Go Back   Wireless and Wifi Forums > News > Newsgroups > alt.computer.security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-19-2006, 12:30 AM
WB Randolph
Guest
 
Posts: n/a
Default Why Current Security Solutions Fail To Prevent Data Theft

I saw a story at net-security.org describing why current security
solutions might be unable to prevent data theft. It describes why
application password protection, disk encryption, file encryption, etc.
fail to prevent data theft so I submitted it here:

http://www.digg.com/security/Why_Cur...ent_Data_Theft

Googling about the story, I found this Flash video showing how password
protected Palm Treo 700p smartphone contacts can be exposed on a PC
running Palm Desktop, disk encryption, firewall, antivirus, etc.:

http://www.innersafe.com/demos/palm_...ure/index.html

It seems the situation is worse than the story (which doesn't even
mention keylogging):

1. disk encryption doesn't help while the disk is mounted (which can be
hours while we're online & using the disk)

2. file encryption requires decrypting to disk which can leave
sensitive data on disk even after the file is re-encrypted again (seems
NTFS and some thumb drives don't always overwrite files.)

3. keylogging software can pretty much steal passwords or file content
before it is encrypted which makes #1 and #2 worse

4. firewalls are vulnerable to insiders with physical access to PC's
and open ports people need to access the web or email.

5. antivirus and antispyware don't detect 100% of malware, require
signature updates, and doesn't address the fact a thief can use
uninfected programs for data theft.

6. password recovery tools can instantly extract passwords or reset
passwords of many popular file formats like Microsoft Outlook 2003 .PST
files.

7. When using EFS (Encrypted File System), "a file's original
unencrypted file data is left on the disk after a new encrypted version
of the file is created." according to Microsoft at
http://www.microsoft.com/technet/sys...s/SDelete.mspx

Besides the "don't run Microsoft Windows" or "don't store sensitive
data on PC's" type of advice, what can be done to secure sensitive data
on a PC?

What do you use today to secure your data? I know keypass and
truecrypt are free & popular, but is there anything better?

Is computer security even possible without spending a fortune?


Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Corrupt NTFS filesystem Citizen Bob alt.comp.hardware 144 11-11-2006 07:38 PM
FBI Monitoring Your Computer And Reading Material re. Patriot Act tightwad alt.computer.security 2 11-08-2005 09:21 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 07:10 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45