Six Reasons Why Encryption Back Doors Won’t Deter Terrorists

Last week’s tragic events in Paris, and fears over similar terrorist attacks around the world, have revived a long-standing debate. Early evidence suggests that the terrorists used a readily available encryption appto hide their plans and thwart detection by law enforcement. This has led to finger-pointing by intelligence officials and politicians demanding that something be done to control this dangerous technology. Keep in mind that the terrorists also used multiple other dangerous technologies including consumer electronics, explosives, lots of guns, cars, trains and probably airplanes – but these are better understood and attract less grandstanding about controlling them.

Setting aside the obvious privacy concerns, the argument for weakening encryption ignores a basic question – can this technology really be controlled? More specifically, those arguing for diluted encryption are demanding “back doors” that would allow easier access by law enforcement. For many reasons, this idea simply won’t work and will have no impact on bad guys. It also could have serious unintended negative consequences. Here are a few reasons why:

  1. Encryption = Keeping Secrets

Encryption is more of an idea than a technology and trying to ban ideas generally backfires. For thousands of years, good and bad actors have used encryption to protect secrets, while communicating across great distances.

In the wake of traumatic public events, it’s easy to start thinking that only bad guys need to keep secrets, but that’s clearly not true. Governments must keep important secrets. Businesses are legally required to protect secrets (such as their customers’ personal information) and individuals have reasonable expectations (and constitutional guarantees in many countries) that they can keep their personal data private. Encryption, if properly applied can be a highly effective way to protect legitimate and important secrets.

  1. Who Keeps the Keys to the Back Door?

Allowing government agencies unfettered access to encrypted data is not only Orwellian – it’s also simplistic and unrealistic. Assuming back doors are created, who exactly should have access? Beyond the NSA, FBI, and CIA, should we share access with British Intelligence? How about the French? The Germans? The Israelis? Saudi Arabia? How about the Russians or the Chinese? Maybe Ban Ki-Moon can keep all the keys in his desk drawer at the UN…

As we all know, the Internet doesn’t respect national boundaries and assuming that all countries will cooperate and share equal access to encryption back doors is naïve. But if governments only require companies within their respective jurisdictions to provide back doors, the bad guys will simply use similar, readily available technology from other places.

  1. Keys to the Back Doors Can Easily Get into the Wrong Hands

If there are back doors to encryption, hackers will almost certainly steal and exploit them. As the Snowden revelations demonstrated, large government bureaucracies are not particularly good at protecting secrets or ensuring that the wrong people don’t get access. The OPM hack, which uncovered millions of government employees’ data (purportedly by Chinese hackers), highlights the risks when large numbers of humans are involved.

In a very real way, the existence of encryption back doors would represent a serious threat to data security across the government, business and private sector.

  1. To Control Encryption You Need to Control Math

Ironically, while some government agencies seek to crack encryption, other agencies such as NIST are chartered with testing and validating the security efficacy of encryption algorithms and implementations. The FIPS 140-2 validation process is globally recognized and provides assurance that encryption does not have flaws.

Today’s best encryption is based on publicly vetted and widely available algorithms such as AES-256. Most smart, college-level math majors could easily implement effective encryption based on a multitude of publicly available schemes.

So far I haven’t heard policy pundits recommend that potential terrorists be barred from high-level math education. Preventing clever people anywhere in the world from applying readily available encryption or developing their own encryption schemes is impossible.

  1. The Tools Do Not Cause the Actions

It does appear that the Paris terrorists used commercial encryption to hide some of their communications and it must be acknowledged that this may have hindered law enforcement. They also probably also used off-the-shelf electronics to detonate their explosives, drove modern rental cars to haul people and weapons and perhaps were radicalized in the first place through social media. Today’s technology accelerates everything in ways that are often frightening, but going backwards is never an option. And the tools, no matter how advanced, do not create the murderous intent behind terrorism.

Readily available technology likely made their jobs easier, but in the absence of easy to find encryption tools, the terrorists could have found many other effective ways to hide their plans.

  1. Neutering Encryption Will Hurt Legitimate Businesses

So let’s imagine that in the heat of terrorist fears, the US, UK and a few other governments demand that companies within their jurisdictions create and turn over encryption back doors. Confidence in security technologies from those countries would plummet, while creative entrepreneurs in many other countries would quickly deliver more effective security products.

The growth of the Internet as a trusted platform for business has been closely tied to encryption. The development of SSL encryption by Netscape in the 90s enabled e-commerce and online banking to flourish. And today, encryption is playing a critical role in creating the trust required for today’s rapid growth of the cloud applications.

There are many recent examples of governments trying to legally close barn doors after the horses have long since disappeared. Ironically, the US government already bars the export of advanced encryption technology to rogue states and terrorist groups including ISIS. Clearly this ban had zero effect on the terrorists’ ability to easily access encryption technology.

We live in scary times and should never underestimate the challenges we all face in deterring terror. But latching onto simplistic solutions that will not work does not make us safer. In fact, if we undermine the effectiveness of our critical security technology and damage an important industry, we will be handing the terrorists a victory.

Willy Leichter, Global Director of Cloud Security, CipherCloud

[Cloud Security Alliance Blog]

Never Pay the Ransomer

CryptoWall has struck again—only this time it’s nastier than before. With a redesigned ransom note and new encryption capabilities, BleepingComputer.com’s description of the “new and improved” CryptoWall 4.0 sounds more like a marketing brochure for a well-loved software product than a ransom demand.

Like the iterations of CryptoWall that came before the 4.0 version, the only way to get your files back is to pay the ransom in exchange for the encryption key or wipe the computer clean and restore the files from an endpoint backup archive. The FBI agrees, stating “If your computer is infected with certain forms of ransomware, and you haven’t backed up that machine, just pay up.”

In addition to encrypting the data on an infected machine and demanding a ransom for the decryption key, CryptoWall 4.0 now encrypts the filenames on an infected machine too, leaving alphanumeric strings where file names once were.

The most significant change in CryptoWall 4.0 is that it now also encrypts the filenames of the encrypted files. Each file will have its name changed to a unique encrypted name like 27p9k967z.x1nep or 9242on6c.6la9. The filenames are probably encrypted to make it more difficult to know what files need to be recovered and to make it more frustrating for the victim.

Not unlike Bill Miner, infamously known as the Gentleman Robber, CryptoWall 4.0 makes a farcical attempt at politeness. CryptoWall 4.0’s ransom note reassures its victims that the infection of their computer is not done to cause harm and even congratulates its victims on becoming part of the CryptoWall community, as if it were some sort of honor.

CryptoWall Project is not malicious and is not intended to harm a person and his/her information data. The project is conducted for the sole purpose of instruction in the field of information security, as well as certification of antivirus products for their suitability for data protection. Together we make the Internet a better and safer place.

Ransomware is a lucrative business. It is estimated that the CryptoWall virus alone cost its victims more than $18 million dollars in losses and ransom fees from April of 2014 to June of 2015. In the spirit that being robbed doesn’t have to be a bad experience, CryptoWall 4.0 makes a bad attempt at customer service, claiming “we are ready to help you always.” Additionally,

CryptoWall 4.0 continues to utilize the same Decrypt Service site as previous versions. From this site a victim can make payments, find out the status of a payment, get one free decryption, and create support requests.

In closing, the ransom note states,

…that the worst has already happened and now the further life of your files depends directly on your determination and speed of your actions.

Whether hackers use CryptoLocker, CryptoWall, CTB-Locker, TorrentLocker or one of the many variants, the outcome is the same. Users have no choice but to pay the ransom—unless they have endpoint backup in place. Even with the best tech resources, decrypting the algorithm used to lock files without the key would require several lifetimes. Whereas, with automatic, continuous backup, end users will NEVER pay the ransomer because a copy of their data is always preserved.

Rachel Holdgrafer, Content Business Strategist, Code42

[Cloud Security Alliance Blog]

CSX 2015—From a Young Professional’s Perspective

ISACA’s inaugural CSX Conference took place in Washington, DC on 19-21 October, and it immediately raised the bar for IT security conferences. The hands-on pre-conference workshops and education sessions during the event provided tremendous value and insight into cybersecurity best practices and industry trends. As a young professional, the opportunity to hear from some industry experts and leading figures within the cybersecurity field was exceptionally beneficial.

The conference provided young professionals a chance to network with subject matter experts, vendors from large corporations or cybersecurity startups, as well as our peers. We were able to understand ways in which threats are evolving and the skills needed to keep up with the demands of protecting systems and sensitive information. It was easy to follow the rapid reactions and thoughts of attendees, as they discussed the conference topics on Twitter, as the updates were displayed on monitors throughout the expo hall or conference center.

Students attending the conference expressed enthusiasm about being able to provide direct feedback to ISACA Headquarters regarding the conference format, CSX career paths and volunteer opportunities. For them, a good challenge to have was deciding how to select the best possible session to attend, since there were so many good learning opportunities and speakers in each of the time slots. This only goes to show the depth and value of the education provided.

The CyberLympics competition added a new dynamic to the event. It was very exciting to observe and follow the progress through the second day of the conference. A previous colleague of mine was part of the team that represented Team USA. He felt the team had a complementary set of skills that enabled them to achieve the success they had in the earlier rounds of the competition to get to the finals.

Keynote speaker John Sileo gave a moving presentation on the value of identity theft, privacy and protecting your own personal information. For young professionals who are used to sharing so much on a daily basis, this session really resonated and demonstrated the real-life dangers of social engineering and sharing too much information. It made you think twice.

The conference concluded with a great keynote from Robert Herjavec, owner of the Herjavec Group and regular on the popular TV show, Shark Tank. His perspectives spanned a long entrepreneurial career and he emphasized the importance of cybersecurity professionals in this day and age, as we face such persistent threats from many sources.

Mark your calendars for the CSX Conference next year in Las Vegas at the Cosmopolitan from 17-19 October. It is an event you do not want to miss.

Jason Yakencheck, CISA, CISM, CISSP-ISSAP
Senior Managing Consultant, Cybersecurity & Privacy, IBM Global Business Services

[ISACA Now Blog]

Five Value-enhancing Adjustments for Information Risk and Security Programs and Professionals

For information risk and security programs and professionals to continue to stay relevant, provide value and be effective in the organizations they support, they must regularly adjust their approach. Organizations are constantly maturing and evolving, while simultaneously changing their activities, expectations and requirements. The most effective way for risk and security professionals to support programs is to mature, evolve and change with them. Consider these 5 adjustments that risk and security programs and professionals can implement to continue to be valuable and beneficial to their organizations:

  1. Organize under enterprise risk management (ERM) functions—Information risk and security should be considered and organized under an ERM function within an organization instead of a technology function. In many organizations, the information risk and security programs and their associated professionals are organized as part of IT groups led by technology leaders (e.g., chief information officers). This potentially limits the risk and security professional’s scope and can create a conflict of interest and tension between them and the technology leaders they are supposed to support. As a result, the information risk and security professional may not be viewed as a valued asset by the technology leader, which could result in punitive action or lack of trust, as IT leaders may not believe information risk and security professionals are properly supporting their views or initiatives.
  2. Present information that the organization really wants—Instead of assuming what business leaders and stakeholders want to know about information risk and security, ask them. It is often the case that information risk and security professionals either assume they know the insights and information that their constituents and stakeholders are interested in or that these individuals are not knowledgeable enough to ask for the right things. Regardless of the scenario, collaboration will help both groups build stronger relationships and understand how to interact with each other more effectively.
  3. Articulate threat, vulnerability and then risk—Risk and security professionals commonly make the mistake of speaking about risk when they really are representing their insights and analysis concerning threats and vulnerabilities. The determination of a risk to an organization includes threat and vulnerability information, but also incorporates important data points such as business impact analysis if the threat is realized or vulnerability is exploited, business value and strategy, and calibration with the organization’s overall risk appetite. If these information risk and security professionals do not have a current and credible understanding of business considerations and tolerances, they cannot be expected to provide accurate representations of risk to their constituents and stakeholders.
  4. Use a consultative approach—Information risk and security professionals are often perceived as being authoritative and unapproachable in many organizations. This is especially true when they are restricting individuals from pursuing a course of action or activity. An effective approach to removing this stigma is to integrate a consultative element into the information risk and security program or activities. This will assist the risk and security professional in building strong relationships, allowing them to provide useful advice and guidance, and be present and active in business activities on a regular basis instead of only at decision or review points. A consultative element will also provide the organization with an interface into the risk and security program where they can ask questions, develop and collaborate on ideas, and proactively engage to ensure they not only understand information risk and security expectations and requirements, but also the reasons for their existence.
  5. Embrace, but educate—Instead of saying no to new technologies, ideas and capabilities in the name of security, try to find a way to say yes. Individuals within the organization often assume that the position of the risk and security professional or program is to restrict the use of new technologies, ideas and capabilities. A more effective approach is to embrace technological changes while at the same time educating the individuals who want to use new technologies about the appropriate information risk and security considerations, concerns and requirements that need to be accommodated as part of their use. This will empower individuals to able to make informed decisions about the use of these resources and, at the same time, ensure they are aware of their risk and security obligations.

Information risk and security programs and professionals need to continue to enhance their value proposition to the organizations and individuals they support so they can continue to be effective and relevant. The fundamental organization, policies, standards, functions and control frameworks to support information risk management and security are typically already in place in most organizations. What may be missing are the adjustments in approach and capability that are required to operate security programs effectively so that they are viewed as a benefit and not as a burden to the organizations and individuals they support.

John P. Pironti, CISA, CISM, CGEIT, CISSP, ISSAP, ISSMP, is the president of IP Architects LLC.

[ISACA Volume 23]

Cloud Security Alliance Summit Los Angeles 2015 To Feature Top Experts from Entertainment and Enterprise on Lessons Learned in Cloud Security

Speakers from The Honest Company, PwC, University of Oxford, Microsoft, Google, SpaceX and Evident.io to Be Featured at the Upcoming Inaugural Event

Los Angeles, CA – November 17, 2015 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today released the agenda for its augural CSA Summit Los Angeles 2015. The event will feature some of the world’s most recognized and respected cloud adopters and providers from across the entertainment and enterprise industries who will come together to share lessons learned in cloud security.

Co-hosted by the CSA LA/SoCal chapter, this year’s event will take place on Thursday, December 3. Wendy Frank, Principal, Advisory, Cyber security, Privacy and Risk at PwC, will deliver the opening keynote.

In addition to the keynote presenter, a number of experts will be on hand to give presentations or as participants in key panel discussions including Mikhael Felker, Director, Information Security, The Honest Company; Nick Reva, Information Assurance & Compliance Lead, SpaceX; Joel Sloss, Program Manager, Microsoft Azure Security, Privacy, Compliance, Microsoft; Jeffrey Ritter, External Lecturer, University of Oxford; Matthew O’Connor, Product Manager Compliance, and Anti-Abuse products, Google Cloud Platform; and Tim Prendergast, CEO and Co-founder, Evident.io.

The agenda will also feature presentations and discussions on some of the most emerging and critical topics facing cloud security including Top Security Challenges Facing the Cloud Adoption Enterprise, Information & Content Security, Achieving Digital Trust, and Securing & Auditing AWS. The event is expected to draw approximately 200 well-qualified attendees with an interest in cloud security from the local region.

WHAT: Cloud Security Alliance Summit Los Angeles 2015
WHEN: Thursday, December 3, 2015, 9:00am – 5:00pm
WHERE: Marina del Rey Marriott, 4100 Admiralty Way
ATTENDEE REGISTRATION: https://csacongress.org/event/summit-los-angeles-2015/#registration
MEDIA REGISTRATION: Email kari@zagcommunications.com

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. CSA has developed the definitive best practices for the industry, such as the “Security Guidance for Critical Areas of Focus in Cloud Computing”, the “Cloud Controls Matrix”, “Top Threats to Cloud Computing” and 50 other cloud security research artifacts.

Contact

Kari Walker
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance News]

English
Exit mobile version