Skip to main content

Is encryption just a waste of time?

posted onSeptember 29, 2008
by hitbsecnews

Faced with the thought of a USB drive, notebook PC or backup tape going missing, most IT managers look to some form of encryption as the first layer of defence. However, according to one storage security expert, that's largely a pointless exercise.

"I often refer to encryption as crypto fairy dust," Eric Hibbard, chair of the Security Technical Working Group in the Storage Network Industry Association, said in a recent interview. "A lot of IT managers sprinkle this on and think it makes certain problems go away."

The reality, Hibbard suggested, is rather different. "If you're doing encryption in the storage ecosystem, the pay off is very limited. A hard drive or tape drive wandering off is a real problem, but that's not a data confidentiality issue; it's a media confidentiality issue. If you're talking about sensitive information, encryption is just one tool in the toolbox. If you don't have that mated to tight authentication and access control, you're screwed."

Source

Tags

Encryption

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th