Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Security-Basics
[Top] [All Lists]

RE:Encrypting data on fileserver

Subject: RE:Encrypting data on fileserver
Date: Wed, 17 May 2006 16:05:02 -0400
On Tue, 16 May 2006 08:39:42 -0500, "Nick Vaernhoej"
<nick.vaernhoej@capitalcardservices.com> said:
We have VPN connections in place to prevent sniffing of traffic. I am
actually trying to prevent data theft happening in case of someone
walking out with a fileserver.
Sometimes management just knows better.....

Tell management that there are dangers in encrypting  filesystems.
No matter the OS, with encrypted filesystems there is always the
possibility of something going wrong and losing all of your data.
I won't go into details. Google it, there are many.
A much more foolproof and safer method is called 'Physical Security'.

On Wed, 17 May 2006 08:13:54 -0500, "Nick Vaernhoej"
<nick.vaernhoej@capitalcardservices.com> said:
We have a server room behind a keypass locked door. I am being told we
need to encrypt the fileserver because of PCI requirements. It seems we
have cardholder information in Excel spreadsheets....


As I stated earlier, encrypted filesystems carry the potential risk
of data loss. You are *much* more likely to lose all of your data
from an encryption key being hosed, or one of many other potentially
disastrous accidents happening, than in someone walking out of your
data center with a server. If someone did that, even if all of your
data 'was' encrypted, there is no guarantee that it will stop them.
Do you actually imagine that if a group of people were resourceful
enough to actually steal a server from a physically secure data
center that they are not going to have someone who can over come
your encryption scheme? The risks *far* out way the benefits.
The above scenario is an absolute fantasy, anyway.
Unfortunately, I used to work for a large bank so I understand a large
corporations management in strictly adhering to some draconian
security policy, even if it doesn't make any sense.
Good luck, your going to need it.
-- 
  Eric Furman
  ericfurman@fastmail.net

<Prev in Thread] Current Thread [Next in Thread>