Digital Edition

SYS-CON.TV
Private Practice: Encryption Exposed | @CloudExpo #Cloud #Security #Encryption
Apple had used some of the strongest encryption technologies and practices to protect its users and their data

In September 2014, Apple made encryption default with the introduction of the iPhone 6. Then, in February 2016, a Los Angeles judge issued an order to Apple to help break into the encrypted iPhone belonging to a terrorist involved in a mass shooting.

Apple had used some of the strongest encryption technologies and practices to protect its users and their data.  The encryption technology did not discriminate between lawful and unlawful users.  While there were many sides to this issue, it surfaced many important debates on security, privacy, and civil rights.

Peekaboo
For developers wanting to add cryptographic libraries to their applications, a number of open source components are available to them. Of course, anyone seeking to add encryption to an application has an important requirement for the privacy and security it provides.

One of the more popular choices for encryption is known as the Legion of Bouncy Castle Java Cryptography library. According to the 2016 State of the Software Supply Chain report, records reveal that 17.4 million Bouncy Castle components across all versions were downloaded last year. Of these, 5.8 million (33%) were known vulnerable versions of Bouncy Castle.

It's a sobering fact, but it's true. Last year alone, organizations downloaded vulnerable versions of the Bouncy Castle cryptography library 5.8 million times. The defective components downloads occurred across 93,253 unique IP addresses from 13,824 organizations in 197 countries.

Think Different
Think about it.  The Bouncy Castle project is developed by experts in cryptography.  Occasionally, their crypto library is discovered to have a flaw and the project owners rapidly fix and release a new version.  If you use the latest versions without known vulnerabilities, your application, your users, and your data are protected.  If you use the versions that include known vulnerabilities, you have electively declined those protections.

Two of the critical principles of using open source components are to use the highest quality components and to select them from the best suppliers.  In this case, the Bouncy Castle project does an excellent job of releasing new and improved versions.  While flawed versions are still available, those seeking to protect applications, users, and data need to use the highest quality versions.

Which Version Are You Using?
Determining which versions of Bouncy Castle or any other open source component you are using is simple.  A number of free and paid services are available to help you analyze your application and report a full list of the components, including dependencies, that are used.

Some of the free services require you to upload your application for analysis while other services are performed on-premises.  One example of a free on-premises tool used to create a software Bill of Materials is the Application Health Check app from Sonatype.  Another example is the OWASP Dependency Check app.  Precision of these tools may vary, but regardless of the tool you use, you should use one.

More insights on the quality, security, and integrity of open source components used to build modern applications can be found in the 2016 State of the Software Supply Chain report.

About Derek Weeks
In 2015, Derek Weeks led the largest and most comprehensive analysis of software supply chain practices to date across 160,000 development organizations. He is a huge advocate of applying proven supply chain management principles into DevOps practices to improve efficiencies, reduce costs, and sustain long-lasting competitive advantages.

As a 20+ year veteran of the software industry, he has advised leading businesses on IT performance improvement practices covering continuous delivery, business process management, systems and network operations, service management, capacity planning and storage management. As the VP and DevOps Advocate for Sonatype, he is passionate about changing the way people think about software supply chains and improving public safety through improved software integrity. Follow him here @weekstweets, find me here www.linkedin.com/in/derekeweeks, and read me here http://blog.sonatype.com/author/weeks/.



ADS BY GOOGLE
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE

Today, we have more data to manage than ever. We also have better algorithms that help us access our...
Andi Mann, Chief Technology Advocate at Splunk, is an accomplished digital business executive with e...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: D...
DevOpsSummit New York 2018, colocated with CloudEXPO | DXWorldEXPO New York 2018 will be held Novemb...
DXWorldEXPO LLC announced today that ICOHOLDER named "Media Sponsor" of Miami Blockchain Event by Fi...
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22...
SYS-CON Events announced today that IoT Global Network has been named “Media Sponsor” of SYS-CON's @...
To Really Work for Enterprises, MultiCloud Adoption Requires Far Better and Inclusive Cloud Monitori...
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news an...
CloudEXPO New York 2018, colocated with DXWorldEXPO New York 2018 will be held November 11-13, 2018,...
DXWorldEXPO | CloudEXPO are the world's most influential, independent events where Cloud Computing w...
Disruption, Innovation, Artificial Intelligence and Machine Learning, Leadership and Management hear...
"We host and fully manage cloud data services, whether we store, the data, move the data, or run ana...
DXWorldEXPO LLC announced today that Telecom Reseller has been named "Media Sponsor" of CloudEXPO | ...
Enterprises are striving to become digital businesses for differentiated innovation and customer-cen...
Enterprise architects are increasingly adopting multi-cloud strategies as they seek to utilize exist...
Digital Transformation: Preparing Cloud & IoT Security for the Age of Artificial Intelligence. As au...
"Calligo is a cloud service provider with data privacy at the heart of what we do. We are a typical ...
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use ...
Discussions of cloud computing have evolved in recent years from a focus on specific types of cloud,...