data privacy vs. ease of use vs. file sync and share, email encryption

11
Information protection for cloud services Data privacy vs. ease of use vs. file sync and share, email encryption. Dr. Günther Hoffmann DocRAID® data privacy

Upload: sophos-benelux

Post on 17-Jan-2017

340 views

Category:

Education


3 download

TRANSCRIPT

Information protection for cloud services

Data privacy vs.

ease of use vs.

file sync and share, email encryption.

Dr. Günther Hoffmann

DocRAID®

data privacy

Information protection for cloud services

Industrial espionage

Information protection

Compliance

IT security (availability, integrity,

confidentiality, …)

Legal framework

Save and share documents: team,

clients, customers, patients, …

any device,

any time,

any where

Requirements from multiple groups

Information protection for cloud services

… we encrypt !

Information protection for cloud services

Attack vectors

Individual attacks

Strategic reconnaissance

Standards, Implementation

Manipulation of IT components

… REALITY CHECK

Information protection for cloud services

… REALITYCHECK

Information protection for cloud services

Economy of password cracking

Brute force:

Hardware $290-$740

Million keys / second: 693 – 4200

Password length = 8 calculate in under 20h (2011)

Costs 2011 $2,39 - $5,86

Costs 2015 $0,50 – $1,50

Information protection for cloud services

Economy of password cracking

50% - 98% of passwords in

Rainbowtables or Dictionaries

Information protection for cloud services

Standards und

Implementierungen

Dual_EC_DRBG “BUG”

Information protection for cloud services

Security

Know-How

WebDAV

Expiration dates for accounts

Expiration dates for links

Share documents (up/down)

Code protection

Workspaces

Rights management

Individual architectures

Multiple jurisdictions

Double-verification

Firewall, white/black lists

Log-Files

Location based security

2-factor authentifikation

Windows, iOS, Android, Blackberry, …

REST API

Secure client for Windows

Security scales via know-how, platforms and devices

Preset security levels

Outlook

no single-point-of-failure

confidentiality, integrity and availablity

compliance ready

zero-knowledge-policy

keep legacy infrastructure

user processes remain unchanged

Unauthorized users that log or hack

into a cloud service will only see

fragmented and encrypted data, which

is unreadable

Protect your data in cloud services with DocRAID cloud encryption gateways

Instead of relying on cloud

service providers to encrypt data,

DocRAID protects sensitive data

before it leaves the secure enterprise

network, without changing the user

experience.

Information protection for cloud services

ContentPro AG / DocRAID®

Dr. Günther Hoffmann

[email protected]

Wilhelm-Kabus-Str. 25-31

10829 Berlin

Tel. +49-30-609898060