Friday, August 21, 2015
Saturday, January 3, 2015
Corporate America, you've been hacked
Sony Cyberattack, First a Nuisance, Swiftly Grew Into a Firestorm. More than 100 terabytes of internal files and films had been stolen, internal data centers had been wiped clean, and 75 percent of the servers had been destroyed. The F.B.I. found that the hackers had used digital techniques to steal the credentials and passwords from a systems administrator who had maximum access to Sony’s computer systems. Once in control of the gateways, theft of the information was relatively easy.
As we bear witness to the destructive cyberattacks on Sony Pictures, it becomes clear that nobody is safe, we are entering an entirely new era of “cyber-vandalism”. Those who do not implement cloud data protection will be the next ripe targets. Those who do not change their approach to cloud data protection will lose. The Sony hack has taught us so much. It’s taught us to send corporate email as if everyone is reading those emails. It’s taught us that people in Hollywood are just as mean as people in any other industry, with equally fragile reputation. Bottom line: This hack is estimated to cost Sony $100 million after all is said and done, and jeopardizes executive careers.
Ohanae develops security tools to facilitate secure document collaboration using enterprise social platforms, and file sync and share tools that are based on the core assumption that it is impossible to tell good from bad. Our security models focus on eliminating attack vectors, and move away from the never-ending battle of separating “good” from “bad”.
For private files in Salesforce Files, Ohanae transparently encrypts files using a highly secure key that is generated on each use and not stored on the device or in the cloud. This encryption prevents access to documents by unauthorized users who might compromise your cloud storage account.
Finally, the password management function ensures that your Salesforce credentials are unique. These unique, highly secure passwords are dynamically created and then erased locally from your desktop or mobile devices. They are never stored on either the device or in the cloud.
As we bear witness to the destructive cyberattacks on Sony Pictures, it becomes clear that nobody is safe, we are entering an entirely new era of “cyber-vandalism”. Those who do not implement cloud data protection will be the next ripe targets. Those who do not change their approach to cloud data protection will lose. The Sony hack has taught us so much. It’s taught us to send corporate email as if everyone is reading those emails. It’s taught us that people in Hollywood are just as mean as people in any other industry, with equally fragile reputation. Bottom line: This hack is estimated to cost Sony $100 million after all is said and done, and jeopardizes executive careers.
Trust No One…Encrypt Everything
Cloud-First, Mobile-First era requires businesses to adopt the discipline of Trust No One, Encrypt Everything! The Sony hack could have been mitigated if these stolen files had been uniquely encrypted, with only the authorized users (internal/external) in the shared list (embedded in the document header) able to decrypt the files; and, most importantly, if the decryption could only be carried out from an authorized computer or mobile device.Assume you’re Always under Attack
Enterprise IT is heavily relying on security features provided by cloud vendors but most of the SaaS vendors do not make security a first priority, and so they fail to provide sufficient data governance, data privacy, data sovereignty, and built-in compliance. CIOs and CISOs have realized that maintaining enterprise-grade security in cloud application usage is a shared responsibility, as traditional infrastructure security technologies that are based on the idea of perimeter defense have become obsolete. The perimeter is dead; mobile devices wounded it and the cloud finished it off. Applications today are mobile, so security must be built to move with them.Ohanae develops security tools to facilitate secure document collaboration using enterprise social platforms, and file sync and share tools that are based on the core assumption that it is impossible to tell good from bad. Our security models focus on eliminating attack vectors, and move away from the never-ending battle of separating “good” from “bad”.
Secure Document Collaboration for Salesforce Users
Ohanae offers near boundless innovations for these new approaches by securing your files in Salesforce cloud, along with your Salesforce credentials. Unlike anyone else, Ohanae takes this two-prong approach to fully secure your data through zero knowledge encryption resulting in:- Easy to use secure file sharing via Chatter and Communities, Salesforce Files guest link, Skype, iMessage, email attachment, and USB flash drive.
- Assurance that sensitive files in the Salesforce Files are encrypted and only you have the encryption key.
- Access to unique complex passwords without the need to remember them.
- Full-fledged logging in compliance with government regulations. Ohanae monitors your private and shared files uploaded/synced to the Salesforce cloud.
How it Works?
In cases of document sharing, files are encrypted using unique encryption keys which are associated with specific recipients. This allows other Salesforce users to receive encrypted files from you without their knowing any of your critical security data, while maintaining the same level of data security.For private files in Salesforce Files, Ohanae transparently encrypts files using a highly secure key that is generated on each use and not stored on the device or in the cloud. This encryption prevents access to documents by unauthorized users who might compromise your cloud storage account.
Finally, the password management function ensures that your Salesforce credentials are unique. These unique, highly secure passwords are dynamically created and then erased locally from your desktop or mobile devices. They are never stored on either the device or in the cloud.
Pricing and Supported Platforms
Now available for download, Ohanae is free for single device use. Multi-device business use (up to 8 devices) costs $2 per user/month. Enterprise use costs $3 per user/month with a centralized management capability from an intuitive web interface. Ohanae supports Android, iOS, Windows Phone, Windows Store App, Windows Desktop and Macintosh, Chrome, Safari, Internet Explorer, and Firefox.
Labels:
chatter,
cloud privacy,
cloud security,
encryption,
hack,
ohanae,
passwords,
privacy,
privacy protection,
salesforce,
Salesforce files,
secure document collaboration,
secure passwords,
security,
sony,
sony picture
Tuesday, September 2, 2014
It Could Happen to You
The recent, high profile compromise of several celebrities’ iCloud personal photo archives (see Jennifer Lawrence naked photos spark fear of mass celebrity hacking) reminds us of the inherent vulnerability of all cloud storage. Popular media now asks if Apple’s iCloud service is safe (see Is Apple's iCloud safe after leak of Jennifer Lawrence and other celebrities' nude photos), but the question should be even broader.
With massive consumer use of general file storage solutions like Dropbox, consumers should worry about compromise of these stores. The type of compromise that Jennifer Lawrence and other celebrities experienced could happen on any cloud storage provider — Dropbox, Box, Amazon Cloud Drive, Google Drive, Microsoft OneDrive, and, of course, iCloud.
As a first step, consumers must secure their access to cloud assets with strong, secure passwords which they change often. This minimizes the risk of an attacker directly accessing the consumer account using their legitimate credentials, and ensures that an attack which compromises one account can not spill over into other accounts.
However, mere password security is not enough as the celebrity iCloud compromise has shown. In this case, the compromise resulted from a flaw in Apple’s Find My iPhone feature, and did not require direct access to user credentials. In order to prevent this kind of compromise, consumers should use encryption to prevent access even when the attacker has possession of the data.
Cloud privacy protection tenants argue for both securing the access to the data (credentials) and the data itself (encryption). This allows users to store and share data in a world where they can’t trust anyone with safety, security, and without fear. Cloud data storage has revolutionized our ability to access data from anywhere, on any device, and it’s important to not let cyber criminals take that freedom from us.
Ohanae can help. Ohanae software, once installed on your mobile and computing devices, provides complete cloud privacy protection with three important features. First, passwords are managed allowing every site to have a unique, complex password, and facilitating password changing on a regular, short schedule. Second, data — both in transit to the cloud storage provider, and at rest in their data centers is encrypted. This encryption allows for access only by you on your registered devices! Finally, Ohanae provides secure filesharing. When you need to share data with others, all the protections of cloud privacy protection can move right along with the data. Ohanae does this all without storing any keys or passwords anywhere (locally or in the cloud) — ensuring that there is no single point of compromise which would reveal your data to prying eyes.
There’s nothing wrong with storing your sensitive data in the cloud — just make sure to use Cloud Privacy Protection to safeguard yourself!
With massive consumer use of general file storage solutions like Dropbox, consumers should worry about compromise of these stores. The type of compromise that Jennifer Lawrence and other celebrities experienced could happen on any cloud storage provider — Dropbox, Box, Amazon Cloud Drive, Google Drive, Microsoft OneDrive, and, of course, iCloud.
As a first step, consumers must secure their access to cloud assets with strong, secure passwords which they change often. This minimizes the risk of an attacker directly accessing the consumer account using their legitimate credentials, and ensures that an attack which compromises one account can not spill over into other accounts.
However, mere password security is not enough as the celebrity iCloud compromise has shown. In this case, the compromise resulted from a flaw in Apple’s Find My iPhone feature, and did not require direct access to user credentials. In order to prevent this kind of compromise, consumers should use encryption to prevent access even when the attacker has possession of the data.
Cloud privacy protection tenants argue for both securing the access to the data (credentials) and the data itself (encryption). This allows users to store and share data in a world where they can’t trust anyone with safety, security, and without fear. Cloud data storage has revolutionized our ability to access data from anywhere, on any device, and it’s important to not let cyber criminals take that freedom from us.
Ohanae can help. Ohanae software, once installed on your mobile and computing devices, provides complete cloud privacy protection with three important features. First, passwords are managed allowing every site to have a unique, complex password, and facilitating password changing on a regular, short schedule. Second, data — both in transit to the cloud storage provider, and at rest in their data centers is encrypted. This encryption allows for access only by you on your registered devices! Finally, Ohanae provides secure filesharing. When you need to share data with others, all the protections of cloud privacy protection can move right along with the data. Ohanae does this all without storing any keys or passwords anywhere (locally or in the cloud) — ensuring that there is no single point of compromise which would reveal your data to prying eyes.
There’s nothing wrong with storing your sensitive data in the cloud — just make sure to use Cloud Privacy Protection to safeguard yourself!
Thursday, August 21, 2014
Ohanae Goes to College
The Whitehat Society, a special interest group dedicated to issues around cyber security at Singapore Management University, recently organized an Ohanae use case competition. Participation was fantastic, with numerous innovative entries submitted for the “Trust No One” essay competition. Lim Yi Shen and Lim Jun Yan claimed the top awards – each winning a Microsoft Surface 2, complete with a sleek keyboard and sleeve.
Meet the Winners
“I am a freelance designer and am working on various Kickstarter projects. Ohanae helps me in my work with its device-centric combined solution for both login and data protection that helps my team collaborate better. With Ohanae, I can conveniently keep using the wide range of cloud service providers, like Dropbox, Google Drive, OneDrive, and Box, without the fear of having my credentials, and hence data, compromised by malicious users. Ohanae also helps me protect my intellectual property rights against plagiarism by maintaining control of my files with information segregation done as simply as clicking to encrypt and decrypt.” – Lim Yi Sheng
“As a student, I use multiple devices like phone, laptop and tablet, and need to manage numerous accounts. Ohanae keeps my data out of reach from anybody but me, allowing me to fully utilize the convenience and flexibility of popular cloud service providers for personal and work-related storage. I realized Ohanae Cloud Privacy Protection’s simplicity and comprehensive coverage of local and cloud storage, on all major OSes during my internship in a large scale company, as it struggled to protect its private corporate information. Indeed, in a world when you can trust no one, a thoughtful all-rounded defence by Ohanae is your best bet.” – Lim Jun Yan
Proactive BYOD
Throughout history, there are many examples of events that led to calamities. In hindsight, it’s often painfully obvious that they could have been predicted and prevented by proactive efforts. Bring-Your-Own-Device, often referred to by security officers as “bring your own disaster”, represents just such a sea change for enterprises. A new article in NetworkWorld discusses several surveys that show that BYOD is continuing unabated, and often, unapproved devices or apps are being actively hidden from hostile enterprise IT departments.
Organizational reaction to BYOD typically falls into one of three categories.
In some organizations, IT has mandated that there is no use of bring-your-own-devices or apps. In a very small number — for instance, military or government intelligence agencies — the organization has the ability to completely control all incoming and outgoing network access, and to enforce physical access to facilities by unauthorized devices, and the mandate works. For the vast majority of mandated companies, controls are company policies, and enforcement is by individual compliance. The Trackvia study finds that non-compliance with company guidelines is a significant problem, with almost 70% of younger workers admitting to doing so.
In other organizations, IT has recognized that mobile devices and apps are required to achieve peak employee performance, but have certified and approved specific devices and tools. TrackVia’s study finds this hasn’t worked either, with from 30 to 50% of specific employee age groups reporting they picked other devices or apps because the ones IT chose did not meet their needs.
CIOs in the last category understand that BYOD and BYOA use within their organization is inevitable, but struggle with the other harsh reality that by-and-large, employees just don’t care about security.
Clearly, employees drive organizations towards the third alternative, and organizational attempts to drive towards the first impact employee productivity and efficiency, and consume valuable IT funding and personnel resources.
Ohanae offers CIOs a better way to embrace the second and third choices. Ohanae’s Cloud Privacy Protection software suite allows enterprises to certify and support some third party applications and devices, or to be completely agnostic to apps and devices, against a secure backdrop. Ohanae software ensures that files are encrypted on devices and in the cloud, alleviating worries about data exposure on devices which are not certified, supported, or under management by an organization. Ohanae’s credential management system ensures that cloud based storage (and other cloud based apps) are accessed using secure, complex passwords that prevent account compromise and related data exposure. Ohanae’s secure file sharing allows users to collaboratively exchange data with industrial strength access mechanisms.
Ohanae Cloud Privacy Protection provides a safe environment for corporate data and credentials, and allows IT the time, freedom and safety to make the right choices for BYOD and BYOA that will keep IT users happy, productive and secure.
For more information, please see our videos: Cloud Compliance for Business and Cloud Compliance Policy.
Organizational reaction to BYOD typically falls into one of three categories.
In some organizations, IT has mandated that there is no use of bring-your-own-devices or apps. In a very small number — for instance, military or government intelligence agencies — the organization has the ability to completely control all incoming and outgoing network access, and to enforce physical access to facilities by unauthorized devices, and the mandate works. For the vast majority of mandated companies, controls are company policies, and enforcement is by individual compliance. The Trackvia study finds that non-compliance with company guidelines is a significant problem, with almost 70% of younger workers admitting to doing so.
In other organizations, IT has recognized that mobile devices and apps are required to achieve peak employee performance, but have certified and approved specific devices and tools. TrackVia’s study finds this hasn’t worked either, with from 30 to 50% of specific employee age groups reporting they picked other devices or apps because the ones IT chose did not meet their needs.
CIOs in the last category understand that BYOD and BYOA use within their organization is inevitable, but struggle with the other harsh reality that by-and-large, employees just don’t care about security.
Clearly, employees drive organizations towards the third alternative, and organizational attempts to drive towards the first impact employee productivity and efficiency, and consume valuable IT funding and personnel resources.
Ohanae offers CIOs a better way to embrace the second and third choices. Ohanae’s Cloud Privacy Protection software suite allows enterprises to certify and support some third party applications and devices, or to be completely agnostic to apps and devices, against a secure backdrop. Ohanae software ensures that files are encrypted on devices and in the cloud, alleviating worries about data exposure on devices which are not certified, supported, or under management by an organization. Ohanae’s credential management system ensures that cloud based storage (and other cloud based apps) are accessed using secure, complex passwords that prevent account compromise and related data exposure. Ohanae’s secure file sharing allows users to collaboratively exchange data with industrial strength access mechanisms.
Ohanae Cloud Privacy Protection provides a safe environment for corporate data and credentials, and allows IT the time, freedom and safety to make the right choices for BYOD and BYOA that will keep IT users happy, productive and secure.
For more information, please see our videos: Cloud Compliance for Business and Cloud Compliance Policy.
Wednesday, August 6, 2014
Unique Passwords for Internet Accounts
With the widely publicized compromise of 1.2 billion user accounts from almost a half a million different websites, one very popular question is what can the average internet user do to protect themselves.
The common recommendations are straightforward:
The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.
Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.
The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.
Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.
Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.
With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.
We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!
The common recommendations are straightforward:
- Use long, strong, and complex passwords
- Use different passwords for every website
- Change your passwords often, at least every six months
- Avoid storing sensitive information (passwords, social security numbers, or other identity information) online
The challenge for users continues to be that secure practices are difficult to do, impact their productivity, and make useful resources harder to access anytime, anywhere. Users continue to make the tradeoff towards speed, productivity, ease of use, and universality — even as the risks and costs dramatically increase.
Ohanae believes that total cloud privacy protection is the solution to this epidemic. Although traditional password management is part of cloud privacy protection, it is not enough alone. Cloud privacy protection must include security of the password manager, so that it does not become a single point of failure, where all passwords can be compromised through it. Cloud privacy protection must include authentication that goes beyond a simple password, preferably by using multi-factor authentication to safeguard access to website credentials.Cloud privacy protection must safeguard data as well as credentials — enabling storage of sensitive, identity related data without risk of trickle-down account compromises if that data is accessed without authorization.
The Ohanae suite for Cloud Privacy Protection implements a password management function called Ohanae 1-Tap. Ohanae 1-Tap does not store passwords anywhere (on your device, on Ohanae’s servers, or in the cloud). Passwords are generated dynamically only when they are used, and generated by two factor authentication based on device and passphrase.
Ohanae’s Cloud Privacy Protection encrypts files stored in cloud storage providers — at creation on your device, during transmission across the Internet, and once stored in the cloud storage provider. The data is protected by strong, multi-factor authentication to dynamically generate decryption keys only on use — industrial strength technology to keep sensitive information in your files from the prying eyes of cyber criminals.
Finally, Ohanae knows that users have the need to securely share data with other collaborators, and supports secure transmission and use.
With Ohanae, it’s easy to establish unique, strong, lengthy passwords for every website, change them as often as you’d like, and have those passwords available on every device you use — whether desktop, laptop, or mobile. You can feel secure storing sensitive files online, and sharing them with others. And, in the unlikely event of a compromise, you have the confidence that the breach is limited — to just a single website, or a single cloud storage provider.
We can defeat the cybercriminals of the world and make epic password theft a news story of the past, and complete Cloud Privacy Protection is the way to do it! To get started, download Ohanae from http://www.ohanae.com today!
Labels:
authentication,
best practices,
cloud,
cloud privacy,
cloud privacy protection,
compromise,
credentials,
password,
password manager,
passwords,
privacy,
privacy protection,
russian,
secure passwords,
security,
theft
Tuesday, July 29, 2014
Mobile, BYOD, and the Enterprise
The consumerization of the mobile and bring-your-own-device trends continues to gain exponential momentum in 2014. According to an infographic published this week in Information Week, 90% of employees use mobile phones at work, and 35% use personal tablets at work. Furthermore, employees use an average of 21 different apps at work. Although email remains the most often used, document-centric apps, including file sharing are now used by more than one in every five employees.
InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.
At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.
Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.
With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.
InfoWorld goes a step farther in an article this week, calling CIOs and business leaders to proactively embrace the two trends rather than just reacting to the inevitable employee uptake. InfoWorld cites potential benefits from employee productivity to better communication and engagement with customers.
At Ohanae, we agree that comprehensive adoption of bring-your-own-device (and bring your own cloud services!) and mobile have significant advantages for the business. But, it’s important to adopt technologies that will protect the business against data loss, account compromise, and device theft or misuse.
Cloud Privacy Protection incorporates a suite of capabilities to allow BYOD, mobile, and user selected cloud-based file sync & share in a secure environment. Cloud Privacy Protection includes protection for data in transit to and at rest in the cloud file sync & share provider. It also includes secure file sharing between collaborators, regardless of the mechanism of sharing. Finally, it includes protection for user credentials — the credentials that provide access to raw storage of encrypted data.
With Ohanae’s suite of cloud privacy protection capabilities, enterprises can feel secure in embracing new trends that embrace cloud storage, pervasive mobile use, and bring your own device tablets and laptops.
Subscribe to:
Posts (Atom)