Thursday, March 6, 2008

Portable Data

Maybe you’ve seen the article – Stolen VA laptop caught in safety net. The Veterans Administration (VA) made several policy improvements after the news story of 5/22/06


The Veterans Affairs Department today revealed that personal, identifying data
for as many as 26 million American veterans was stolen from a VA employee's home
in May. The information is a list of all veterans who served in the military and
were discharged since 1975.
I’m really glad organizations are starting to understand that the reason portable devices were created were to allow for people to have access to their electronic date from more places than just their desktop! Of course once they’re out of the office they are more at risk, but that’s the nature of the beast of being portable.

So – what data do you carry around town? Names, phone numbers, birthdates on your phone? Email on a PDA? A personal laptop with Quicken?

Window’s Vista’s BitLocker or Apple’s FileVault are both steps in the right direction. With most security topics it’s like the old joke

Q. you and a friend are in the woods when a Grizzly Bear decides you look
like breakfast and starts to chase you! how fast do you need to
run?
A. Faster than your friend!

If you have implemented anything to prevent identity theft, you’ll be ahead of most people. Depending on the sophistication of your thief – it should be enough, but these products are not perfect.

A write up from the SANS institute on ‘cold boot’ In memory of hard disk encryption?
With the appropriate replies from the vendors 'Cold boot' - vendor reactions
PGP: press release
Utimaco: original link broken now, new press release
Mobile Armor: note and press release
Winmagic: support note
GuardianEdge: news article
Bitlocker: blog (protection) and technical explanation
Pointsec: advisory
Bitarmor: article and press release
Jetico: FAQ entry related to a new release to mitigate "coldboot" effects



ps. for those of you keeping score, yes - this area would be a new one that we haven't talked about before adding a new dimension to your personal threat profile. :)

No comments: