and it’s here now!

Saturday, January 3, 2015

Corporate America, you've been hacked

Sony Cyberattack, First a Nuisance, Swiftly Grew Into a Firestorm. More than 100 terabytes of internal files and films had been stolen, internal data centers had been wiped clean, and 75 percent of the servers had been destroyed. The F.B.I. found that the hackers had used digital techniques to steal the credentials and passwords from a systems administrator who had maximum access to Sony’s computer systems. Once in control of the gateways, theft of the information was relatively easy.

As we bear witness to the destructive cyberattacks on Sony Pictures, it becomes clear that nobody is safe, we are entering an entirely new era of “cyber-vandalism”.  Those who do not implement cloud data protection will be the next ripe targets. Those who do not change their approach to cloud data protection will lose. The Sony hack has taught us so much. It’s taught us to send corporate email as if everyone is reading those emails. It’s taught us that people in Hollywood are just as mean as people in any other industry, with equally fragile reputation.   Bottom line: This hack is estimated to cost Sony $100 million after all is said and done, and jeopardizes executive careers.

Trust No One…Encrypt Everything

Cloud-First, Mobile-First era requires businesses to adopt the discipline of Trust No One, Encrypt Everything! The Sony hack could have been mitigated if these stolen files had been uniquely encrypted, with only the authorized users (internal/external) in the shared list (embedded in the document header) able to decrypt the files; and, most importantly, if the decryption could only be carried out from an authorized computer or mobile device.

Assume you’re Always under Attack

Enterprise IT is heavily relying on security features provided by cloud vendors but most of the SaaS vendors do not make security a first priority, and so they fail to provide sufficient data governance, data privacy, data sovereignty, and built-in compliance. CIOs and CISOs have realized that maintaining enterprise-grade security in cloud application usage is a shared responsibility, as traditional infrastructure security technologies that are based on the idea of perimeter defense have become obsolete. The perimeter is dead; mobile devices wounded it and the cloud finished it off. Applications today are mobile, so security must be built to move with them.

Ohanae develops security tools to facilitate secure document collaboration using enterprise social platforms, and file sync and share tools that are based on the core assumption that it is impossible to tell good from bad. Our security models focus on eliminating attack vectors, and move away from the never-ending battle of separating “good” from “bad”.

Secure Document Collaboration for Salesforce Users

Ohanae offers near boundless innovations for these new approaches by securing your files in Salesforce cloud, along with your Salesforce credentials. Unlike anyone else, Ohanae takes this two-prong approach to fully secure your data through zero knowledge encryption resulting in:
  • Easy to use secure file sharing via Chatter and Communities, Salesforce Files guest link, Skype, iMessage, email attachment, and USB flash drive.
  • Assurance that sensitive files in the Salesforce Files are encrypted and only you have the encryption key.
  • Access to unique complex passwords without the need to remember them.
  • Full-fledged logging in compliance with government regulations. Ohanae monitors your private and shared files uploaded/synced to the Salesforce cloud.

How it Works?

In cases of document sharing, files are encrypted using unique encryption keys which are associated with specific recipients. This allows other Salesforce users to receive encrypted files from you without their knowing any of your critical security data, while maintaining the same level of data security.

For private files in Salesforce Files, Ohanae transparently encrypts files using a highly secure key that is generated on each use and not stored on the device or in the cloud. This encryption prevents access to documents by unauthorized users who might compromise your cloud storage account.

Finally, the password management function ensures that your Salesforce credentials are unique. These unique, highly secure passwords are dynamically created and then erased locally from your desktop or mobile devices. They are never stored on either the device or in the cloud.

Pricing and Supported Platforms

Now available for download, Ohanae is free for single device use. Multi-device business use (up to 8 devices) costs $2 per user/month. Enterprise use costs $3 per user/month with a centralized management capability from an intuitive web interface. Ohanae supports Android, iOS, Windows Phone, Windows Store App, Windows Desktop and Macintosh, Chrome, Safari, Internet Explorer, and Firefox.

Thursday, August 21, 2014

Proactive BYOD

Throughout history, there are many examples of events that led to calamities. In hindsight, it’s often painfully obvious that they could have been predicted and prevented by proactive efforts. Bring-Your-Own-Device, often referred to by security officers as “bring your own disaster”, represents just such a sea change for enterprises. A new article in NetworkWorld discusses several surveys that show that BYOD is continuing unabated, and often, unapproved devices or apps are being actively hidden from hostile enterprise IT departments.

Organizational reaction to BYOD typically falls into one of three categories.

In some organizations, IT has mandated that there is no use of bring-your-own-devices or apps. In a very small number — for instance, military or government intelligence agencies — the organization has the ability to completely control all incoming and outgoing network access, and to enforce physical access to facilities by unauthorized devices, and the mandate works. For the vast majority of mandated companies, controls are company policies, and enforcement is by individual compliance. The Trackvia study finds that non-compliance with company guidelines is a significant problem, with almost 70% of younger workers admitting to doing so.

In other organizations, IT has recognized that mobile devices and apps are required to achieve peak employee performance, but have certified and approved specific devices and tools. TrackVia’s study finds this hasn’t worked either, with from 30 to 50% of specific employee age groups reporting they picked other devices or apps because the ones IT chose did not meet their needs.

CIOs in the last category understand that BYOD and BYOA use within their organization is inevitable, but struggle with the other harsh reality that by-and-large, employees just don’t care about security.

Clearly, employees drive organizations towards the third alternative, and organizational attempts to drive towards the first impact employee productivity and efficiency, and consume valuable IT funding and personnel resources.

Ohanae offers CIOs a better way to embrace the second and third choices. Ohanae’s Cloud Privacy Protection software suite allows enterprises to certify and support some third party applications and devices, or to be completely agnostic to apps and devices, against a secure backdrop. Ohanae software ensures that files are encrypted on devices and in the cloud, alleviating worries about data exposure on devices which are not certified, supported, or under management by an organization. Ohanae’s credential management system ensures that cloud based storage (and other cloud based apps) are accessed using secure, complex passwords that prevent account compromise and related data exposure. Ohanae’s secure file sharing allows users to collaboratively exchange data with industrial strength access mechanisms.

Ohanae Cloud Privacy Protection provides a safe environment for corporate data and credentials, and allows IT the time, freedom and safety to make the right choices for BYOD and BYOA that will keep IT users happy, productive and secure.

For more information, please see our videos: Cloud Compliance for Business and Cloud Compliance Policy.

Wednesday, August 6, 2014

Unique Passwords for Internet Accounts

With the widely publicized compromise of 1.2 billion user accounts from almost a half a million different websites, one very popular question is what can the average internet user do to protect themselves.

The common recommendations are straightforward:
  • Use long, strong, and complex passwords
  • Use different passwords for every website
  • Change your passwords often, at least every six months
  • Avoid storing sensitive information (passwords, social security numbers, or other identity information) online
These are the same, proactive recommendations that have been made for several years in response to password and credential breaches. However, historically users have been lax. For instance, among users directly affected by a large password attack, one survey found more than 1/3 of those users did not change their password at all. In 2013, the passwords “123456”, “12345678”, “password”, “qwerty”, and “abc123” continued to be the five most common passwords, just as they were in 2012 (see 2013's report here), even after many large, significant, and well publicized password thefts.

The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.

Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.

The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.

Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.

Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.

With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.

We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!

Tuesday, July 29, 2014

Mobile, BYOD, and the Enterprise

The consumerization of the mobile and bring-your-own-device trends continues to gain exponential momentum in 2014. According to an infographic published this week in Information Week, 90% of employees use mobile phones at work, and 35% use personal tablets at work. Furthermore, employees use an average of 21 different apps at work. Although email remains the most often used, document-centric apps, including file sharing are now used by more than one in every five employees.

InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.

At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.

Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.

With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.

Monday, July 21, 2014

Password Manager Security

A recent CSO Online article summarized the findings of a UC Berkeley research team, finding that five browser based password managers contained security flaws that could lead to the compromise of login credentials they were protecting.

The research team’s work outlines an evaluation of password managers against their primary directive of ensuring that stored passwords are only accessed by the authorized user and the website that the password is for. Unfortunately, their evaluation found all five password managers contained flaws in their implementation.

In order to evaluate the password managers, the research team looked at five main attack vectors.
  1. The password manager must maintain the integrity of the master account and password, making it impossible for an attacker to impersonate a valid user and retrieve credentials.
  2. The password manager must securely store the list of credentials. The storage mechanism must ensure confidentiality, integrity, and availability of the database. In particular, attackers should not be able to learn, modify, or delete credentials.
  3. If the password manager provides sharing of credentials between users, then appropriate safeguards must be taken to maintain collaborator security.
  4. The password manager must not operate in a way which allows user fingerprinting to happen. This would allow multiple, coordinated attacker websites to deduce identity information based on information passed between the websites by the password manager.
At Ohanae, we believe that password security is a key piece of our overall cloud privacy protection offering. We review some of the key vulnerabilities found, and how they apply with Ohanae below.

In the password managers surveyed, each provided a cloud based implementation that exposed the password store. In some implementations, the cloud-based password store was not encrypted, or data for the password store (usernames and passwords) were sent in the clear to the server in the cloud.

Ohanae does not store passwords in the cloud, or on local devices. Other credential information (domain and username) are stored on the local device, and passed through the cloud (for synchronization with other devices), but is encrypted during transmission and while stored.

Passwords are generated on demand only on authorized devices by a user with the master passphrase. This provides two factor authentication on local devices, and ensures that there is no static store which can be attacked and decrypted.

Finally, the master passphrase is only used, and not transmitted, even between devices of the same user — using Ohanae’s patent pending technology to ensure that sensitive passwords and pass phrases are retained and used only on authorized end devices.

Many of the password managers surveyed used bookmarklet technology to allow web browsers on popular mobile computing platforms (iOS and Android) to directly retrieve credentials from their stores. Due to the untrusted execution environment of bookmarklets, they require special handling to ensure that only secure APIs are called.

Ohanae does not use bookmarklet technology. We use secure browser extensions where available (primarily on our PC and Mac implementations), and rely on user copy and paste for insecure environments (such as most mobile operating systems).

Furthermore, since we only provide username and password to login forms, we do not add any additional data to form submission which would allow any type of fingerprinting operation.

The researchers also mention vulnerability of password managers to phishing attacks. In particular, allowing attacker websites to open dialogs which ask for the password managers username and password. Since the Ohanae application does not run inside the browser, it is easy to differentiate an attacker prompt (in a web UI) from the valid client login prompt.

Finally, at the time of this writing, Ohanae software does not provide a mechanism for sharing passwords between users. However, this feature is part of our product vision and roadmap, and we’ll pay close attention to the UCB research team’s recommendations in this area.

Ohanae believes, as the research team states that “password managers provide tremendous security and usability benefits at minimal deployability costs”, and we appreciate the time and effort the research team has spent to analyze typical attack vectors and the current state of the password manager art.

Ohanae is committed to providing industrial strength security in all three parts of our complete cloud privacy protection offering: securing login credentials, securing data in-motion and at-rest in cloud storage providers, and securely and collaborative sharing data.

Tuesday, June 3, 2014

Ohanae supports Reset The Net

On June 5, 2014, individuals and organizations around the world will rally to support Fight For Freedom’s “Reset the Net” initiative. This effort suggests that users adopt tools that provide end-to-end encryption as one mechanism to counter mass surveillance efforts by government agencies.

Government entities like the United States’ National Security Agency (NSA) cast a wide net in their surveillance efforts. As country and world citizens, we all benefit from the legitimate success of these agencies — when they counter criminal or terrorist elements that intend harm to us. However, it’s important to find the right tradeoff between privacy and protection — a challenging question that the framers of US Constitution wrestled with over 200 years ago when writing the Fourth Amendment. Fight for Freedom advocates end-to-end encryption as a mechanism to counter passive, widespread, un-targeted surveillance and preserve personal privacy, while allowing government agencies to continue the targeted surveillance of specific individuals or organizations that pose a threat to their citizens.

But, government agencies are not the only entities in the unprotected seas of the internet. Russian hacker Evgeniy Bogachev was identified Monday as the leader of a vast group of internet criminals that compromised hundreds of thousands of computers, leading to over $100 million in identified losses to date.

A recent United States federal lawsuit against a popular cloud and email provider asserted that email sent through the cloud provider’s servers had been scanned and indexed in order to provide targeted ads. Indeed, the privacy policies of all the major cloud providers usually contain language that allows the provider to “use” data uploaded to their services to generate derivative services.

The end-to-end encryption recommendations of the Fight for Freedom’s Reset the Net are important because they help individuals and companies ensure that their data is ONLY used for approved purposes. It helps us set a fair and reasonable bar for the tradeoff between privacy and legitimately beneficial services (in the case of government agencies and service providers). And it protects us without compromise for dangerous, criminal elements that inhabit the Internet in abundance.

Ohanae is proud to support the Reset the Net initiative with Ohanae's cloud privacy protection software. Our software provides end-to-end encryption for data at rest locally, during transmission to cloud storage, and at rest in the cloud. It prevents unauthorized use by ANYONE except the owner at all points. Ohanae also provides secure file sharing for similar protection when you need to collaborate with others, and secure password management to protect against damaging account compromises.

Ohanae software is free for the first device, and available on iOS, Android, Windows, and Mac OS. Through referral bonuses, up to five complimentary years of premium service may be easily earned. Please navigate to http://www.ohanae.com to learn more about Ohanae and get started today!

Thursday, April 17, 2014

Heartbleed and Cloud Privacy Protection

Cloud Privacy Protection software is fundamentally about protecting your data and logins in the cloud. The recently disclosed Heartbleed SSL vulnerability affected hundreds of thousands of websites, allowing attackers to gain access to user passwords on those sites.

As web site providers have patched their servers, removing the heartbleed vulnerability, affected users could safely change their password. This prevented further use if the password was compromised.

How Cloud Privacy Protection Helps

Although heartbleed was unique in its reach, bugs and vulnerabilities in authentication processes, worms, and viruses have a lengthy history. It’s reasonable to expect that further compromises may happen in the future. However, there are some steps that you can take to protect your private cloud data today.

A fully implemented Cloud Privacy Protection system shields data loss, protects against wide spread login loss, and mitigates the resolution if an exposure does occur.

Protect the Data

First, data should be protected by keys and passwords that are distinct from user login credentials. This ensures that data at rest (stored in the cloud) and data in transit (while being sent to the cloud or to your local devices) cannot be accessed simply through compromise of your login credentials.  By utilizing a zero knowledge system,  file encryption keys are never transmitted or stored on the cloud provider. This prevents file data from disclosure even if the cloud storage provider is fully compromised.

Limit the Exposure

Second, use individual passwords for each web site. This guarantees that a security compromise like heartbleed, that allowed retrieval of user credentials on an affected website, is limited to only that website. If the same password is reused for multiple websites, then a successful breach of one can be turned into a breach of all.

Ease the Pain

Finally, using a Cloud Privacy Protection system, once the initial exposure has passed, reissue passwords – while keeping them strong and unique to each website. This ensures that potential future login breaches are prevented.

Ohanae Can Help

Ohanae’s flagship offering provides full cloud privacy protection in a zero knowledge, multi-factor local authentication system. Ohanae encrypts data files (for storage or sharing) using keys which are never transmitted to other servers. Additionally, Ohanae provides strong password management with unique passwords for each application and website. Access to these passwords is through Ohanae’s patent-pending, local, multi-factor authentication system.

Sunday, September 8, 2013

Trust No One

The fundamental fabric of the Internet has been destroyed.

The U.S. National Security Agency (NSA) and intelligence agencies in allied countries have found ways to circumvent the encryption used on the Internet, according to stories published by the New York Times and the Guardian.

According to the reports, NSA and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies. In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it is incredibly destructive for the NSA to add flaws to such critical infrastructure. The NSA seems to be operating on the assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners.

It appears that any possible way that the NSA might have bypassed encryption was almost certainly due to faulty, incomplete or invalid key management processes or simple human error, rather than through the cryptography itself. The new revelations raise major concerns from Internet users over who they can trust. We should assume that all big companies are now in cahoots with the NSA and cannot be trusted. You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer.

Businesses are acutely sensitive to government information requests because they are also beholden to privacy laws, such as HIPAA and the Gramm-Leach-Bliley Act. So, in highly regulated industries, such as financial services and healthcare, businesses must strike a balance between government oversight and consumer privacy. They feel they cannot comply with local privacy laws and have their data subject to the Patriot Act.

The U.S. Electronic Communications Privacy Act of 1986 came along in the early days of the Internet. The act did not require government investigators to obtain a search warrant for requesting access to emails and messages that are stored in online repositories. In 2001, the Patriot Act further added to the authority of the federal government to search records under its "Library Records" provision, offering a wide range of personal material into which the government could delve.

At Ohanae, we believe that ultimate security and compliance boils down to being able to protect data and logins. Trying to control the device (especially BYOD), in many cases, is neither necessary nor sufficient. At the end of the day, if you have the ability to protect the data and make sure that your data is not leaking, you do not have to touch the rest of the device.

Ohanae® Cloud Privacy Protection is a patent pending technology for securing data and logins without requiring storage of any associated credentials by the user either locally or in the cloud. Users’ data is transparently encrypted in the cloud and locally on their devices, and passwords cannot be guessed, phished, or stolen with Ohanae’s sophisticated endpoint protection mechanism.