Self-erase HDDs clear way for better security

 

Summary

IT executives welcome extra security layers in self-wiping hard-disk drives, but caution needed to plug other gaps such as human error and lax attitudes toward disposal of storage devices.

Events

IBM Technology Conference & Expo 2012
May 23, 2012

Convention Centre B2 Room at 22nd Floor, Centara Grand @ Central World, 999/99 Rama I Road, Pathumwan, Bangkok 10330

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

With data theft coming under the spotlight recently, IT executives say they are in favor of self-erase hard-disk drives, but reiterate the human element remains critical in any information security policy.

In April, Toshiba announced Self-Encrypting Drives (SED) that includes hardware encryption and data invalidation technology, where data stored in a "self-erase" area can be wiped automatically once the host system is switched off, the drive is powered off or if the drive is removed.

According to the vendor, the erase process is performed by deleting the encryption key for the self-erase area, which is generated by the host each time the drive is powered up. Therefore, the next time power is re-established to the drive, the self-erase area will rely on a new key, with all previous data eliminated along with the old cryptographic key.

Users of SEDs have the ability to customize the level of data erase, whether to wipe out all information or simply restrict access to particular data, according to an Information Ground blog post. Wiped data is not be completely destroyed, as the drive could still be recovered with the use of administrator credentials.

Thumbs up for more security
Thio Fu Wang, senior manager for domains and technology at CrimsonLogic, noted that such HDDs are a step forward in light of increasing data breaches.

"This device provides distinct advantage of relatively little performance degradation as compared to software full-disk encryption that is offered in the market, while still ensuring strong protection of the data in storage," he said in an e-mail.

Organizations such as banks, investments firms, government agencies, security companies and R&D (research and development) facilities that deal with sensitive information, are more likely to adopt SEDs in their printers or PCs, he added.

Kevin Low, an IT executive with a local small and midsize business, told ZDNet Asia in an e-mail the device would make perfect sense if it is installed in laptops which contain corporate information that would otherwise be privy to competitors. There is assurance that in the event of a theft or loss of device, sensitive data will remain safe from outsider access, he explained.

"However, [even] with the fail-safe device in place...I worry that hackers might have a way to gain access to my data even it is self erasing," said Low.

Consider human factor, holistic perspective
C.K. Lee, Singapore country manager for data recovery vendor Kroll Ontrack, similarly emphasized the need for such devices to better secure sensitive data, since stored information in devices are typically still easily retrievable.

The general attitude toward data security and disposal of storage devices, he pointed out, remains "careless" and self-erase features of such HDDs will help to protect sensitive data.

Lee added his company has witnessed many cases of data loss and information security issues. "The majority of these are still caused by human error or technical failures.

"Although technological advances and features will increase data security and prevent data loss up to a certain level, the human element remains the most critical in any information security policy," the executive said.

CrimsonLogic's Thio highlighted the need for a "holistic data leakage prevention" framework, which encompasses the entire architecture of data creation, transit and storage.

He also noted that most data thefts do not occur in the form of digital data or media but physical documents. There is hence a need to plug the gap in physical security, he said.

Portable alternative
Low expressed preference for secure portable drives over built-in devices, citing Datalocker as one such provider.

Its DL3 HDD comes with a touchscreen keypad and requires two-factor authentication for access. The user has to swipe a card equipped with radio frequency identification (RFID) technology and thereafter enter a password on the touchscreen alphanumeric keypad. Once successfully authenticated, the drive becomes visible on the computer system.

Jay Kim, DataLocker's COO said in an article on PCMag that hardware-based authentication is more effective than software-based authentication, adding such products can be used in environments that do not allow software installation.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Integration, focused investments to propel Windows Phone http://t.co/6JkDa9sB

RT @AsianFashionLaw: Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

Acquisitions in the Big Data market increasingly important to enterprises… http://t.co/Br4BkXyZ

Experience trumps content in apps monetization http://t.co/iaCY5ebX

Malaysia offers some manufacturing benefits over China http://t.co/bMquIFiX

RT @MDMGeek: Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Thats it.Im digging up an old bus plan i wrote around acquisition of #bigdata talent. http://t.co/gpkha5A1 Any investors want2 read/discuss?

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 mins ag... http://t.co/aaa0Cb73

Homegrown smartphone OSes gaining favor in China http://t.co/lOBVp1T6

Homegrown smartphone OSes gaining favor in China: 59 Jakarta 10350, Indonesia Locally-made mobile operating syst... http://t.co/gHypbdIY

Integration, focused investments to propel Windows Phone - ZDNet Asia http://t.co/7sZi6Dhb

RT @zdnetasia: Homegrown smartphone OSes gaining favor in China. http://t.co/lL8KbccW

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia http://t.co/ky8YgPAn #Bigdata #analytics via @ciropuglisi

Big data acquisitions pave way to fast, effective innovation - ZDNet Asia: Big data acquisition... http://t.co/r6taCmG1 #ITNews #BigData

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

5 days ago by wykoong on Drop the egos, copy ideas, then innovate