Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Monday, January 14, 2013

Big Data Solution for the Big Security Problem

Recently, I wrote about the content security dilemma. As much as we are trying to secure our information without completely giving up on convenience, we can barely stay one step ahead of the bad guys. The hackers, equipped with easily available immense computing power are using brute-force attacks to overcome even the most sophisticated authentication and encryption technologies.

The inconvenient truth remains, that we don’t really have any practical security today outside the perimeter security measures offered by encryption. As soon as the information leaves the secure repository, it is basically no longer secure. If I share a report with you via email, social software, or shared folder, I can only hope that my trust in you will be rewarded by your discretion. If not, you can easily share the document with anyone and I can’t do anything about it.

So what do we do? How do we secure our data in transit? After all, we have to make it travel to put it to work. Data locked up in a vault is of limited value. The answer isn’t easy and it will likely consist of multiple measures.

First, we will adopt advanced means of authentication to ensure that it really is the right person accessing the data. I have described some of such advanced authentication in the above mentioned article - ranging from multi-factor authentication to, yes, chip implants.

Next, we will employ our social media networks as a mean of collective endorsement of authenticity. Authenticity is an issue for both, the people and the information assets. Is the message from Barack Obama really from the President or from an imposter? Is the report I’ve received the right report or has it been substituted by malicious disinformation? Endorsement by a group of people doesn’t completely solve the problem, of course, but it adds another hurdle for the bad guys. Just think of the product reviews on Amazon. Sure, they can be fake but it is a lot of work to fake them and so most of them can be trusted and so can be the products they endorse.

Finally, we will see a greater use of analytics to identify any suspicious behavior - just like the credit card companies do today. The idea is that they trust every transaction as long as the transaction remains within the expected pattern of behavior. When the behavior deviates from the expected pattern, you get one of those calls. Most of us have received a call alerting us to a fraudulent transaction at some point. The system works. It may not prevent the initial fraudulent transaction but with a sufficient audit trail, that transaction can be investigated. What’s important, though, is that the timely detection prevents any subsequent transactions.

This is a big data problem in need of a big data solution.  Analytics software will be reviewing the behavior patterns of people accessing data and detecting any behavior that is out of the norm. Such behaviors will be flagged for investigation while the system shuts down any additional data exposure.


Yet again, there is no perfect solution in sight. But we may have a few options to stay ahead of the bad guys. Because for the foreseeable future, information security remains an arms race. The only way to defend ourselves from the ever smarter hackers will be our ever stronger defenses.

Sunday, December 16, 2012

Can We Solve the Security Dilemma?

I recently wrote a blog post about the need to strike the right balance between security and convenience. In this post, I'd like to examine the ways to find that balance amid ever raising security requirements. The challenge lies in the fact that the traditional security measures such as strong passwords are becoming increasingly insufficient. The computing power available to every hacker today is simply so immense that brute-force attacks are rather easy to execute. Note: a brute-force attack is an encryption decoding technique that uses vast computing power to quickly try all possible combinations of characters - until the right key is found.

So, how do we overcome this problem?

The solution isn’t easy, particularly given the security and convenience trade-off. Strong passwords force us to use longer passwords and passphrases that have to include a combination of letters, numbers, special characters, etc. that cannot be found in the dictionary. We all know that such passwords are less convenient, particularly when entering them on a smartphone but the benefit of this trade-off is higher security. Alas, not much higher, as strong passwords can be still broken with brute-force attacks.

Multi-factor authentication takes things to the next level by combining passwords with another authentication mechanism such as one time passcodes or tokens. My bank, for example, gave me a one-time passcode generator the size of a credit card that I use for some of the more important transactions. I don’t need it to check my account balance but I do need it for money transfers. That, by the way, is a good example of the security-convenience balance in a practical use case.

The next level of security can be provided by biometrics. Today, retina scans are the way the government identifies citizens at border crossings who use the Global Crossing or Nexus service. It seems to work and for a long time I thought this would solve the authentication problem for good. However, the biometric signatures can be falsified and even stolen which not only compromises the security but also introduces a new identity theft challenge. No, I am not talking about stolen fingers and eyeballs like we see in the movies - I am talking about the series of data points that biometric scanners look for. Same is true for a DNA-based authentication, by the way. I am not aware of any practical DNA authentication use cases outside of science fiction today, but the signature files for DNA samples could be falsified or stolen just like any password.

Biometric security could be even more vulnerable as a result of genetic research. There are various initiatives underway today to build an open source library of decoded human genomes for the purposes of genetic research. That is a great cause which I fully support. However, there may be a dark side to it - as there usually is with any scientific discovery. I am not a genetic scientist but I wonder if the human genome could be used to reproduce biometric features such as fingerprints, retinas, or DNA samples. After all, a lot of the genomic research is aimed at the ability to reproduce vital human organs...

One day, we might be voluntarily or involuntarily implanting chips into the human body for the purposes of strong, fast, and secure authentication. Some of this is already happening today. We are chipping our pets to find them when they get lost. We are tagging prisoners under home confinement. We are traveling with passports containing our biometric data. A chip using some type of RFID technology could transmit our identity to various applications to identify us. The chip could do so frequently - perhaps every few seconds - to continuously validate the identity of the user. That is, until someone finds a way to falsify the chip signature...

Clearly, solving the security dilemma is not easy. Just like any high stakes game, there may never be a perfect solution. Instead, it will be a race. We will keep inventing better authentication while trying to stay a step ahead of the bad guys. Every time the good guys invent a new security measure, the crooks will find a way to beat it. Hence a new level of security has to be invented - without completely sacrificing convenience. And so it will keep going round after round.

Sunday, November 25, 2012

Security and Convenience - The Balance Matters

In our world, where information is the ultimate strategic resource, security is important. Very important. But security usually stands in the way of productivity and convenience.

Take something like strong passwords and the need to change them regularly. We could significantly increase the system security if we mandated very long, strong passwords with 256 characters and if we mandated them to be changed every day. The data would be very safe with these passwords. Of course remembering such passwords would be highly inconvenient, if not impossible, and changing them daily would be annoying. Want even higher security? How about 1024 character long passwords that have to be changed every hour?

Practical security today has to reach a compromise; a balance between security and convenience. We have to keep pushing the barriers on security without annoying users so much that they either give up or develop behavior that actually compromises the security altogether. In my password example above, people would lose productive time every day and they would likely have no choice but to write the password down every morning on a piece of paper kept right next to their monitor. All of those passwords lying around would severely compromise the security of the system which would achieve exactly the opposite from the intended result. If you are interested in learning more about password related challenges, I recommend reading the recent Wired article titled Kill the Password: Why a String of Characters Can’t Protect Us Anymore.

Clearly, there is a constant tradeoff that we have to make between security and convenience. However, not every organization is the same in terms of how strong their security needs to be  and how much inconvenience they can impose on their employees. I often meet customers who are on very different points of the spectrum, from very casual to utterly paranoid.


Of course nobody will admit that they have a casual attitude towards security. However, consider the differences between retail, manufacturing, and, yes, many technology companies which often get by with relatively simple security (I know, there are always exceptions) versus organizations such as military installations, intelligence agencies, and nuclear facilities. These operate on a completely different security level and have no choice but to impose a lot of inconvenience on their employees.

Think about all of the employees working at Internet startups in Silicon Valley and about how much security hassle you could put them through - not much! James Bond, on the other hand, never tires of opening the cafeteria doors using his palm and voice print. Apparently, high security standards come with some jobs (or companies).

What’s important is that one size doesn’t fit all when it comes to security. Different organizations face different security problems and their solutions have to be adjustable. For example, a two-factor authentication may be appropriate in some environments while a biometrics based authentication is a good fit in others.  Getting the balance right between security and convenience is important - the balance matters!

Friday, June 22, 2012

Alan Turing - Faster than Lance

This blog post is my tribute to Alan Turing who was born on this day, exactly 100 years ago. As as computer engineer, I have learned about Turing in some of my first courses back at the university. In the 1930s, Dr. Turing introduced ground-breaking concepts such as the Turing Machine and the Turing Test. The Turing Machine is regarded as the grandfather of all computers while seeing the IBM Watson compete on Jeopardy last year has shown that we are not far away from passing the Turing Test. And let’s not forget Turing’s legendary contributions to cryptology in his role at the Bletchley Park while breaking the German Enigma codes during WW II.
Alan Turing, the runner
One less known fact are Turing’s accomplishments as an athlete. He was a competitive runner, starting for the Walton Athletic Club in Walton, Surrey. In 1947, he competed in the Amateur Athletic Association Championships marathon finishing in 4th place in 2 hours 46 minutes and 3 seconds. Folks, 2:46:03 is an amazing time for a non-professional runner even today. Back then, he was within some 11 minutes off Olympic gold medal pace. In fact, that pace is even faster than the marathon time Lance Armstrong posted in the 2007 New York City Marathon which he completed in 2:46:42.


Clearly, Alan Turing was a remarkable person and we should celebrate his life and accomplishments - not just today.

Monday, May 30, 2011

Securing Content via Tethering

A few weeks ago, I met with a group of customers representing the government institutions of a small Asian nation. For a variety of geo-political reasons it was apparent that for a relatively small country they spend quite a bit of money on their national defense. And so it was no surprise that every other question turned to security.

Securing content has long been an integral part of every decent Enterprise Content Management (ECM) system on the market. Most offerings provide solid authentication and access control (often called permissions). Robust auditing is a requirement not just for security but also for many compliance applications. For example, the 21 CFR Part 11 regulation in the Pharmaceutical industry is big on auditing and electronic sign-offs.

But what most of these security capabilities don't consider is that they are really securing the system and not the content. Yes, the repository is very secure but the content wants to be used, and to be used, it cannot just sit in a secure repository. Even the most basic use such as viewing usually means taking the content out of the repository where all of the fancy authentications and permissions become irrelevant. Indeed, as soon as users have the right to read a document and open it with their desktop application, the document is controlled by the users and not by the content management system (CMS). The users can save it on their flash drive, forward it via email or post it on Facebook. Not much security if you ask me.

During the meeting, I explained to the customers the two ways to secure content outside of the repository. The first method is using encryption via rights management - sometimes referred to as information rights management (IRM) or enterprise rights management (ERM). This approach is based on the same technology as digital rights management (DRM) which dates back to the mid 90s with companies such as Intertrust. DRM was the entertainment industry's attempt to control content piracy by encrypting the content and requiring users to apply a key that would control what they are allowed to do with it.

The vendors in rights management in the enterprise market applied the same approach by extending the repository permissions to content outside of the repository. But as we've seen with DRM, rights management really gets in the way of usability. The key distribution becomes a challenge and the users struggle to encrypt and decrypt their content. This inconvenience was so significant that consumer companies such as Sony and Apple eventually abandoned DRM altogether.

In the enterprise space, most rights management vendors got acquired by the bigger players who now rule this market - Oracle acquired Sealed Media (via Stellent), EMC got Authentica and Microsoft built their own RMS which OpenText integrates with to offer a solution for it's own repository. But because of the user inconvenience, rights management deployments are usually limited to specific applications such as deal rooms or contracts management.

Rights Management controls content
permissions outside the repository
The other way of securing content is much newer and more innovative: content tethering. Its main idea is to address the key security weakness of a secure repository - which is controlling the content when it leaves the repository - by not letting it ever leave. It's not a surprise that this approach has yet again been pioneered by the media companies. The most notorious example is YouTube which allows any user to view the content on their site but also make it available on any other site, blog, RSS reader, portal or mobile device by providing a simple widget that can be easily embedded in such applications. That’s done by copying a short snippet of code that YouTube makes readily available to anyone.

Widgets can be easily embedded
With the widget approach, the YouTube content can be easily used by any application but - and here is the beauty of this technology - the content never leaves the YouTube repository. The widget displays the content straight from the YouTube repository while YouTube retains complete control and security of the content. The content cannot be downloaded unless explicitly permitted (sorry Wikileaks) and the content owner can update it any time or take it down which is something YouTube has to do regularly to please those pesky media companies crying about copyrights infringement.

The content tethering works not just for video. SlideShare does the same for PowerPoint slides, Flickr does it for pictures and RSS feeds do it for news articles. And just as DRM found its use in the enterprise, the same is happening with content tethering.

Widgets enable tethering for any type of content
OpenText (yes, my employer) has released an enterprise version of widgets that allow customers to tether content residing in the Enterprise Library, a highly secure repository. Leveraging our own set of content viewers (remember that little Spicer acquisition in 2008?), the OpenText Widget Services work with virtually any type of content from documents to rich media. The widgets can be embedded via tiny code snippets into any web site, blog, portal or mobile site. And with tethering, customers have a new way to secure their content while making it widely available to users who don't need any pre-requisite software on their devices and who don't need to worry about how to decrypt that darn contract I'm supposed to review by noon today.

And that's an interesting solution for security sensitive customers like the security sensitive folks from Asia I met the other day.