Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Security Management

11/28/2017
02:12 PM
Simon Marshall
Simon Marshall
Simon Marshall
50%
50%

PreVeil Pushes Encryption Past the End

PreVeil is pushing encryption beyond its normal endpoints to protect data wherever it is.

We all know that perimeter technologies are somewhat now playing second string to newer approaches to data security: acceptance that breaches are inevitable. Once in a while, we find one technology that cuts through the noise and presents an approach that looks very novel and very workable.

Whether or not you believe in "encryption everywhere," its time will come in 2018, when an innovative startup will commercialize and launch an encryption concept incubated from the labs at MIT.

Spearheading the new technology, which concept claims that even after an intrusion, information stored on servers remains encrypted and is therefore useless data to cyber thieves, is founder and CTO at PreVeil, Raluca Ada Popa.

Popa holds a double major Bachelor's degree, a Master's and a Doctorate in computer science -- all with a GPA of 5.0 -- and also holds the patents to PreVeil's encryption everywhere concept. She's also an assistant professor at U.C. Berkeley specializing in computer science and applied cryptography.

"I was always thinking of algorithmic, logical things, but at the same time, I also wanted to have an impact on the world," said Popa, "I had to do math, had to think analytically and I was only interested in solving difficult problems."

The math and operational processing behind the concept supports the idea that traditional encryption, although it has served well, just doesn't extend far enough given that intrusions are inevitable. Encryption od data in transit and storage works fine. But encryption during computing and processing of data is missing.

Don't worry about server breaches
"Servers were continually being breached, so my Light Bulb Moment was 'maybe we should stop fighting that battle because we're always losing,' " Popa told SecurityNow, "Let's stop trying to have a wall around data and instead always have it encrypted." Today's encryption protects data when it's at rest or in transit, but it's decrypted at the destination, and that leaves a huge security hole and low-hanging hacker opportunities.

Thinking of taking the concept from the whiteboard to commercialization, there was a healthy dose of reality that the process might be too much of a challenge. Also, it was Popa's first outing into forming a company and trying to drive a new mindset about the use of encryption.

"[But] I had a hard time thinking about only making an incremental change," said Popa, who loves challenges.

Having formed in 2015, PreVeil has been developing the technology and now has productized the concept. Solutions for file sharing and email security will be available by the end of the year for Windows, Mac, Android and iPhone. Its enterprise security solution will also released within a month. Services will be free for individual users, and the business model is to charge enterprises. Currently, PreVeil has about 30 enterprise trials on the go, but no formal customers yet.

Show me the money
Popa reckons that a big driver of enterprise interest is being driven by media coverage of attacks, and is starting some thinking about new solutions rather than necessarily beefing existing systems.

Apparently, some enterprise budget is being moved from perimeter defense towards newer technologies, and some companies are even able to justify additional security spending. There are also worries out there that companies which don't keep up with encryption may become soft targets for hackers.

Another pressure point is consumer expectation. There may be more realistic views on the street about weak data security from consumer brands, and Popa speculates that the next generation of encryption will power competitive differentiators for consumers willing to pay for stronger security-as-a-service.

Enterprise teams adopting new encryption technologies could face a knowledge gap and steep learning curves. "The good thing is that the high-level concepts are actually easy to grasp. There are no more single key-holder approvals, and now firms can get encryption through a group of people," said Popa. "It's definitely a big step to take, and there are those who are still thinking about it."

The past and the future
PreVeil is notable by the presence of chairman and founder Sanjeev Verma. Apart from the practicality of ensuring financing (the firm was initially privately funded) for the idea, Verma has a track record of success that includes being the founder of Airvana, the giant of CDMA in the early Noughties.

As a business partner, Popa liked him because he also had good technical knowledge and bridged the gap between her academic expertise through enabling the packaging of a new service. "We had been friends for a long time, and he was interested in potentially commercializing my research. There were a few other organizations who approached me, but I basically said 'no' to all of them," said Popa.

There are some roadmap items coming up that indicate an extension of PreVeil's ambitions as well as a fledgling move to apply encryption everywhere, well, everywhere. "We're looking at adding chat functionality, and looking to integrate with the blockchain, so that cryptographic identities are really secured by the blockchain."

How does the new technology work?

There's an explainer video here. And yes, the time-honored characters of Bob, Alice and Chris all star in the clip.

Related posts:

— Simon Marshall, Technology Journalist, special to Security Now

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/17/2020
APT Groups Set Sights on Linux Targets: Inside the Trend
Kelly Sheridan, Staff Editor, Dark Reading,  9/11/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9739
PUBLISHED: 2020-09-18
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exp...
CVE-2020-9744
PUBLISHED: 2020-09-18
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exp...
CVE-2020-9745
PUBLISHED: 2020-09-18
Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exp...
CVE-2020-0089
PUBLISHED: 2020-09-18
In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137015603
CVE-2020-0262
PUBLISHED: 2020-09-18
In WiFi tethering, there is a possible attacker controlled intent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156353008