« More on visualizing data breaches | Main | Another non-alternative to encryption »

Thursday, 06 August 2009

I just don't get this one

Here’s another case where I just don’t get what the excitement is all about. In this case, it’s around the announcement of a new technology that identifies sensitive information on its way to a monitor and substitutes some sort of inoffensive pattern in place of the sensitive data. This technology is called Masking Gateway for Enterprises, or MAGEN.

I’m sure that this new technology is very impressive, but I’m also fairly sure that there’s going to be a better way to spend your security budget, like on encryption technology that protects the data both on its way to the monitor and after its displayed. You can even do this while keeping your encrypted data the same format at the unencrypted data, so integrating the encryption into existing applications really isn't that hard. You can encrypt a credit card number using format-preserving encryption, for example, and the encrypted credit card number will look just like an unencrypted one.

I haven’t heard of monitors being a big source of data leakage. What problem is this technology really trying to address?

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e55375ef1c8833011571319b22970c

Listed below are links to weblogs that reference I just don't get this one:

Comments

Andrew Yeomans

The two word answer is "legacy applications".

Format-preserving encryption may be good for new apps, but may cost quite a lot to retro-fit to existing apps. And some apps might need partial visibility of the data. I suppose you could create a FPE that also allowed the last four digits of a credit card number to be unencrypted, so a customer service person could check the right one was used. A bit harder to use any form of FPE on people's names.

Were you also thinking of Oculis http://oculislabs.com/ as a neat way of stopping shoulder surfing? And potentially cheaper than privacy filters.

Post a comment

If you have a TypeKey or TypePad account, please Sign In.

Voltage Data Breach Index

  • Grab the Voltage Data Breach Index

February 2012

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29