Feeds

Truly secure clouds? Possible but not likely say Georgia Tech boffins

And that's before we hook up the Internet of Things

Choosing a cloud hosting partner with confidence

Georgia Tech has added itself to the chorus, nay, throng of voices warning that poorly-implemented cloud computing and the world of BYO mobile devices are threats to enterprise security.

In its Emerging Cyber Threats 2014 report, GT's Information Security Center joins World+Dog in noting that the Snowden NSA whistle-blowing has concentrated minds wonderfully on the question “who's reading my cloud?”

However, trying to secure what leaves the premises comes at a cost, says GTISC director Wenke Lee: “Encryption in the cloud often impacts data accessibility and processing speed. So we are likely to see increased debate about the tradeoffs between security, functionality and efficiency.”

Even if a company bites the bullet and encrypts everything going to the cloud services it has bought on contract with an enterprise provider, the report notes that employees' individual use of “shadow” services like Dropbox, Box.com and Google's sharing services can undermine that security (although The Register notes that Google began encrypting enterprise level cloud data in August, and with more recent NSA revelations, the encryption deployment will probably expand).

In the mobile space, GTISC points to the university's own work on AppStore vetting bypasses and malicious chargers. No matter how robust vendors' security models might be, GTISC says this only deals with large-scale attacks: targeted attacks that can be used against smaller groups or individuals still remain a threat.

GTISC also highlights the burgeoning enthusiasm for the Internet of Things as an embryonic threat for the future. The report notes that the simplicity of IoT devices can be an attack point. Detecting, for example, counterfeit devices in an IoT environment is resource-intensive, the report notes, which works against the low-power and simplicity sought by device makers.

In the industrial space, the report also criticises system designers for failing to build defences against side-channel vulnerabilities such as timing attacks. ®

Internet Security Threat Report 2014

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Edward who? GCHQ boss dodges Snowden topic during last speech
UK spies would rather 'walk' than do 'mass surveillance'
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
NOT OK GOOGLE: Android images can conceal code
It's been fixed, but hordes won't have applied the upgrade
Apple grapple: Congress kills FBI's Cupertino crypto kybosh plan
Encryption would lead us all into a 'dark place', claim G-Men
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.