Feeds

iPhones and social networking add to IT security headaches

A security admin's life is not a happy one

Internet Security Threat Report 2014

RSA Europe 2009 The flood of consumer devices such as iPhones into the enterprise and workers giving away snippets of potential sensitive information via social networking sites have emerged as new threats in the information security landscape.

During a roundtable at the RSA Conference Europe 2009, in London, Herbert Thompson, chief security strategist at People Security, explained how snippets of information that might by themselves appear unimportant can be put together like a jigsaw to reveal potentially sensitive information. For example, a series of new LinkedIn recommendations referring to senior staff at a single company could be a sign of an imminent merger.

Alternatively it could suggest that workers at an organisation of interest are searching for jobs. “The data seems harmless but when you correlate it across a group of people it can become interesting,” Thompson explained. The risk adds to the better understood problem of individuals giving away potentially sensitive personal information, such as a time when they are away on holiday, via social networking sites such as Twitter. Micro blogging also poses a means for organizations to leak potentially sensitive morsels of information.

For example, if someone with a sales job says that they are flying to Bentonville for work it’s a fair bet that they are traveling to the headquarters of Wall-Mart since there’s little else in the town.

Data loss prevention is touted as a means of guarding against the leak of confidential information but “it’s no use to apply DLP technology without first classifying data”, explained John Madelin, head of professional services at Verizon Business. Educating users about the potential pitfalls of social networking is the best way of tackling the problem, he added.

Mobile devices in the enterprise pose another challenge but adopting security policies to control how smartphones such as the iPhone are used by enterprise users is rarely successful. Newer mobile technology is more stylish and fashionable than anything a corporation might supply.

Furthermore, firms are under cost pressure to allow workers to bring in their own devices.

Information security staff face more traditional threats alongside the new risks in areas such as application security. Web applications, in particular, remain a frequent source of security problems because developers are pushed to implement new features but not encouraged to think about security in writing new apps. “Security runs counter to usability, Thompson explained. “There’s also a trade-off between performance and security,” he added. ®

Internet Security Threat Report 2014

More from The Register

next story
George Clooney, WikiLeaks' lawyer wife hand out burner phones to wedding guests
Day 4: 'News'-papers STILL rammed with Clooney nuptials
Shellshock: 'Larger scale attack' on its way, warn securo-bods
Not just web servers under threat - though TENS of THOUSANDS have been hit
Apple's new iPhone 6 vulnerable to last year's TouchID fingerprint hack
But unsophisticated thieves need not attempt this trick
PEAK IPV4? Global IPv6 traffic is growing, DDoS dying, says Akamai
First time the cache network has seen drop in use of 32-bit-wide IP addresses
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Who.is does the Harlem Shake
Blame it on LOLing XSS terroristas
Researchers tell black hats: 'YOU'RE SOOO PREDICTABLE'
Want to register that domain? We're way ahead of you.
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.