Encryption is not a Silver Bullet

Apr 19 2007

By Ira Winkler

I was just reading how the IRS lost 500 laptops that likely contain sensitive information. In response, they want all laptops to be encrypted. I am actually very much in favor of that.

Unfortunately though, the encryption is made out to be a magical cure for lost laptops, and it is not. While encryption does potentially add an exponential layer of complexity to compromise data, that is only the case when the encryption is properly implemented. It also assumes that the data isn’t accessed via an application that automatically decrypts the data to provide it to the user.

I have seen several cases where encryption keys have been taped to the laptops. More frequently, the passcodes are trivial. Again, encryption, when properly implemented, can stop a major compromise of information and significantly decrease risk. But just decreeing the use of encryption without providing guidance of proper implementation, and most importantly, enforcement of a strong implementation, will render the encryption useless.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • Slashdot
  • Digg
  • del.icio.us
  • Reddit
  • digg
  • Technorati
  • StumbleUpon

Related posts:

  1. Phishing: Silver Hooks, Not Silver Bullets
  2. Miniature Computers That Can Break Your Network Wide Open
  3. Macbook wireless device driver insecurities allow remote compromise
  4. Of PDAs, Expectations and Underpants
  5. Enterprise Data Protection Podcast

Posted by Ira.Winkler on Thursday, April 19th, 2007, at 3:31 am, and filed under Articles.

Follow any responses to this entry with the RSS 2.0 feed.

You can post a comment, or trackback from your site.