The Experts below are selected from a list of 6252 Experts worldwide ranked by ideXlab platform
Peter James - One of the best experts on this subject based on the ideXlab platform.
-
Preventing the Acquisition of Data from Virtual Machine based Secure Portable Execution Environments
2013Co-Authors: Peter JamesAbstract:A Virtual Machine (VM) based secure Portable Execution Environment (PEE) provides a safe and secure environment that can be loaded into a host PC and an application executed with a degree of confidence that the application is separated, protected and little or no forensic evidence remains after the application has executed. A VM based secure PEE is characterised as a USB storage Device containing a VM with a trusted guest operating system and application(s) which is stored in a protected partition, strong authentication to only allow an authorised user to load the VM into the host PC, and full storage Device Encryption to protect the confidentiality of the contents of the Device. Secure PEEs provide an opportunity for organisations to issue a portable Device to an individual (to perform a secure transaction on an available host PC) with the reduced risk to the organisation that neither malicious software (resident on the host PC) will infect the secure PEE Device, nor sensitive data remnants (resulting from the transaction) will remain on the host PC hard disk drive after the secure PEE Device has been removed. A VM based secure PEE significantly reduces the opportunity to use dead forensic analysis techniques to acquire evidence of the occurrence of a transaction. However, VM based secure PEEs are susceptible to the acquisition of data through monitoring software and live forensic techniques. This paper considers the mechanisms that can be used to prevent various monitoring and live forensic techniques acquiring data from a VM based secure PEE
-
Abstract Preventing the Acquisition of Data from Virtual Machine based Secure Portable Execution Environments
2009Co-Authors: Peter JamesAbstract:A Virtual Machine (VM) based secure Portable Execution Environment (PEE) provides a safe and secure environment that can be loaded into a host PC and an application executed with a degree of confidence that the application is separated, protected and little or no forensic evidence remains after the application has executed. A VM based secure PEE is characterised as a USB storage Device containing a VM with a trusted guest operating system and application(s) which is stored in a protected partition, strong authentication to only allow an authorised user to load the VM into the host PC, and full storage Device Encryption to protect the confidentiality of the contents of the Device. Secure PEEs provide an opportunity for organisations to issue a portable Device to an individual (to perform a secure transaction on an available host PC) with the reduced risk to the organisation that neither malicious software (resident on the host PC) will infect the secure PEE Device, nor sensitive data remnants (resulting from the transaction) will remain on the host PC hard disk drive after the secure PEE Device has been removed. A VM based secure PEE significantly reduces the opportunity to use dead forensic analysis techniques to acquire evidence of the occurrence of a transaction. However, VM based secure PEEs are susceptible to the acquisition of data through monitoring software and live forensic techniques. This paper considers the mechanisms that can be used to prevent various monitoring and live forensic techniques acquiring data from a VM based secure PEE
John L Potapchuk - One of the best experts on this subject based on the ideXlab platform.
-
A Second Bite at the Apple: Federal Courts’ Authority to Compel Technical Assistance to Government Agents in Accessing Encrypted Smartphone Data Under the All Writs Act
Boston College Law Review, 2016Co-Authors: John L PotapchukAbstract:IntroductionIf you own a smartphone with a lock-screen passcode, you most likely use Encryption or at least have the option to turn it on.1 The extent to which that Encryption is secure depends on a myriad of factors, most notably the Device and its operating system.2 Full-disk Encryption, once an underappreciated and underutilized security feature available for smartphones, has proliferated in recent years.3 Its increasingly widespread use as a default feature on newer Devices is flooding the market with phones designed to be impenetrable when locked.4 Since October 2014, versions of Apple's iOS and Google's Android, which collectively comprise over ninety-six percent of the worldwide operating-system market share for smartphones, have supported Encryption capabilities originally believed to be impossible to circumvent without the owner's passcode.5The new enhancements in Device Encryption are creating significant problems for law enforcement personnel, however, who are increasingly obtaining warrants to search the smartphones of criminal suspects and homicide victims with no means of executing those searches.6 In the past, Apple had regularly assisted law enforcement officials in bypassing the passcodes of seized phones in response to a valid court order and search warrant.7 That assistance, Apple claims, is no longer an option with updated phones because the newer Encryption is designed to make it impossible for anyone, even company technicians, to access a locked phone without the passcode.8 Additional security features, such as automatic data-wiping protocols, may nullify many alternative methods of hacking into phones.9Collectively, these newer impediments effecting law enforcement's ability to access stored data represent the most recent installment in a larger issue colloquially referred to as "Going Dark."10 Generally, the term refers to the evolving gap between the government's authority to conduct criminal investigations and the ability to exercise that authority in light of technological advancements.11 Enhanced Encryption has reignited a simmering debate between government officials and technology executives regarding the proper balance between data security and effective law enforcement.12 Moreover, recent court proceedings have drawn particular attention to the government's practice of obtaining uncontested court orders requiring Apple to provide technical assistance in accessing locked Devices, which it has relied upon for several years.13 In October 2015, in In re Order Requiring Apple, Inc. Assist in Execution of Search Warrant ("In re Apple, Inc."), before U.S. Magistrate Judge James Orenstein in the U.S. District Court for the Eastern District of New York, Apple asserted its first challenge to such an order-application.14 Apple argued that it no longer conceded that the All Writs Act grants the authority to federal courts to order it to provide assistance to the government.15 Judge Orenstein agreed, and entered a decision holding the All Writs Act as unavailable as a matter of law to direct thirdparty assistance in this context, which represents the first of its kind.16 Although many believe that the issue will eventually be settled through legislation, the government's interim efforts to get into several locked phones has drawn much attention to the propriety of the All Writs Act and the federal courts' authority to command private assistance in order to effectuate a warrant.17This Note will discuss the federal courts' authority to issue orders upon third parties to provide technical assistance to the government under the All Writs Act, and the related implications within the debate regarding cellphone Encryption of data at rest.18 Part I discusses the Encryption of data at rest on cellphones, particularly the type of Encryption used on iPhones, and further discusses some of the constitutional and statutory implications that arise when law enforcement officials wish to search a cellphone. …
-
a second bite at the apple federal courts authority to compel technical assistance to government agents in accessing encrypted smartphone data under the all writs act
Boston College Law Review, 2016Co-Authors: John L PotapchukAbstract:The analogy is simple: imagine an unpickable and unbreakable lock. A safe-deposit box, or a house with no physical way in other than a unique passcode known only to the owner. Absolute security. This was generally the ideal behind Apple, Inc.’s most recent stride in mobile security, which dramatically widened the breadth of data receiving full-disk Encryption by default on iPhones with the introduction of iOS 8 in 2014. The result for law enforcement has been hundreds of Device search warrants unable to be executed. The heated public debate that has followed, which has largely focused on the nefarious potential of the uncompromising privacy this newly utilized Encryption provides, has intensified amidst continuing efforts by government agents to obtain aid from the federal judiciary by means of orders under the All Writs Act. Although Apple had regularly complied with such orders directing the company to assist government agents in accessing locked iPhones since as early as 2008, Apple changed its position in October 2015 and will no longer acquiesce. This Note provides a detailed discussion of the underlying legal implications surrounding the so-called public standoff between Apple and the FBI, with particular attention to the propriety of the decryption assistance orders sought by the government under the All Writs Act. It further provides a detailed discussion of In re Order Requiring Apple, Inc. Assist in Execution of Search Warrant, an ongoing matter in the U.S. District Court for the Eastern District of New York, where Apple mounted its first opposition to a decryption assistance order under the All Writs Act. It further argues that the federal courts are authorized to compel third party assistance under the statute in certain situations, however, the statutes authority will eventually become obsolete as advancing technology will soon render such orders overly burdensome. It finally offers an expansion of the Communication Assistance to Law Enforcement Act (“CALEA”) as one potential solution to the threat that impenetrable Device Encryption poses to the functioning of the American criminal justice system.
Potapchuk, John L. - One of the best experts on this subject based on the ideXlab platform.
-
A Second Bite at the Apple: Federal Courts’ Authority to Compel Technical Assistance to Government Agents in Accessing Encrypted Smartphone Data Under the All Writs Act
Digital Commons @ Boston College Law School, 2016Co-Authors: Potapchuk, John L.Abstract:On February 29, 2016, in In re Order Requiring Apple, Inc. Assist in Execution of Search Warrant (“In re Apple, Inc.”) the U.S. District Court for the Eastern District of New York held that the All Writs Act did not provide the legal authority to require Apple Inc. to bypass the encrypted lock-screen passcode of an iPhone for the federal government in order to execute a search warrant. Accordingly, the decision, which was the first of its kind, stripped the government of an investigative tool upon which it had routinely relied since as early as 2008. In In re Apple, Inc., after years of acquiescence to such orders, Apple mounted its first challenge to the propriety of the All Writs Act and courts’ authority to compel the company to bypass its own Encryption for the government. This position followed from Apple’s most recent efforts to provide tighter mobile security for its customers with the rollout of iOS 8 in October 2014, which offered more extensive full-disk Encryption by default—so extensive, Apple claimed, that its previous assistance to the government is no longer technologically feasible. As a result of the newly enhanced Encryption law enforcement officials across the country have encountered hundreds of lawfully searchable phones with no means of executing searches. This Note provides a discussion of the underlying legal implications surrounding the heated public debate that has emerged in the wake of In re Apple, Inc. and other similar cases as well as the practical challenges enhanced data Encryption creates for law enforcement officials. Particularly, it focuses on the propriety of decryption assistance orders that have been issued under the All Writs Act. It argues that the decision in In re Apple, Inc. was incorrect, and that the All Writs Act does in fact confer authority to federal courts to compel third-party assistance in certain situations. It concludes by offering an expansion of the Communication Assistance to Law Enforcement Act as one potential solution to the threat that impenetrable Device Encryption poses to the functioning of the American criminal justice system
Bruce H. Curran - One of the best experts on this subject based on the ideXlab platform.
-
TH-A-12A-01: Medical Physicist's Role in Digital Information Security: Threats, Vulnerabilities and Best Practices
Medical Physics, 2014Co-Authors: K Mcdonald, Bruce H. CurranAbstract:I. Information Security Background (Speaker = Kevin McDonald) 1. Evolution of Medical Devices 2. Living and Working in a Hostile Environment 3. Attack Motivations 4. Attack Vectors 5. Simple Safety Strategies 6. Medical Device Security in the News 7. Medical Devices and Vendors 8. Summary II. Keeping Radiation Oncology IT Systems Secure (Speaker = Bruce Curran) 1. Hardware Security a. Double-lock Requirements b. “Foreign” computer systems c. Portable Device Encryption d. Patient Data Storage e. System Requirements 2. Network Configuration a. Isolating Critical Devices b. Isolating Clinical Networks c. Remote Access Considerations 3. Software Applications / Configuration a. Passwords / Screen Savers b. Restricted Services / access c. Software Configuration Restriction d. Use of DNS to restrict accesse. Patches / Upgrades 4. Awareness a. Intrusion Prevention b. Intrusion Detection c. Threat Risk Analysis . Conclusion Learning Objectives: 1. Understanding how Hospital IT Requirements affect Radiation Oncology IT Systems. 2. Illustrating sample practices for hardware, network, and software security. 3. Discussing implementation of good IT security practices in radiation oncology. 4. Understand overall risk and threats scenario in a networked environment.
K Mcdonald - One of the best experts on this subject based on the ideXlab platform.
-
TH-A-12A-01: Medical Physicist's Role in Digital Information Security: Threats, Vulnerabilities and Best Practices
Medical Physics, 2014Co-Authors: K Mcdonald, Bruce H. CurranAbstract:I. Information Security Background (Speaker = Kevin McDonald) 1. Evolution of Medical Devices 2. Living and Working in a Hostile Environment 3. Attack Motivations 4. Attack Vectors 5. Simple Safety Strategies 6. Medical Device Security in the News 7. Medical Devices and Vendors 8. Summary II. Keeping Radiation Oncology IT Systems Secure (Speaker = Bruce Curran) 1. Hardware Security a. Double-lock Requirements b. “Foreign” computer systems c. Portable Device Encryption d. Patient Data Storage e. System Requirements 2. Network Configuration a. Isolating Critical Devices b. Isolating Clinical Networks c. Remote Access Considerations 3. Software Applications / Configuration a. Passwords / Screen Savers b. Restricted Services / access c. Software Configuration Restriction d. Use of DNS to restrict accesse. Patches / Upgrades 4. Awareness a. Intrusion Prevention b. Intrusion Detection c. Threat Risk Analysis . Conclusion Learning Objectives: 1. Understanding how Hospital IT Requirements affect Radiation Oncology IT Systems. 2. Illustrating sample practices for hardware, network, and software security. 3. Discussing implementation of good IT security practices in radiation oncology. 4. Understand overall risk and threats scenario in a networked environment.