Security Information

Its Time to Sing the Encryption Song - Again!


Yes, I'm wearing my encryption hat again. Why you may ask? Well I just finished reading about the newest security hole in Microsoft's latest server product. Then couple that with all the recent hacker activity, new reports from the GAO (that's the Government Accounting Office) that the government can't protect it's own computers and data much less the data WE send them, reports that computer theft is on the rise and news that the FBI is now developing a new computer "worm" (read virus) to spy on citizens, I decided to sing the encryption song again. This time I'll sing a verse about personal data encryption.

So what do I mean by personal data encryption? I mean ANY data on ANY storage medium that relates to you, your family or your business. Encryption is the process of scrambling electronic data in such a way that it's unreadable to all but the owner.

For the purposes of this article I'll cover two different ways to encrypt data and the pros and cons of each.

The first way is file/folder encryption. This is the process by which someone identifies what data they want to protect on a file by file or folder basis and then encodes each file or folder using some kind of software encryption tool.

What are the pros of this style of encryption? First, each file or folder can be assigned its own "encryption key". Then, even if one key gets "cracked" open, all the other files or folders will still be safe. Next, only those files and folders you identify and select will be encrypted. This allows for a "gnat's behind" level of detail that some folks need to feel secure.

What are the cons of file or folder level encryption? Well, at this level of detail, tracking of all the different encryption keys and file locations would be an administrative nightmare! So, unless you have days to spend identifying files and folders and encrypting them or if you are really, really into details, file level encryption just isn't practical for most people.

The second way to protect personal data is drive encryption. Unlike file encryption, drive level encryption allows a user to create a reserved area on the hard drive called a container. Once created, this container can be "mounted" or set to act like another fully functional hard drive on a computer. It will appear in the file manager just like any other drive.

What are the pros for drive encryption? This space can be "mounted" using a single encryption key and the key only needs to be entered once. After it's mounted, this virtual drive can contain any data and / or program, just like any regular drive. But when it's dismounted, the virtual drive is no longer visible and the container looks like any other file, the contents of which are completely inaccessible without the encryption key.

What's the down side to drive encryption? If you forget your key, all the data and / or program information in the container is lost. Also, all the information is only protected by a single key. So if your key is compromised, all your information is available to prying eyes.

What's my recommendation? Drive encryption. Drive encryption is far more efficient than file encryption especially if you need to access your data frequently. Drive encryption also allows for the complete encryption of programs, something virtually impossible to do with file level encryption. (Well not impossible but certainly problematic and time consuming!) And by creating an encryption key of sufficient size and complexity, the single key issue becomes almost moot.

One site I visited recently stated that it would take one million computers performing one million operations per second approximately 11 trillion years to crack a 128 bit encryption key! So, by using an encryption key of about 64 random characters, a hacker would need multiple life times to crack open your files.

There are several programs available online for both file and drive encryption. All these programs differ in functionality, price, encryption algorithms and interfaces. The best way to proceed is to do a search from your favorite search engine on encryption tools and read about the options available.

Don't wait! The day will come when your system gets compromised by some hacker or thief or FBI agent and then you'll wish you had protected your data.

Privacy is your right! Exercise it!

Michael Ameye has been developing web sites since 1995. He started writing about online privacy issues to answer questions from family, friends and co-workers. Visit http://www.canyourspam.com to see his latest work.

He is also the chief editor of PSS Online, A Privacy, Safety and Security eZine dedicated to bringing important information to people in order to foster a safer more secure environment - online and off. Visit http://www.pssonline.info to subscribe.


MORE RESOURCES:

National Post

UN Security Council urges int'l action to fight Somalia piracy
Xinhua, China - 13 hours ago
UNITED NATIONS, Oct. 7 (Xinhua) -- The UN Security Council voted unanimously on Tuesday to urge states to deploy naval vessels and military aircraft to ...
Join hands against pirates along Somalian coast: UN Press Trust of India
UN chief sees obstacles to helping Darfur, Somalia The Associated Press
New Somalia piracy resolution adopted at UN AFP
AllAfrica.com - ReliefWeb (press release)
all 266 news articles


Homeland Security Capital Corporation Awarded $3.1 Million ...
WELT ONLINE, Germany - 10 hours ago
HSCC is an international provider of specialized technology-based radiological, nuclear, environmental, disaster relief, and security solutions to ...


Jerry L. Pettis Memorial VA Medical Center Awards $200000 Security ...
MarketWatch - 10 hours ago
By deploying BrightSite, the Jerry L. Pettis Memorial VA Medical Center will be able to unite more than 21 individual security systems into an integrated ...


Feds question Georgia’s checking of new voters
Atlanta Journal Constitution,  USA - 8 hours ago
Social Security Commissioner Michael Astrue said Georgia has asked the administration to verify the identities of nearly 2 million voters, more than any ...
Feds question new voter checks in 6 states The Associated Press
Feds question new voter checks in 6 states WTHI
Feds question 6 states' new voter checks, including Georgia NBC Augusta
Atlanta Journal Constitution
all 151 news articles


Vanguard Policy Manager Enhances RACF Security, Prevents Security ...
MarketWatch - 7 hours ago
This new software enables organizations to reduce security risks and meet regulatory compliance requirements while providing an immediate return on ...


Voice of America

Palin Rips Obama on Social Security 'Fear and Panic,' but Tangles ...
Washington Post, United States - 10 hours ago
John McCain's Social Security views, continuing her criticism of the Democratic nominee. "Beware! No presidential election cycle is complete without the ...
Video: Town Hall Debate - Humanitarian Deployments: Would you us... CSPAN
McCain-Obama Presidential Debate Analysis Dakota Voice
'Preventive medicine' wastes time, money Sun-Sentinel.com
all 1,535 news articles


FaceTime Unified Security Gateway Named Best Anti-Malware Gateway ...
MarketWatch - 14 hours ago
has awarded FaceTime Communications' Unified Security Gateway (USG) top honors in its recent live testing and review of the secure Web gateway appliance. ...


McCain at his best talking national security
Chicago Sun-Times, United States - 1 hour ago
But it was in the area of national security that McCain became a clear choice and was at his most presidential. "My hero is a guy named Teddy Roosevelt," ...


Q&A: E-voting security results 'awful,' says Ohio secretary of state
Computerworld, MA - 4 hours ago
... Standards & Testing" analysis, otherwise known as EVEREST, in which "critical security failures" were found in every system tested by several teams of ...
Red flags on voter records may lead to nothing Columbus Dispatch
all 36 news articles


Six essential Apple iPhone security tips
NetworkWorld.com, MA - 12 hours ago
By Al Sacco , CIO , 10/07/2008 If you're an Apple iPhone user and security's not on your mind, you're at risk; at risk of having a Web mail account hacked; ...

Security - Google News

home | site map
© 2006