Editor : Martin Simamora, S.IP |Martin Simamora Press

Kamis, 16 Desember 2010

Secure Flash Drives Lock Down Your Data

Hollywood makes secure flash storage look easy. If the bad guy steals a thumb drive, it either blows up or some secret counterintelligence agency marshals the nation's resources in a no-holds-barred data hunt--most likely with Bruce Willis or Tommy Lee Jones working the streets. If the good guy steals the drive, it goes to a special-needs, special-deeds sidekick in a basement somewhere who cracks the code in 5 minutes.

That's the Hollywood treatment, but--exaggerations aside--it contains some elements of truth. Flash drive security is readily available, and some of it is free. Ease of use, however, is another matter.
Secure flash drives give security-conscious users a great way to transport sensitive information. And you can work directly off of such drives so that their top-secret data never resides in another location--except on a secure online backup service, of course.


The three basic approaches to securing data on a flash drive involve using software, hardware, or a combination of both.
The simplest, least expensive way to secure your data is to use a program such as 7-Zip to create encrypted archives on your flash drive. The obvious drawback of this method is that you must have the appropriate decryption software on any PC that you want to access the data from. (A portable version of 7-Zip is available, however.)

A slightly more elegant solution is Encrypt Stick, which also resides on the flash drive as a portable application but is designed solely for secure storage.
Easier yet is a secure flash drive that, upon being inserted into a PC's USB port, automatically runs software by tricking the operating system into thinking that you've inserted a CD. This software resides on a small CD emulation partition; the rest of the drive is used for storage. Variations on this approach run the gamut from simply providing access to the encryption program (as with the CMS Vault OTG) to hiding the data partition until you've run its control panel and entered a password to enable it (which is the method that IronKey Personal S200 uses).
A hardware-only product has special appeal to businesses and other security-conscious organizations that don't want and won't allow users to insert any type of executable file from a flash drive into their systems. Any type of software on a flash drive is vulnerable to tampering.

Hardware-only options include the Lok-It drive from Systematic Development Group, which requires the user to enter a PIN, using the buttons on face of the drive. Though it's a nice product, Imation's Defender F200 is the hands-down winner for cool, softwareless ease of use. The drive has a biometric finger scanner on top, which requires no software intervention when used alone. The F200 also uses the CD trick, but only for the configuration software or for additional password protection.
How Many Bits Are Enough?
No matter which hardware or software product you choose, it pays to know what type of security the item uses.
Any number of programs offer AES 128, 192, or 256. AES (Advanced Encryption Standard) is a symmetrical ciphering system--which means that it uses the same password or key to encrypt and decrypt data--and 128, 192, and 256 represent the number of bits in the key. The greater the number of bits, the larger the number of possibilities a cracking program must try to ensure that it will come up with the right one.

Because of the current choice between 32-bit and 64-bit computing and operating systems, you may know that an unsigned 32-bit binary number can be anything up to about 4.3 billion (4GB), and an unsigned 64-bit number can be up to about 18.4 quintillion. It follows that 128-bit, 192-bit, and 256-bit numbers areimmense, and they have names you've probably never heard of.

Though computers are fast, they aren't fast enough to crack numbers at those sizes in a reasonable amount of time. At today's processing speeds, a brute-force attack that tried every possible solution would take billions of years (on average) to crack a 256-bit number--assuming that the person who created the password chose a full-strength password that used all of the bits. The larger the number, the slower the encryption or decryption--but for the modest amounts of data we're talking about here, that's generally not an issue.

Government Standards
If you're planning to transport a working recipe for cold fusion, you might want to confirm that your portable drive satisfies a high level of FIPS 140-2 (Federal Information Processing Standard, Publication 140-2). FIPS 140-2 isn't a technology, but a definition of what security mechanisms should do.

There are four FIPS 140-2 levels. Level 1 involves using an approved encryption algorithm (such as AES 256). With level 2, the encryption is supplemented by a means to reveal tampering. Level 3 adds protection for the encrypting mechanisms and algorithms themselves. And with level 4, you add physically daunting packaging and fry the data and decrypting mechanisms if a breach occurs. At last, Mission Impossible!
The Imation Defender F200 has been validated for level 3 security. Validation is an expensive process performed by a trusted partner of the company; it can take 12 to 18 months. More commonly in the product packaging or advertising, you'll see an indication such as "FIPS compliant," as with the IronKey Personal S200, which simply means the device follows the guidelines. Lexar's JumpSafe S3000 FIPS says that the product is "designed to meet," which might mean nothing more than that the company read the government's 140-2 guidelines.
What You Want
For most users, the free software approach is adequate, though not particularly convenient. Auto-run flash drives are a bit easier, and they carry only small price premiums. Full on, software-less, Hollywood-like magic such as the Defender F200 costs you four, five times or more per gigabyte than a plain drive, but the convenience and wow factors are huge.

(NetWorkWorld)




Navy's Electromagnetic Railgun Pumps Out World Record Blast

The US Navy has fired off what it called a world-record, mach 5 velocity shot of its high-energy electromagnetic railgun it says can now hit targets 110 nautical miles away.
The record is the fact that the gun generated 33 megajoules of energy upon firing, the Navy stated. A megajoule measures the amount of energy associated with a mass traveling at a certain velocity, the Navy stated. A one-ton vehicle moving at 100 mph equals a megajoule of energy.

On the ocean, the railgun would gather electricity generated by the ship and store over several seconds in the system's pulsed power system. Next, an electric pulse is sent to the railgun, creating an electromagnetic force accelerating the projectile to Mach 7.5, the Navy stated. Ultimately the Navy wants the gun to fire projectiles more than 200 nautical miles.

In 2008, the Navy test-fired a 10-megajoule shot.

Such systems have a number of advantages. First they let a ship stand further offshore to deliver ordnance, protecting sailors. Onboard, the system doesn't require ordinary shells etc, further boosting safety.

NASA recently said it was looking into rail gun-like technology as a way to blast spacecraft into space hitting speeds of about Mach 10. The craft would then return and land on a runway by the launch site.

The rail launcher, known Advanced Space Launch System is one of a few new launch systems a team of engineers from Kennedy Space Center and several other NASA centers are looking at that would use existing cutting-edge technologies to offer the space agency a next generation launcher to the stars, NASA stated.


(NetworkWorld.com)

McDonald's Warns Customers about Data Breach

McDonald's (U.S) is warning customers who signed up for promotions or registered at any of its online sites that their e-mail address has been compromised by an unauthorized third party.
The customer name, postal address, phone number, birth date, gender, and information about promotional preferences may also have been exposed, the company said in an FAQ on its Web site. Social Security numbers were not included in the database, the company said.

The data was managed by an e-mail database management firm hired by Arc Worldwide, a "longtime business partner" of McDonald's, according to a recorded message on the company's toll-free number. The unnamed database management firm's computer systems were improperly accessed by a third party, McDonald's said.

McDonald's did not disclose the number of records involved or when the breach happened. McDonald's representatives did not immediately return a call seeking comment this morning.

"This incident has nothing to do with credit card use at the restaurants," the FAQ says. "The database that was accessed by the unauthorized third party did not contain any credit card information or any other financial information. Further, the information in the database was not gathered from our restaurant registers, but from voluntary subscriptions to our websites or promotions."

McDonald's is informing customers by sending e-mails to people who subscribed on the sites and has notified law enforcement authorities. The company advised customers to be wary of anyone calling them reporting to be from McDonald's and to report it to the company if that happens.



(ZDNetAsia)



E-govt Services to See 'Dramatic Change'

Governments around the world would like to move from their legacy infrastructure to more effective, unified IT systems yet many are ill-equipped to do so, said a senior Microsoft executive.
Craig Shank, associate general counsel of Microsoft Corporation, explained that many of today's e-government portals and backend systems are a digital implementation of their paper-based predecessors. While this leap into the digital age has resulted in a slightly more efficient mode of communicating with citizens, it is still not a "transformative" system, he added.

Furthermore, the public sector is facing a similar data deluge that its private sector counterparts are experiencing. These two factors are impeding the timely access of relevant data to citizens, the executive pointed out to ZDNet Asia at the sidelines of a technology forum held here Tuesday.

Shank's observation reiterates the fact that citizens perceive governments to be unresponsive online. According to an earlier survey conducted by the U.K.-based Economist Intelligence Unit, businesses and citizens point the finger to unresponsive public officials as the reason for the slow adoption of e-government services.

While acknowledging that there's "quite a bit of work to be done", Shank expressed confidence that the world will see a "dramatic change" in the way e-government services are delivered in the future. To achieve this, though, all parties involved ought to be looking into issues such as specific interoperability between existing and new IT systems as well as the re-architecting and redeveloping of new systems to achieve transformation, he added.

For instance, new technologies must respect legacy systems, particularly the data that sits in existing databases. To address this challenge, the Microsoft executive recommended "some level of capability" that can cut horizontally across multiple government systems to access the various silos of information.

He cited how the Portuguese government merged four identity systems into one as a positive example. The exercise involved the project partner taking the original Linux, mainframe and Windows server systems to build a horizontal layer that was able to access data in all the systems. With this unification, citizens can now, for example, use their driving licenses to access health care services, he stated.

"That's the kind of [transformation] we can anticipate seeing going forward," Shank observed.

Asked if emerging markets are less receptive toward such IT transformation, Shank disagreed. He pointed out that besides Asian countries, Latin America, for one, is very keen on harnessing innovation for the future.

"[However,] I think each market has its own specific sets of challenges that it will have to deal with, and there isn't a single solution," he surmised.

As with most technological advances, there is no fixed timeframe but he advised that it will be a journey that spans beyond 5 or 10 years.

Cloudy prospects
Another area of interest for governments is cloud computing, the associate general counsel noted. For the public sector, such a deployment will increase efficiencies, provide cost savings and become a driver to make IT systems more heterogeneous and nimble, Shank said.

However, challenges surrounding data storage location, access, jurisdiction, law enforcement, privacy rights and security issues are pressing matters that no one has answers to, he noted.

"Today, there is the possibility that one can be trapped in an absolute impossible situation with cloud computing, where data responsibilities of its stored location is in direct conflict with the data responsibilities where the services are being developed," Shank observed.

He did add that Microsoft is actively engaging governments in the region on these challenges, but there are certain "hurdles" that will have to be ironed out before governments jump on to the cloud bandwagon.



(ZdNetAsia)

Rabu, 15 Desember 2010

MasterCard SecureCode Service Impacted in Attacks Over WikiLeaks

The attacks against MasterCard by WikiLeaks supporters that knocked the credit card company's Web site offline today may have caused more problems than previously thought.

MasterCard itself has so far said publicly only that its corporate Web site experienced availability issues as a result of a sustained distributed denial of service (DDoS) attack against the site. In a statement this afternoon, the company said that it was making progress addressing the issue and that no customer transactions had been affected.

It now appears that the company's Securecode service for secure online transactions was also affected. It's not clear, however, whether the SecureCode problems were caused by Anonymous, the group that knocked MasterCard's corporate site offline after the attacks began about 4 a.m. ET.

In multiple bulletins to transaction processing companies , the company said that MasterCard and Maestro transactions could not be processed via SecureCode because of a service disruption to the MasterCard Directory Server.

The server has been since failed over to a secondary site, but customers could still experience intermittent connectivity issues, MasterCard said. It did not offer a timetable for when it hopes to restore full service.

A MasterCard spokeswoman confirmed the disruptions to the SecureCode service, but insisted that online transactions had not been affected. Instead, there were "isolated reports" of SecureCode service slowdowns reported, she said, adding that SecureCode service has been restored to normal.

Meanwhile MasterCard rival Visa, which has also been under a DDoS attack, was finally knocked offline this afternoon. Visa's main corporate site appears to have been hit by two separate attacks according to Sean-Paul Correll, a researcher with PandaLabs. Correll has been maintaining a regularly updated blog on the unfolding attacks.

The first attacks against the site started last night after midnight ET and resulted in intermittent service disruptions for several hours. No group has so far claimed responsibility for those attacks, Correll said.

Then at about 4 p.m. ET today, the company was hit with another DDoS attack -- this time by Anonymous, the group of loosely affiliated hackers that has vowed to attack organizations seen as attempting to censor WikiLeaks.

In a statement, Visa said that its corporate Web site Visa.com was "currently experiencing heavier than normal traffic" and said it hoped to restore full site operations in the next few hours. "Visa's processing network, which handles cardholder transactions, is functioning normally and cardholders can continue to use their cards as they routinely would. Account data is not at risk."

Anonymous, which has also been attacking entertainment industry sites over copyright enforcement issues, this week launched Operation: Avenge Assange. It is targeted at "entities involved in censoring [WikiLeaks'] information."

So far, the group is believed to have been behind the attacks on MasterCard, Visa, Swiss payment transaction firm PostFinance , PayPal, EveryDNS and others. All of the targets recently announced plans to terminate service for WikiLeaks after the site began releasing confidential U.S. State Department cables.

In addition to these attacks, Anonymous has also launched attackes on the Web sites of Sen. Joseph Lieberman (I-Conn.), former Alaska Gov. Sarah Palin and the Web sites of the Swedish prosecutors who are pursuing rape charges against WikiLeaks founder Julian Assange.



(networkworld.com)
Jaikumar Vijayan covers data security and privacy issues, financial services security and e-voting for Computerworld. Follow Jaikumar on Twitter at @jaivijayan or subscribe to Jaikumar's RSS feed . His e-mail address is jvijayan@computerworld.com .

Pro-WikiLeaks Cyber Army Gains Strength; Thousands Join DDoS Attacks

The retaliatory attacks by pro-WikiLeaks activists are growing in strength as hackers add botnets and thousands of people download an open-source attack tool, security researchers said today.


In recent days, distributed denial-of-service (DDoS) attacks have been launched against several sites, including those belonging to Amazon, MasterCard , PayPal and the Swiss payment transaction firm PostFinance, after each terminated WikiLeaks accounts or pulled the plug on services.

As of Thursday, WikiLeaks had posted the full text of more than 1,200 leaked U.S. State Department cables from its trove of over 250,000 messages.

Most of those participating in the attacks are using the LOIC (Low Orbit Ion Cannon) DDoS tool, said researchers with Imperva and Sophos.

The open-source tool, which is sometimes classified as a legitimate network- and firewall-stress testing utility, is being downloaded at the rate of about 1,000 copies per hour, said Tal Be'ery, the Web research team lead at Imperva's Application Defense Center.

"Downloads have soared in the last two days," said Be'ery in an interview. As of 4 p.m. ET, more than 44,000 copies of LOIC had been downloaded from GitHub.

LOIC has become the DDoS tool of choice in the pro-WikiLeaks attacks because users can synchronize their copies with a master command-and-control server, which then coordinates and amplifies the attacks.

"If I download [LOIC] and voluntarily set the server information, the command-and-control server can control my copy of LOIC," said Be'ery. "The command-and-control server can then sync the attack, which makes it much more powerful because the DDoS attacks are occurring at the same time and hitting the same target."

Some will still want manually control LOIC, Be'ery said, calling those people "old school guys." But even then, the attacks are being coordinated.

"They're just syncing their attacks to the announcements made on Twitter and IRC (Internet Relay Channel)," Be'ery said, referring to the messages posted by several hacker groups, including Anonymous, which has been in the forefront of what's called "Operation Payback."

In a new step in the campaigns, botnets -- armies of already-compromised computers that hackers control remotely -- are now being recruited for the DDoS attacks, said Beth Jones, a senior threat researcher with Sophos. "Until now, the attacks have been done by volunteers who download LOIC," said Jones. "But now more groups are joining in with their botnets."

Be'ery said that Imperva had seen IRC chatter of at least one 100,000-PC botnet being thrown into the attacks.

"Operators of these attacks have repeatedly asked on IRC if someone can donate botnets," said Be'ery. "It looks like they feel the need for some more horsepower."

The fact that the organizers of Operation Payback are soliciting more firepower is a clue that they're not able to match the defenses erected by the sites they've targeted, said Be'ery. "They're having a bit of a problem. PayPal and others are doing good work to keep their sites alive, so they're after more machines and telling people [participating in the DDoS attacks] to do what they're told and focus on the targeted sites."

There seems to be something to Be'ery's point.

An attack launched earlier Thursday against Amazon.com by Anonymous appears to have fallen flat ; the group then dropped Amazon and instead directed its PCs and followers to again hammer a PayPal URL.

But for all the problems that Operation Payback's having, Be'ery doesn't believe the DDoS attacks have peaked. "There doesn't seem to be any decay in the download rate of LOIC," he noted. "I really don't think things will change unless one of the attacked companies tries to take down the main command-and-control server."

There is only one such server currently coordinating the attacks, he added, but the organizers claim that they have a backup on stand-by. "But if the main server falls, it will certainly give them some trouble regrouping," said Be'ery.

Jones of Sophos saw a different end game.

"What's really surprising is that so many people are willing to put themselves on the line legally," she said, pointing out that using a tool like LOIC to attack a site is illegal in most jurisdictions, including the United States.

"A more firm legal response may be helpful," Be'ery agreed. "I'm not even sure that everyone understands that what they're doing is illegal."

On Wednesday, Dutch police arrested a 16-year-old in The Hague for allegedly participating in the attacks against Visa, MasterCard and PayPal. The teen is to be arraigned in Rotterdam on Friday.

"The penny will drop when some of these guys are arrested," predicted Be'ery.








(Computerworld)
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworld.com .

Corruption Perceptions Index 2018

Why China is building islands in the South China Sea

INDONESIA NEW CAPITAL CITY

World Economic Forum : Smart Grids Explained

Berita Terbaru


Get Widget