Guide to the TechWeb Network











Vulnerability in Encrypted Info
By Nathan Conz
Feb 26, 2008 at 03:25 PM ET

Having just written about how insurers' view information security, I took special interest in a recent New York Times article, entitled Researchers Find Way to Steal Encrypted Data, that reported that a Princeton University group has discovered a frighteningly simple way to steal encrypted data stored on computer hard disks. You know, like the encrypted data that some insurance carrier employees have on their laptops.

from the New York Times:

The technique, which could undermine security software protecting critical data on computers, is as easy as chilling a computer memory chip with a blast of frigid air from a can of dust remover. Encryption software is widely used by companies and government agencies, notably in portable computers that are especially susceptible to theft.

...

The move, which cannot be carried out remotely, exploits a little-known vulnerability of the dynamic random access, or DRAM, chip. Those chips temporarily hold data, including the keys to modern data-scrambling algorithms. When the computer's electrical power is shut off, the data, including the keys, is supposed to disappear.

This got me thinking about something WellPoint vice president and chief security officer Shamla Naidoo told me when I spoke with her for my recent feature: "What we see as challenges today may no longer have the same priority in three to five years if insurers find there are new risks they haven't considered yet."

Could this recent news regarding the vulnerability of encrypted data be one of the new risks to which Naidoo was referring?

Whenever I interview insurers about new mobile initiatives, including those that involve laptops, I always ask how they plan to keep their customers' private information secure. And 99% percent of the time, the only security measure that's in place is encryption.

That used to be enough, it seems, but perhaps that's not the case anymore. A few insurers have already taken the next steps to secure sensitive data on laptops and mobile devices. Some have the capability to remotely wipe a device that is reported stolen or missing. Others have leveraged biometrics to make it exceedingly more difficult to access a device.

Hopefully, others will follow suit. There are many technology areas where it is advantageous for a carrier to be proactive rather than reactive, but none where it is more critical than information security.



Topics: What We're Reading



COMMENTS




This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in the message center do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this forum becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.

Important Note: The Message Center is NOT intended for commercial messages or solicitations of business.









Face-to-Face Events:
November 2-5, 2008
Insurance & Technology's 10th Annual Executive Summit








CSC Would like to congratulate this Year's Tech Savvy CEOs.
More than 700 organizations rely on CSC’s industry-leading P&C software and outsourcing services to support growth and create new sources of business value. Backed by more than 30 years of experience, no other company is more skilled at delivering results for P&C companies. When you go with CSC, you become part of a vibrant community with thousands of insurance professionals focused on innovation. CSC makes business transformation practical. Learn more at csc.com/industries/insurance/casestudies.


INSURANCE & TECHNOLOGY CAREER CENTER
Function:
Information Technology
Engineering

Keyword(s):

State:
Post Your Resume
Employers Area
News & Features
Blogs & Forums
Career Resources

Browse By:
State | City
Most Recent Posts: open | close





WHITEPAPER
ACORD Made Easy with XQuery
Learn how DataDirect XQuery helps organizations quickly and cost-effectively implement ACORD-based standards and maintain compliance. A high-performance, scalable XML solution, DataDirect XQuery dramatically improves developer productivity and enterprise deployment timelines.







MEDIA NETWORK


RESOURCE CENTERS
Policy Administration Resource Center
Policy administration has become the focal point of many insurance companies’ hopes and goals – in terms of gaining more insight into policyholders, and improving loyalty/retention – as well as their most difficult challenges, in terms of legacy systems issues, compliance and information management.

Outsourcing Resource Center
Find out from industry leading analysts what kind of value and cost savings outsourcing can provide to insurance companies by visiting Insurance & Technology's Outsourcing Resource Center, which also provides outsourcing best practices, timely research, case studies and more.

Topics:

techweb
Online Communities TechWebInformationWeekLight ReadingIntelligent EnterprisebMightyNetwork ComputingDark ReadingDigital LibraryWall Street & Technology
Byte & SwitchNo JitterInternet EvolutionLight Reading's Cable Digital NewsContentinopleUnStrungBank Systems & TechnologyAdvanced TradingInsurance & Technology
Face-to-Face Events
InteropWeb 2.0 ExpoWeb 2.0 SummitVoiceConBlack HatCSISoftwareEntrprise 2.0 ConferenceGTEC
Mobile Business Expo
InformationWeek 500 ConferenceBuy Side Trading XchangeBuy Side Trading SummitBank Executive SummitInsurance Executive SummitTelcoTVEthernet ExpoOptical Expo
Magazines  
InformationWeekWall Street & TechnologyInsurance & TechnologyBank Systems & TechnologyAdvanced TradingMSDNTechNetSmart EnterpriseThe Architecture JournalDatabase Magazine
 
Research & Analyst Services  
Heavy ReadingInformationWeek ReportsInformationWeek Analytics
 
   
   
Ed Cals  |  Contact Us  |  Reprints  |  Ad Info  |  Media Kit  |  Send Us Your Feedback  |  RSS