Showing posts with label encryption software. Show all posts
Showing posts with label encryption software. Show all posts

Thursday, August 11, 2016

What Is Encryption And How Can It Work For Me?


Image courtesy of Intel Free Press at Flickr.com
We truly live in an era where information has become one of the most traded commodities available. Is it possible to ensure that the information we send, receive, create and store in our devices stays safe and accessible only to those you want to share it with?

The use of encryption software has been associated with paranoid conspiracy-theory enthusiasts who believe the government is out to get them and wants to steal their information. However, as ridiculous as it may sound, they are not entirely wrong. Your information can be at risk but not exactly the way you think. Identity theft, hacking, state-sponsored snooping and even advanced steps of social hacking may take place by violating your electronic privacy accessing your files, pictures and personal computer content.

You’ve probably heard the word “encryption” many times before but are unsure of what it means exactly, how it works and what can you do to take advantage of its benefits.

First of all, encryption is a method of protecting information in a way so that only those intended by you are able to access it. Using encryption is not something new, and the basic concept of it remains the same even if the tools available to encrypt have changed. Rudimentary forms of encryption have existed since the times of the Old Kingdom of Egypt when non-standard hieroglyphics were carved in monuments. It wasn’t until around 800 AD when Al-Kindi invented a frequency-analysis technique for breaking mono-alphabetic substitution ciphers, something that proved to be the most fundamental cryptanalytic advanced until WWII.

Encryption uses algorithms to jumble data into a string of code that is complete gibberish to those who do not have permissions to see the information. Those permissions come in the form of an encryption key that decodes the information and rearranges characters and code so it can be read the way it was meant to and without the key it is impossible to decrypt the data.
Data can be encrypted in transit, meaning when the information is traveling towards its destination; or at rest, when the data is stored at a terminal or server. End-to-end encryption for communication platforms is considered the most secure. If messages are end-to-end encrypted, only the people who are having the conversation have the keys to decrypt what’s being sent.

Software for encryption is very easy to use nowadays and it doesn’t take much to get started. Here you can see a very easy info-graphic showing you all the necessary steps to do basic encryption for folders in different operative systems. 

It is important to choose an encryption key length that is strong enough to withstand any attacks or attempts to decrypt your data. An AES 128-bit encryption key is considered suitable for your security needs as it can have more than 300,000,000,000,000,000,000,000,000,000,000,000 key combinations.  
Encryption software gathers random data before encrypting your files, also known as entropy. The password you use will be part of this random data gathered to cipher the files, this is why it is very important that you choose a long passphrase, in addition, you should not use any dictionary words to avoid brute force attacks. A brute force attack consists of an automatic process where all of the dictionary words are quickly input at the password login window. As computers have become increasingly faster this can be done in a matter of hours or less using cloud computing.

Here are some tips to follow:
Image courtesy of Kevin Spencer at Flickr.com
  • Always choose an encryption program that uses a standard cipher that has been approved and tested by experts, like AES for example.
  • Do not use common dictionary words as your password, use a long passphrase made up of capital and small letters with punctuation signs and numbers that will remember and try not to write it down anywhere
  • Do not use the passphrase you use to encrypt your data for anything else like your email, Facebook or any other computer password.
  • Never trust a third party service to store your encryption keys or carry out the encryption implementation, if you store data online encrypt it yourself in your computer before uploading it.
  • Watch out for key-loggers and malware in your computer that could capture your keystrokes and your secret passphrase, use an antivirus and firewall and always keep it up to date.
  • Never reveal to anyone your password, not even to a support department whose staff could be outsourced overseas or could be impersonating someone else. Always verify personnel before giving out any of your information over the phone
All of your information is valuable and should be protected, so take the necessary steps and get in the positive habit of encrypting your files and your communicated over the web.

If you want to learn more about encrypted communications and more advances in telecommunication technologies, be sure to check out our many articles at our blog at Don Burns’ Blogspot.

Monday, March 14, 2016

Encryption Software at the Heart of Apple’s Battle with Government

A San Bernardino couple launched a deadly attack at a government rehabilitation center on December 2, 2015 that resulted in 14 deaths and more than 21 injuries. Aside from the firearms used, the cell phones of the suspects were the subject of intense law enforcement scrutiny. In order to determine a motive, investigators sifted through shipping records; interviewed co-workers, neighbors, and family; and even combed the suspects’ social media posts.

To date, federal investigators have been unable to get their hands on any information contained in the smartphone of suspect Syed Rizwan Farook due to Apple’s refusal to allow access to the server. The FBI issued a warrant for the data contained in Farook’s phone, but received a flat-out refusal from Apple. Apple cites privacy concerns that go beyond individual users and asserts that accessing data cannot be accomplished without potentially compromising the data security of millions of iPhone users.

How Apple Approaches User Privacy

In addition to the built-in encryption software, Apple has gone to great lengths to increase privacy from the user’s end. There is a two-step verification process that requires users to enter their Apple ID credentials for functions like making purchases, making account changes, or setting up a new device. In the event that an iPhone is lost or stolen, a user can access their iCloud account from another device and remotely lock the device to prevent information from being accessed. Remote Wipe allows users to completely erase data from the iPhone should it end up in the wrong hands.

Apple uses what are called tokens to transmit and store encrypted data on its iPhones. Tokens store information on the phone itself and on Apple’s servers, as well as in the cloud (Apple’s proprietary cloud software is called iCloud). The data is subject to high-level encryption that obscures credit cards stored in Apple Pay and passwords stored in Apple’s Keychain and emails, just to name a few.

These privacy features are so secure that Apple asserts that it cannot directly access the information stored on a user’s iPhone. While this eases fears of prying eyes accessing sensitive information, it presents a huge problem when law enforcement has a legitimate need to access phone data during an investigation.

Apple’s Encryption Software

Apple devices have been praised for their high level of security and the encryption in its devices. Although no device is 100% safe from unauthorized data access, Apple has gone to great lengths to protect user information. In fact, Apple’s encryption software is at the heart of the conflict with the FBI.

As details began to emerge about the San Bernardino shooters, officials attempted to access the data in Farook’s iPhone but thanks to encryption software it proved impossible. Apple’s software ensured that the phone’s data would be permanently erased after several unsuccessful password attempts. Once the FBI was made aware of how the data encryption software functions, it was compelled to request the data from Apple directly.

Apple CEO Tim Cook insists that the encryption software is so secure that the company itself cannot even access the information. Cook stated that in order to access data from any user’s phone, the code for the company’s encryption software would have to be completely rewritten. This would not only be a major undertaking for Apple, but it would essentially open the door to every iPhone owner’s personal information.

While this is certainly not the first time that Apple has been ordered by a court to unlock an iPhone, it is one of the first instances since the company rolled out the iOS 8 update in 2014. The update included encryption software that cannot be accessed by a third party or Apple. Previous iOS versions could be accessed in certain circumstances, especially when law enforcement requested the information. The update came on the heels of widely publicized iPhone data leaks – some of which involved celebrity photos – so Apple had a lot at stake and sought to quell criticism of its privacy protection efforts.

Current Issues

Although the company has cooperated with law enforcement in the past, Apple does not make it easy to access information, and each request is reviewed on a case-by-case basis, even if a search warrant is issued. According to the Apple website, “National security-related requests are not considered Device Requests or Account Requests and are reported in a separate category,” which may change the way that Apple handles requests similar to the ones related to the San Bernardino case.

Going forward, it’s uncertain if Apple will find a way to comply with the federal government’s request for information. The FBI is losing patience with Apple and has accused it of sympathizing with terrorists. In 2014, Cook said "[We] have never worked with any government agency from any country to create a backdoor in any of our products or services. We have also never allowed access to our servers. And we never will."

It appears Apple’s stance has not changed since then. Just last week, Los Angeles Court Magistrate Sheri Pym ordered Apple to allow the federal government access to Farook’s iPhone data. The order asks Apple to supply the federal government with software that would enable it to access data, but so far Apple is holding firm in its stance and has refused.