ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Are we encrypting to much at rest

    IT Discussion
    encryption security storage
    6
    14
    2.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      If you are looking to encrypt the entire system from the system side (LUKS, TC, VC, etc.) you are stuck with the need to have the password be external. If you want the system to decrypt storage automatically that makes this completely useless. Anyone stealing your server will get the whole thing, data, password and all. It only works if you are only concerned with stealing small portions of your systems.

      What you can do, when you really are concerned with theft, is to keep the passwords externally and have either a human or a custom security system that will put in the password for you. If you are not willing to do that, it is really a pointless exercise.

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        How often are SMBs really experiencing server theft? Is this a real problem in the real world? If so, maybe addressing that would be more effective.

        1 Reply Last reply Reply Quote 0
        • dafyreD
          dafyre
          last edited by

          I would heavily consider using encryption such as Bitlocker for a business -- especially for business with Windows and Windows 8 or higher (I have zero experience with full disk encryption before then)...

          I have not had any problems at all using the features. It is more aggravating if I have to reboot my computer for any reason... but since that is not a regular occurrence for me, it works nicely.

          1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender @scottalanmiller
            last edited by

            @scottalanmiller said:

            So there are places where it works and risks that it can mitigate. But is drive theft a realistic threat? Even in the financial world this is rarely considered a viable threat. In the SMB, it seems bordering on the pathological.

            I'm not sure I'd agree with that.. SMB are notorious for not physically securing their servers, so the potential is much greater.

            scottalanmillerS 1 Reply Last reply Reply Quote 0
            • scottalanmillerS
              scottalanmiller @Dashrender
              last edited by

              @Dashrender said:

              @scottalanmiller said:

              So there are places where it works and risks that it can mitigate. But is drive theft a realistic threat? Even in the financial world this is rarely considered a viable threat. In the SMB, it seems bordering on the pathological.

              I'm not sure I'd agree with that.. SMB are notorious for not physically securing their servers, so the potential is much greater.

              Sure, but what SMB is going to be okay with "the server can't reboot anymore" but isn't willing to, you know, lock the door?

              1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller
                last edited by

                While there is certainly threat of physical theft in the SMB, has anyone experienced it? Does anyone know anyone who has? Do people really walk off with full servers regularly?

                1 Reply Last reply Reply Quote 0
                • BRRABillB
                  BRRABill
                  last edited by

                  Always the thought that gets you.

                  It's probably similar to other disasters, no? How many times does an entire building burn down?

                  1 Reply Last reply Reply Quote 0
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    Probably more often than servers are stolen 🙂

                    1 Reply Last reply Reply Quote 0
                    • BRRABillB
                      BRRABill
                      last edited by

                      I bet it is close.

                      1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller
                        last edited by

                        I bet the primary case is buildings burning down and people making off with the server from the ashes 😉

                        I've heard of people having fires, not heard of anyone having a stolen server in the real world. Even with SMBs rarely doing anything to protect against it.

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post