Monday, June 23, 2008

Re: Issues of data in the cloud...

A mistake is to assume encrypting data makes it secure. While it can't
be read when it is encrypted, it doesn't guarantee that once it is
unencrypted to be used that it can't be viewed (or stolen) by others.

Think of how simple it would be to write a wrapper DLL or library that
looks ands acts like some encrypt library but also diverts the contents.
It would be very very simple to do this.

Yes, it is possible to have this same thing happen in a corporation
under my control, but I can audit for it or lock the system down (well
almost). But in a remote site holding my data how can I be sure?

Chuck Wegrzyn

No comments: