Cryptography

Cryptographic Vulnerabilities and How to Avoid Them

Cryptographic Vulnerabilities and How to Avoid Them

Cryptographic Vulnerabilities and How to Avoid Them

Implementing proper security for data, both at rest on servers and devices, plus in transit across the network is hopefully well understood and now just a core part of deploying IT systems. A crucial part of protecting data is the use of cryptographic keys and encryption for files and data in all locations.

Nearly everything we do on the Internet, and when working securely with data, relies on proper and functional cryptography. Whether it’s to secure connections to web sites and web apps, or to protect the data on our mobile devices, cryptography is key. Pun intended!

Cryptographic protections need to be set up and maintained over time to deliver and keep the required protections we all need. But like any system that is complex and changing, mistakes can be made, and problems can occur. And this can lead to security breaches and all the issues that come along with them. Below we outline some of the common issues in cryptographic solutions and how Renaissance and our security partner community can help ensure they don't occur or address them if they do. Contact us today to discuss your cryptography needs, or read on for more details.

No Encryption in Use

Hopefully, this won't be the case for anyone reading this, but make sure you are using encryption end-to-end within your organisation from the point of data creation and storage. Make sure data is stored using secure cryptographic storage on servers and end-user devices. Also, make sure that any transfer that moves data from one location to another has encrypted transmissions, whether it is over the Internet or just within a private network.

Use the Latest Encryption Standard

Vulnerabilities are regularly discovered in existing encryption standards and libraries. You should ensure that you are using the latest available as older versions do not always get fixes. For encrypting network connections be sure to use TLS 1.3 which came into force in August 2018. Aim to phase out TLS 1.2 as soon as possible. And move from SSL to TLS if you are still using SSL anywhere!

For data at rest, look to use a solution based on AES encryption. AES is generally seen as the most secure algorithm. NIST recommends it in the USA, and the US government uses AES based encryption to protect sensitive data. Use 256-bit AES if you can as it is the most secure.

Code Library Bugs

Most software development projects include third party open source and commercial libraries that provide functionality that can be used without the developers needing to write everything from scratch. Many of these libraries are delivered as compiled modules without source code to inspect. Even those that do have source code are too complex or large for busy programmers to check. Often they include bugs and vulnerabilities that have been discovered after shipping. So it's vital to ensure that the latest versions of code libraries are used and that applications are recompiled and deployed using the latest versions. Tools from Renaissance partner Veracode can automate code checking to highlight vulnerabilities, even in modules that don't ship with source code.

Application Design Issues

Designing and developing applications is complex, and the process can lead to security vulnerabilities due to improper code design and review, or via the use of third-party code as outlined above. Again the Veracode tools can scan and highlight issues in code using a machine learning backed code checking system. Contact Renaissance for more info.

Core OS Vulnerabilities

All software has bugs. And that includes the core OS software from Microsoft, Apple, VMware, Google and others. Often the bugs in OS releases are security vulnerabilities, so it’s vital to have a mechanism to test and deploy the latest versions of Windows, iOS, macOS, Android, VMware vSphere, and others as soon as possible after release.

Configuration Mistakes

In the same way that a building is only secure if the entrance points are correctly secured, IT systems are only protected if the security solutions are appropriately configured. Some known issues ship as part of default installations and these are known and exploited by cybercriminals. Don't leave default configurations in place. Unique and discoverable vulnerabilities can be introduced into security systems during setup. Those configuring the systems should be expert in the field. Renaissance and our security partners have all the experts you could need to ensure correct setup and maintenance of security infrastructure.

Certificate Issues

Security is built on trusted certificates. These need to be obtained from trusted enterprise sources and maintained during their lifetime. It's also vital they are renewed before they expire so that services are not suddenly interrupted. There have been several high profile national service outages in recent years that have been traced back to a security certificate expiring. Renaissance partners provide everything needed to deliver and ensure that proper security certificates are in place. Including full managed services that take responsibility from an organisation and place it with experts who are focused on certificate management.

Conclusion

Proper data security is vital in the age of GDPR. Encryption and cryptographic solutions are core to providing that security. Renaissance can provide everything that is needed for any organisation. Contact us today to find out more.