| There are numerous technological tools and resources that can help individuals preserve their online privacy. Some tools ensure that email communications are confidential, some allow users to browse webpages securely and others still ensure that files are encrypted before they are transferred between two computers. This article will explore some tools that a user might rely on to protect their online [...] Cryptography refers to the science of rendering information unrecognizable and thus useless to those without proper authorization. This field includes mathematics, computer science and engineering. While cryptography was initially applied to protect message confidentiality, it has grown to include issues such as privacy concerns, data integrity, identity authentication, secure computing and more. This article introduces the field of cryptography, defines the basic concepts of encryption and decryption and discusses related concepts. It also explores current uses of cryptography in the information security [...] Executive Order 13402 commanded the creation of a Presidential Identity Theft Task Force to examine how the Federal Government could better respond to and protect against data breaches resulting in identity theft. Under Federal regulations, such as the Privacy Act of 1974 and the Federal Information Security Management Act, individuals are guaranteed the security of their data, making adequate protection of data a matter of [...] In 2007, the Department of Homeland Security an Office of Management and Budget, along with the Presidential Identity Theft Task Force, investigated information privacy and security practices in the United States Government. They developed a report called the Common Risks Impeding the Adequate Protection of Government Information (pdf)which included a list of ten common mistakes made by U.S. departments and agencies and provided recommendations for new practices to be implement to eliminate and reduce security [...] Visiting the doctor’s office is a nightmare for the Data Privacy Professional. One glance at all that paper reaching as far as the eye can see and all containing so much PII. Nancy Northrup discusses a new encryption product which shows potential for slowing the persistence of the [...] The recently unveiled flaw in SSH reiterates the idea that, no matter how good the technology, it will eventually fail from a whole host of threats. In this case, the implementation flaw occurred in a software product that had been previously “proven secure”. Real world implementations are more complex than security models, and other mitigations must be in place when a design does finally [...] We had a chance to talk with Mr. Steven Elefant, Executive Director of end-to-end security at Heartland Payment Systems shortly after the security breach reportedly affecting hundreds of millions of credit card transactions. While the complete interview is available in the forums, we include a few excerpts in the articles section of the [...] Proposed legislation H.R. 2221 by Illinois Representative Rush seeks to preempts more restrictive privacy laws on the books in several states. While the Data Accountability and Trust Act handles several important information privacy issues, the State’s Rights infringement could hurt citizens’ [...] Over the weekend, I did a lot of reading on a company in the mail gateway business called Ironport. I mean a lot of reading. This was another consolidation (see Why behemoths buy startups & March 08′s Information Security Magazine’s Schneier/Ranum Face Off), with Cisco snatching up the market leader. I read about capabilities, product offerings, market penetrations, strategic positioning, competitors and magic quadrants. All of this was at the urging of a friend of mine at Cisco, and how this product would drive profits for the company for the next several quarters. I did a similar [...] Everyone wants a certain comfort level, especially with computers. You like finding your programs on your system. You want your bookmarks in FireFox or your buddy list on Instant Messenger. What if you were able to do carry all of this on a USB thumb drive? In fact, what if you were able to bring your entire “computer” with you on a USB memory stick? How could you hope to secure it against viruses, keystroke loggers, or even un-trusted/hostile networks? What about other users poking around for your files, or maybe reading your emails? Not [...] | |