Encryption Not All It's Cracked Up to Be: Assessing the Risks and the Cost

A new type of attack discovered by Princeton researchers demonstrates that encryption alone may not be an effective defense. Managing security is managing risk, and these tips can help show you whether encryption software and self-encrypting disks are worth the cost.

By Charlie Martin
Fri, April 04, 2008

CIO — With major data breaches occurring on a regular basis, encryption vendors are going into hyperdrive, touting the need for their products. However, encryption is only one aspect of protecting your sensitive data, and a new attack shows that it may not be enough.

Recently, the security research group at Princeton University published a report on its success at recovering data from an encrypted disk image on a laptop. This caused a good bit of consternation and some breathless coverage in the press (as with this New York Times story that got the headline "Researchers Find Way to Steal Encrypted Data"), leading to some speculation that this meant on-disk encryption was simply not worth the effort. (Read more on Laptop Encryption Strategies.)

The next morning, having read the New York Times, your CEO stops you in the coffee room and asks, "Is it worth using this disk encryption? It's a pain, and from this article it sounds like someone could get my data anyway."

The security community gets excited about any cool hack that can be exploited to get something you're not supposed to get, and we know that sometimes it's really an important issue. On the other hand, sometimes it isn't. How is a nonspecialist to know the difference, and how can a CIO answer the CEO's questions in the coffee room the morning after a story like this appears?

It turns out that we can answer this sort of question quickly with some good expectation of accuracy, using ideas from that half-remembered Finance 101 class we took years ago. What we're concerned with is the risk posed by this new attack, risk as defined in finance as the probability of the undesired event multiplied by the cost of the undesired event (which is called the hazard). We can manage security issues, first of all, by considering the risk.

Risk = Probability X Hazard

An easy way to see how this is applied is to think about the PIN on your ATM card. Most banks have simple policies for ATM cards: You have a four-digit PIN; there is a limit on how much cash can be taken out of the account every day, say $500; and there is a policy that says after three wrong PIN attempts, the ATM annoyingly eats your card, usually on Friday afternoon just before you leave for that weekend in Vegas.

Now, assume the card is lost, and someone is attempting to get money from it illicitly. The chances of guessing the PIN correctly with no extra information (you didn't write the PIN on the back of the card, right?) are 1 in 10,000 for one try, or about 1 in 3,333 for the three tries you get. The hazard is $500, so the risk is about 15 cents. In other words, the bank can be pretty confident that over many thousands of depositors and ATM cards, the cost of this kind of fraud per card is about 15 cents each.

Of course, with more data and a longer time to explore it, we could get a much better estimate that takes into account the people who do write the PIN on the back of the card, the people who manage to watch over your shoulder as you enter the PIN and so on, but remember, we're in the coffee room and the CEO doesn't want "I'll get back to you in a week or so when I've had time to research this." In any case, for many purposes this is good enough: If someone is trying to sell you a $5 solution to a 15-cent problem, it really doesn't matter much if the accurate answer is really 16.231 cents.

Evaluating Risk

So, how can we apply this to the problem of an encrypted disk? The attack the Princeton group outlined goes something like this: You have data stored on a disk, say on a laptop, that you have protected with a commercial disk-encryption program like Microsoft's BitLocker or Apple's FileVault. (Also read How to Lock Up Laptop Security.) A technically sophisticated attacker wants that data and has significant resources he can apply to the problem, including tools, a bottle of "canned air" and a computer with some specialized software. To execute the attack, the bad guy must first get the computer with the power on, or within a few minutes of the power being turned off; second, cool the memory chips in the computer to -50 C using the "canned air"; third, get the chips where they can be read by the attacker's computer; and finally apply a statistical method and some knowledge of the disk encryption to find and extract the keys. He can then read the data from the disk.

Can it be done? Sure: See the Princeton website for a description and even a video, but it isn't easy. Still, "It can be done, but it's hard" isn't necessarily reassuring in the coffee room on Monday morning; using a risk estimate, though, we can compare it to other possible problems.

To start with, how much is the data on the disk worth? Let's take an all-too-common example: Someone has copied the customer data for 100,000 customers to his laptop to work on over the weekend, and this data includes enough information to be of use to an identity thief. If this data were to be lost or compromised, your company would have to respond by, say, buying a year's credit monitoring service for each of the 100,000 customers, at a cost of about $20 each. So, from the standpoint of a potential loss, the data is worth around $2 million. (Let's stop and think about that number for a minute: two million dollars. The loss of a $2,000 laptop is nothing.)

Continue Reading

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Learn how to maximize control and minimize loss with SafeNet, the company that Frost & Sullivan named the "clear market leader" in software license management.
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications. The goal is to virtualize 75% of the environment by the end of 2012. This paper highlights the steps they are taking to overcome security challenges of virtualizing Internet-facing applications.
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions posed to three cloud infrastructure providers, three managed or hosted infrastructure providers, and three cloud technology providers. Compare their answers to questions on data protection, compliance, ROI and more.
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different endpoints. This guide provides recommendations for strengthening data, identity, and platform protection and will also walk you through seven key steps to plan your cloud security strategy from the ground up.
A recent IDG survey of businesses with 100-500 employees reveals data security is the top barrier to supporting employees' mobile devices. This KnowledgeVault highlights survey results and explores how IT leaders are dealing with issues from encrypting mobile data without impacting performance and remotely disabling devices, to dealing with the Apple App Store for iPad and iPhone apps.
If you are responsible for protecting retail systems, download this case study to learn how this retailer eliminated the threat of malware on their POS systems using Bit9's award winning solutions.
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents indicated they were not confident that their organization would be able to detect the loss or theft of sensitive personal information in their company's databases and applications.

Join featured guest Dr. Larry Ponemon from the Ponemon Institute, to discuss these new findings and how to best address the growing number of data breaches and privacy challenges that are facing your organization. This webinar will focus on:

- Understanding the current state of privacy and data protection in the production environment
- Identifying areas of greatest vulnerability
- Keeping data secure without sacrificing productivity
- Enterprise and configurable solutions for multiple applications
Date: Wednesday, May 23, 2012
Time: 11:00 a.m. PDT / 2:00 p.m. EDT

IT security faces challenges as never before. At one end of the spectrum, industrialized exploits hammer organizations with a volume and frequency of attacks that only a few short years ago would have been unimaginable.
Learn how IT teams can protect against spear phishing tactics. Harry Sverdlove, chief technology officer of Bit9 offers a frank discussion about spear phishing - the most common technique used in today's advanced attacks. Learn how spear phishing works and three recommendations for IT to protect against modern threats.
Download this eSeminar to hear from experts Ziff Davis Enterprise, VMware and HP and learn how client-side virtualization can improve your organization's performance, while reducing the IT burden of managing and maintaining an increasingly diverse client universe.
In this exclusive webcast from Viewfinity, you'll hear how to leverage Group Policy Object settings to close this vulnerability by elevating privileges for standard users.
Secure your servers and your mission critical applications with Application Whitelisting and on-demand antivirus for optimal security with comprehensive and integrated management.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links

Learn how Accenture helps clients become high-performing businesses

Choose New and slash the number of devices you manage

Customized information views & Twitter events at New Fulcrum Point

Splunk translates machine data into "aha" moments for IT and the business.

ManageEngine Desktop Central - Automate and Audit Your Desktop Management! Learn More...

Cloud Readiness Starts with Intel® Technology

Visit the Virtually There Learning Page to learn how to use virtualization to your competitive advantage.

High performance. Delivered. Click to see Accenture's client successes

CYBERMARYLAND | Learn Why Maryland is the Epicenter for Cybersecurity

Get Ethernet speeds from 1 Mbps to 10 Gbps - Comcast Business Class

Cognizant. Leading in Business, Application & Technology Services

Collaboration: driving better business outcomes

Managed Hosting Buyer's Guide - Benefits to key considerations

Click to see how Accenture has delivered high performance to clients

Learn how Accenture helps clients become high-performing businesses.

Choose New and manage one device instead of 170

Choose New for 8x the firewall and NAT performance

Check out a smart way of mobilizing your business with enterprise-ready Samsung Mobile.

Redefine your data center with HP servers.

Enhance your business with Windstream IT Solutions. Speak to someone local.

BlackBerry® Mobile Fusion. Different mobile devices. One platform.

Akamai Kona Security. Web security so you can innovate fearlessly

Click to see how Accenture has delivered high performance to clients

Free: Hunter Muller's "The Transformational CIO."

Join us for an upcoming Microsoft 365 live online demo event.

Discover your easiest path to unified communications

Virtualizing Your Infrastructure Just Got Easier

Gain cutting-edge insights at MIT in 2-5 day executive programs.

See how Accenture helps clients perform at the highest levels

Connect with global CIOs now at Enterprise CIO Forum

Resource Center