|By Zafar Khan||
|June 29, 2013 07:00 AM EDT||
There has been quite a buzz around the power of the alleged NSA eavesdropping considering the insights that the NSA Whistleblower, Edward Snowden, presented to the American public.
The NSA Whistleblower exposed how our digital identities are being captured, stored, analyzed, and categorized, allegedly by NSA, as well as companies that publicly state that they store and analyze your data (Facebook, Linkedin, Google email, etc.). The power of the NSA system, according to Snowden, is that they aggregate your digital communications across telephone, internet, web, mobile app, and email data.
With regards to email, email encryption works, to keep your email message content private. As The Guardian reported on Monday, June 17, the NSA Whistleblower said:
"Encryption works. Properly implemented strong crypto systems are one of the few things that you can rely on."
But, encryption is a broad term. Not all email encryption and methods of use are the same, in terms of privacy. Not all are "strong crypto systems".
What type of "encryption" works, for whom, what, and when?
"Caesar Cipher" and "Pig Latin" are Forms of Encryption
Suppose Alice wants to send a secret message to her friend Bob but worries that her snoopy Big Brother may intercept it. Alice needs a way to scramble her message so that only Bob can read it. A simple way to do this would be for Alice to replace each letter in her message with the next highest letter; shifting it by one (think "Caesar Cipher" or "Pig Latin").
But, of course, that is too simple. If Big Brother intercepts the message he'll be able to easily decipher it by looking for hidden patterns in the letters it contains. All it will take to crack the code is a little mathematics and a little trial and error.
And, of course, if Big Brother uses a computer he'll be able to crack the code even faster. So just shifting the first letter to the end and adding "ay" as a suffix (turning "HELLO" into "ELLOHAY" for example) isn't a very strong cipher. What can Alice do?
Well, she can try to think up a more complicated mathematical formula to scramble the letters and numbers. And maybe she could use a computer herself to apply the formula. This will help, but the problem is still that if Big Brother hires clever mathematicians, or if he just has a big enough computer, he will be able to crack the code eventually. So it looks like it's going to be an arms race with Big Brother to see who can come up with the biggest computers and the most complicated formula. But because Big Brother is big, it is a race Alice and Bob are bound to lose.
What is Considered "Strong Crypto"?
Then, what did the NSA Whistleblower mean by "strong crypto systems" when he said, according to The Guardian, "Properly implemented strong crypto systems are one of the few things that you can rely on."
We have established that more complex patterns used to encrypt are harder to read by Big Brother but capable of being read if Big Brother has a powerful computer to figure out the pattern; yet easy for Bob to read with knowledge of the pattern (the decryption key). Most technicians understand that more complex algorithms are harder to "crack", or said another way, take more computing power to crack.
How does Computing Power Impact the Time to Crack the Encryption?
Let's consider the example of using computing power to try to guess a 10 digit seemingly random alpha numeric password, such as: tjo9i0982d using a "Brute Force" attack (i.e. trial and error). This would be similar to trying to find a pattern in a universe of combinations of 36 digits (26 possible letters and 10 possible numbers). According to Gibson Research Corporation, in this example, there are 3700 trillion combinations, and the time to guess and test the right combination using trial and error in an online environment is one thousand centuries (assuming one thousand guesses per second). However, in what Gibson Research calls a "Massive Cracking Array Scenario" with one hundred trillion guesses per second offline, this password can be guessed in just 38 seconds.
Computing power does matter. But, not many, if any (today), can implement a "Massive Cracking Array Scenario".
Is Today's Commercial Encryption Readable by the NSA with its Computing Power?
This is a question that clearly some people know the answer to. I do not. Most commercial encryption uses algorithms that the NSA has "approved" for "civilian, unclassified, non-national security systems". These algorithms are what encrypt your email or financial transactions when using email encryption or secure HTTP web based connections with commercially available systems. Some of these NSA approved (unclassified) algorithms include DES, Triple DES, AES, DSA and SHA.
Note: it is not only use of encryption that is important, but as Snowden added, "properly implemented strong crypto systems". Those who encrypt email should be sure to use "properly implemented strong crypto systems".
So, let's explore this notion of "properly implemented strong crypto systems".
Security by Obscurity
Bringing this back to Bob and Alice, or you and me, would our use of commercial (NSA approved for unclassified use) encryption be strong enough for our general commercial purposes? I suppose you could consider it so, as long as those who you think may be trying to read your information do not have the computing power, financial resources, and incentive to try to crack the method of encryption you use in your correspondence. To get a sense of the scale in terms of NSA computing power, NPR reported that the NSA is putting the finishing touches on its biggest data farm yet, a $1.2 billion complex in Utah with 1.5 million square feet of top secret space including high-performance NSA computers alone filling up 100,000 square feet.
So, unless (or until, since the NSA Whistleblower says your messages are saved just in case they later need to be read) you elevate yourself the importance of your electronic correspondence to the level that makes your information interesting to the people with this power, your commercially encrypted email should remain private enough...
But if private enough is not good enough, if you are encrypting FOR personal privacy, you should use "properly implemented strong crypto systems" that also consider endpoint security.
As The Guardian reported, the NSA Whistleblower added, "Encryption works... Unfortunately, endpoint security is so terrifically weak that NSA can frequently find ways around it." What does Snowden mean by this? A properly implemented strong crypto system should take into account the endpoints, as well as the transmission.
Google Has an Easier Way to Read Your Email
So, for example, if you take great care to type your email in a Gmail compose page, encrypt the transmission, and then send, you are forgetting that Google may be recording, storing, analyzing, and cross referencing the content of the message you type before you encrypt it (as well as perhaps other personal information on your computer or mobile device).
So, for those encrypting for privacy, endpoint security should be evaluated. Note, you can somewhat control your endpoint security by choices you make, but what about the encrypted email recipient's endpoint security?
What to Do to Keep Your Email Private
So, where does this leave us in the new light of the NSA Whistleblower (and Google privacy disclosures)?
The endpoint security is the most likely source of data exposure; meaning, it may be far less computer intensive to access the metadata stored on your computer hard drive every time you type, or access the messages stored in your mailbox on your desktop, mobile device, email server, or internet mail service provider host before encryption when composing, or after decryption, after reading.
If you use commercial encryption for email, you should consider strong crypto systems that take into account providing endpoint security, in particular at the recipient's end, which is out of your control.
There are generally three types of systems to commercially encrypt email today.
1. Public Key Exchange - Secure but Complex for Many. Exchanging public encryption keys among your contacts (PKI Digital Certificates) and using Microsoft Outlook on your desktop computer is a "strong crypto system", but has proven to be too cumbersome for most to purchase and install these certificates, manage the expiration, ensure your recipients have a copy of your public key and you theirs, and all are using a compatible email program such as Microsoft Outlook desktop software.
2. Secure Store and Forward - "Man in the Middle" Problems. Systems that store your message content in the middle, and send a link to the recipients to download the content, are often used, but are not considered "strong crypto systems", as your most sensitive information is now stored on a third party server with unknown data security and message purge practices (which may differ from their stated policies). Further, there is no protection from unknown recipient endpoint security or lack thereof. Note, systems that wrap your email in an encrypted HTML file and send, often purport themselves to be "direct delivery" but leave out the important point that the process of decrypting, is often sending the data back to the server in the middle, and that server storing the decrypted message and displaying it in a web browser (with the same Man in the Middle storage purge concerns). Further, there is no protection from unknown recipient endpoint security or lack thereof. This is better than simple Secure Store and Forward but still has Man in the Middle issues, and for these reasons, these are also not considered "strong crypto systems".
3. True Direct Delivery - Best Method. Systems that wrap the message in an encrypted PDF file are "strong crypto systems" as (a) the message content is not stored in the middle, (b) content is truly delivered to the recipients' desktops encrypted, AND (c) the content remains encrypted at the recipient endpoint to prevent potential disclosure regardless of the recipient endpoint security. Systems that make this method easy to use and implement for both sender and recipient become the true best method "strong crypto systems" for email encryption (for both compliance and personal privacy).
“This win means a great deal to us because it is decided by the readers – the people who understand how use of our technology enables new insights that drive the business,” said Matt Davies, senior director, EMEA marketing, Splunk. “Splunk Enterprise enables organizations to improve service levels, reduce operations costs, mitigate security risks, enhance DevOps collaboration, create new product and service offerings and obtain deeper insight into customer behavior. Being named Best Business App...
Jan. 25, 2015 10:30 PM EST Reads: 1,737
The Industrial Internet revolution is now underway, enabled by connected machines and billions of devices that communicate and collaborate. The massive amounts of Big Data requiring real-time analysis is flooding legacy IT systems and giving way to cloud environments that can handle the unpredictable workloads. Yet many barriers remain until we can fully realize the opportunities and benefits from the convergence of machines and devices with Big Data and the cloud, including interoperability, ...
Jan. 25, 2015 07:45 PM EST Reads: 2,292
The move in recent years to cloud computing services and architectures has added significant pace to the application development and deployment environment. When enterprise IT can spin up large computing instances in just minutes, developers can also design and deploy in small time frames that were unimaginable a few years ago. The consequent move toward lean, agile, and fast development leads to the need for the development and operations sides to work very closely together. Thus, DevOps become...
Jan. 25, 2015 07:00 PM EST Reads: 2,324
SYS-CON Media announced that Cisco, a worldwide leader in IT that helps companies seize the opportunities of tomorrow, has launched a new ad campaign in Cloud Computing Journal. The ad campaign, a webcast titled 'Is Your Data Center Ready for the Application Economy?', focuses on the latest data center networking technologies, including SDN or ACI, and how customers are using SDN and ACI in their organizations to achieve business agility. The Cisco webcast is available on-demand.
Jan. 25, 2015 07:00 PM EST Reads: 1,193
Datapipe has acquired GoGrid, a provider of multi-cloud solutions for Big Data deployments. GoGrid’s proprietary orchestration and automation technologies provide 1-Button deployment for Big Data solutions that speed creation and results of new cloud projects. “GoGrid has made it easy for companies to stand up Big Data solutions quickly,” said Robb Allen, CEO, Datapipe. “Datapipe customers will achieve significant value from the speed at which we can now create new Big Data projects in the clou...
Jan. 25, 2015 06:30 PM EST Reads: 1,558
IoT is still a vague buzzword for many people. In his session at @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, discussed the business value of IoT that goes far beyond the general public's perception that IoT is all about wearables and home consumer services. He also discussed how IoT is perceived by investors and how venture capitalist access this space. Other topics discussed were barriers to success, what is new, what is old, and what th...
Jan. 25, 2015 06:15 PM EST Reads: 3,778
The Internet of Things (IoT) is rapidly in the process of breaking from its heretofore relatively obscure enterprise applications (such as plant floor control and supply chain management) and going mainstream into the consumer space. More and more creative folks are interconnecting everyday products such as household items, mobile devices, appliances and cars, and unleashing new and imaginative scenarios. We are seeing a lot of excitement around applications in home automation, personal fitness,...
Jan. 25, 2015 06:00 PM EST Reads: 2,697
Security can create serious friction for DevOps processes. We've come up with an approach to alleviate the friction and provide security value to DevOps teams. In her session at DevOps Summit, Shannon Lietz, Senior Manager of DevSecOps at Intuit, will discuss how DevSecOps got started and how it has evolved. Shannon Lietz has over two decades of experience pursuing next generation security solutions. She is currently the DevSecOps Leader for Intuit where she is responsible for setting and driv...
Jan. 25, 2015 06:00 PM EST Reads: 1,394
Dale Kim is the Director of Industry Solutions at MapR. His background includes a variety of technical and management roles at information technology companies. While his experience includes work with relational databases, much of his career pertains to non-relational data in the areas of search, content management, and NoSQL, and includes senior roles in technical marketing, sales engineering, and support engineering. Dale holds an MBA from Santa Clara University, and a BA in Computer Science f...
Jan. 25, 2015 06:00 PM EST Reads: 2,966
The Internet of Things (IoT) promises to evolve the way the world does business; however, understanding how to apply it to your company can be a mystery. Most people struggle with understanding the potential business uses or tend to get caught up in the technology, resulting in solutions that fail to meet even minimum business goals. In his session at @ThingsExpo, Jesse Shiah, CEO / President / Co-Founder of AgilePoint Inc., showed what is needed to leverage the IoT to transform your business. ...
Jan. 25, 2015 04:30 PM EST Reads: 3,005
SYS-CON Media announced today that PagerDuty has launched a popular blog feed on DevOps Journal. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. DevOps Journal brings valuable information to DevOps professionals who are transforming the way enterprise IT is done.
Jan. 25, 2015 04:00 PM EST Reads: 1,334
Things are being built upon cloud foundations to transform organizations. This CEO Power Panel at 15th Cloud Expo, moderated by Roger Strukhoff, Cloud Expo and @ThingsExpo conference chair, addressed the big issues involving these technologies and, more important, the results they will achieve. Rodney Rogers, chairman and CEO of Virtustream; Brendan O'Brien, co-founder of Aria Systems, Bart Copeland, president and CEO of ActiveState Software; Jim Cowie, chief scientist at Dyn; Dave Wagstaff, VP ...
Jan. 25, 2015 04:00 PM EST Reads: 2,416
SYS-CON Events announced today that CodeFutures, a leading supplier of database performance tools, has been named a “Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9–11, 2015, at the Javits Center in New York, NY. CodeFutures is an independent software vendor focused on providing tools that deliver database performance tools that increase productivity during database development and increase database performance and scalability during production.
Jan. 25, 2015 04:00 PM EST Reads: 1,536
SYS-CON Events announced today Isomorphic Software, the global leader in high-end, web-based business applications, will exhibit at SYS-CON's DevOps Summit 2015 New York, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Isomorphic Software is the global leader in high-end, web-based business applications. We develop, market, and support the SmartClient & Smart GWT HTML5/Ajax platform, combining the productivity and performance of traditional desktop software ...
Jan. 25, 2015 03:00 PM EST Reads: 2,691
Cloud Technology Partners on Wednesday announced it has been recognized by the Modern Infrastructure Impact Awards as one of the Best Amazon Web Services (AWS) Consulting Partners. Selected by the editors of TechTarget's SearchDataCenter.com, and by votes from customers and strategic channel partners, the companies acknowledged by the Modern Infrastructure Impact Awards represent the top providers of cloud consulting services for AWS including application migration, application development, inf...
Jan. 25, 2015 03:00 PM EST Reads: 1,195