<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Terry White&#039;s Tech Blog &#187; Security</title>
	<atom:link href="http://terrywhite.com/techblog/archives/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://terrywhite.com/techblog</link>
	<description>Welcome to my technology blog!</description>
	<lastBuildDate>Fri, 10 Feb 2012 05:11:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Carry Sensitive Data on an IronKey</title>
		<link>http://terrywhite.com/techblog/archives/4211</link>
		<comments>http://terrywhite.com/techblog/archives/4211#comments</comments>
		<pubDate>Thu, 17 Dec 2009 08:01:39 +0000</pubDate>
		<dc:creator>Terry White</dc:creator>
				<category><![CDATA[Gadgets]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Flash Drive]]></category>
		<category><![CDATA[IronKey]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Portable]]></category>
		<category><![CDATA[Thumb Drive]]></category>

		<guid isPermaLink="false">http://terrywhite.com/techblog/?p=4211</guid>
		<description><![CDATA[Although I have what seems like a mountain of thumb/flash drives lying around, I&#39;ve never had one as cool as the one my friend Mary just gave me. It&#39;s called the IronKey. While it looks like an ordinary thumb drive in a cool aluminum casing, it&#39;s actually a lot more. &#160; For the Security Conscious [...]]]></description>
			<content:encoded><![CDATA[<!-- Start Shareaholic LikeButtonSetTop Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fbsend' data-shr_href='http%3A%2F%2Fterrywhite.com%2Ftechblog%2Farchives%2F4211'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fterrywhite.com%2Ftechblog%2Farchives%2F4211' data-shr_title='Carry+Sensitive+Data+on+an+IronKey'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetTop Automatic --><p><img alt="ironkey" class="alignnone size-full wp-image-4212" height="292" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/ironkey.jpg" title="ironkey" width="450" /></p>
<p>Although I have what seems like a mountain of thumb/flash drives lying around, I&#39;ve never had one as cool as the one my friend Mary just gave me. It&#39;s called the IronKey. While it looks like an ordinary thumb drive in a cool aluminum casing, it&#39;s actually a lot more.</p>
<p>&nbsp;</p>
<h3>For the Security Conscious</h3>
<p>As computer users we&#39;re taught not to leave a list of our passwords next to our computer right? Some will take it a step further and put that list on their computers in a text filed called something less obvious like &quot;Johnson Rod Repair Manual&quot;. However, sensitive data should really be encrypted! While there is no shortage of encryption apps for Mac and PC&#39;s, I don&#39;t run across hardware solutions as often. Sure, most portable drives will offer something, but in that case it&#39;s usually very platform specific and requires the software to actually be &quot;installed&quot; to use it. The IronKey takes a simpler&nbsp;more straight forward approach.</p>
<p>&nbsp;</p>
<h3>Set it up</h3>
<p><img alt="ironkeysetup" class="alignnone size-full wp-image-4213" height="362" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/ironkeysetup.png" title="ironkeysetup" width="400" /></p>
<p>When you first plug in the USB thumb drive, you can launch the app for your platform right off the device itself. They have the documentation there as well. Give it a name and your secure password (please remember it!). You can also enable the Device Reset feature at this point so that if your device is lost/stolen and someone keys in the wrong password too many times it will automatically and securely erase or destroy the device.&nbsp;</p>
<p><img alt="ironkeyinit" class="alignnone size-full wp-image-4214" height="362" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/ironkeyinit.png" title="ironkeyinit" width="400" /></p>
<p>&nbsp;</p>
<h3>At this point your IronKey is ready to use</h3>
<p><img alt="ironkeyunlock" class="alignnone size-full wp-image-4215" height="362" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/ironkeyunlock.png" title="ironkeyunlock" width="400" /></p>
<p>Just key in your password and it will unlock and mount the drive</p>
<p><span id="more-4211"></span></p>
<p><img alt="IronKeymounted" class="alignnone size-full wp-image-4216" height="144" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/IronKeymounted.png" title="IronKeymounted" width="173" /></p>
<p>If you enter the wrong password twice, you&#39;ll be warned</p>
<p><img alt="warning" class="alignnone size-full wp-image-4217" height="198" src="http://terrywhite.com/techblog/wp-content/uploads/2009/12/warning.png" title="warning" width="420" /></p>
<p>You can either configure the device to erase all content after the password has been incorrectly entered so many times and it will still be usable minus your data or you can have it not only erase your data but also destroy the drive so that it can&#39;t ever be used again. Wow!</p>
<p>&nbsp;</p>
<h3>What would I use this for?</h3>
<p>I asked this question and at first couldn&#39;t really think of too much that I carry around that needs this level of security and then it dawned upon me that this would be great for a backup of my <a href="http://macgroup.org/blog/2009/11/30/1password-is-all-you-need/" target="_blank">1Password</a> file in Encrypted HTML format. This way I could have all my passwords and logins with with If I need them on a different computer AND add one more level of security. I&#39;ll probably also use it to story backup copies of client presentations.&nbsp;</p>
<p>&nbsp;</p>
<h3>A word about Security from IronKey &#8211; only read this part if you&#39;re a security geek <img src='http://terrywhite.com/techblog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Otherwise you can skip down to The Bottom Line</h3>
<p>We are endeavoring to be very open about the security architecture and&nbsp;technology that we use in designing and building the IronKey devices and&nbsp;online services. There is no hocus-pocus or handwaving here. We use&nbsp;established cryptographic algorithms, we develop threat models, and we&nbsp;perform security analyses (internal and third party) of our systems all the&nbsp;way through design, development and deployment.</p>
<p>
	<strong>IronKey Device Security</strong><br />
	Data Encryption Keys<br />
	&raquo; AES keys generated by onboard Random Number Generator<br />
	&raquo; AES keys generated by user at initialization time and encrypted<br />
	&raquo; AES keys never leave the hardware and are not stored in NAND flash</p>
<p>
	<strong>Self-Destruct Data Protection</strong><br />
	&raquo; Secure volume does not mount until password is verified in hardware<br />
	&raquo; Password try-counter implemented in tamper-resistant hardware<br />
	&raquo; Once password try-count is exceeded, all data is erased by hardware</p>
<p>
	<strong>Additional Security Features</strong><br />
	&raquo; USB command channel encryption to protect device communications<br />
	&raquo; Firmware and software securely updateable over the Internet<br />
	&raquo; Updates verified by digital signatures in hardware</p>
<p>
	<strong>Physically Secure</strong><br />
	&raquo; Solid, rugged case<br />
	&raquo; Encryption keys stored in the tamper-resistant IronKey Cryptochip<br />
	&raquo; All chips are protected by epoxy-based potting compound<br />
	&raquo; Exceeds military waterproof standards (MIL-STD-810F)</p>
<p>
	<strong>Device Password Protection</strong><br />
	The device password is hashed using salted SHA-256 before being&nbsp;transmitted to the IronKey Secure Flash Drive over a secure and unique<br />
	USB channel. It is stored in an extremely inaccessible location in the&nbsp;protected hardware. The hashed password is validated in hardware (there&nbsp;is no &ldquo;getPassword&rdquo; function that can retrieve the hashed password), and&nbsp;only after the password is validated is the AES encryption key unlocked.&nbsp;The password try-counter is also implemented in hardware to prevent&nbsp;memory rewind attacks. Typing your password incorrectly too many times&nbsp;initiates a patent-pending &ldquo;flash-trash&rdquo; self-destruct sequence, which is run&nbsp;in hardware rather than using software, ensuring the ultimate protection&nbsp;for your data.</p>
<p>&nbsp;</p>
<h3>The Bottom Line</h3>
<p>If you need or want to carry around files that are secured and accessible on just about any computer with a USB port, this is a great portable option. By it being Mac and PC compatible, it&#39;s also a no brainer. The fact that it has a &quot;Self Destruct&quot; feature is icing on the cake.&nbsp;</p>
<p>It comes in the follow configurations:</p>
<p><a href="http://www.amazon.com/gp/product/B000RXYV5K?ie=UTF8&amp;tag=terwhitecblo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B000RXYV5K" target="_blank">1GB</a></p>
<p><a href="http://www.amazon.com/gp/product/B000RY0Q9O?ie=UTF8&amp;tag=terwhitecblo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B000RY0Q9O" target="_blank">2GB</a></p>
<p><a href="http://www.amazon.com/gp/product/B000RXYV5U?ie=UTF8&amp;tag=terwhitecblo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B000RXYV5U" target="_blank">4GB</a></p>
<p><a href="http://www.amazon.com/gp/product/B00155184G?ie=UTF8&amp;tag=terwhitecblo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=390957&amp;creativeASIN=B00155184G" target="_blank">8GB</a></p>
<!-- AdSense Now! V1.98 -->
<!-- Post[count: 2] -->
<div class="adsense adsense-leadout" style="text-align:center;margin: 12px;"><script type="text/javascript"><!--
google_ad_client = "pub-3486243114991095";
/* 300x250, created 2/5/11 */
google_ad_slot = "1042141778";
google_ad_width = 300;
google_ad_height = 250;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><div class="shr-publisher-4211"></div><!-- Start Shareaholic LikeButtonSetBottom Automatic --><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><div class='shareaholic-like-buttonset' style='float:none;height:30px;'><a class='shareaholic-fblike' data-shr_layout='button_count' data-shr_showfaces='false' data-shr_href='http%3A%2F%2Fterrywhite.com%2Ftechblog%2Farchives%2F4211' data-shr_title='Carry+Sensitive+Data+on+an+IronKey'></a><a class='shareaholic-fbsend' data-shr_href='http%3A%2F%2Fterrywhite.com%2Ftechblog%2Farchives%2F4211'></a><a class='shareaholic-googleplusone' data-shr_size='medium' data-shr_count='true' data-shr_href='http%3A%2F%2Fterrywhite.com%2Ftechblog%2Farchives%2F4211' data-shr_title='Carry+Sensitive+Data+on+an+IronKey'></a></div><div style="clear: both; min-height: 1px; height: 3px; width: 100%;"></div><!-- End Shareaholic LikeButtonSetBottom Automatic -->]]></content:encoded>
			<wfw:commentRss>http://terrywhite.com/techblog/archives/4211/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

