<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Data Loss Prevention with Microsoft Enterprise Rights Management &#8211; The Desktop Files</title>
	<atom:link href="http://www.ditii.com/2008/10/23/data-loss-prevention-with-microsoft-enterprise-rights-management-the-desktop-files/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ditii.com/2008/10/23/data-loss-prevention-with-microsoft-enterprise-rights-management-the-desktop-files/</link>
	<description>Technology, Blogging, Computer, Hardware, Software, Networking, Web, Media, LifeStyle, Gadgets</description>
	<lastBuildDate>Tue, 24 Nov 2009 01:13:20 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Danny Lieberman</title>
		<link>http://www.ditii.com/2008/10/23/data-loss-prevention-with-microsoft-enterprise-rights-management-the-desktop-files/#comment-61851</link>
		<dc:creator>Danny Lieberman</dc:creator>
		<pubDate>Thu, 23 Oct 2008 20:05:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.ditii.com/2008/10/23/data-loss-prevention-with-microsoft-enterprise-rights-management-the-desktop-files/#comment-61851</guid>
		<description>You must be kidding.

Enterprise DRM as a way of protecting data loss???

Please - unauthorized use is not even close to being an internal threat.

By definition - data loss, is unauthorized network transfer of data that the user is ALREADY permitted to access.

There are really 3 sources of data loss, DRM is worthless security countermeasure for preventing data loss.   

The first (and mildest) is trusted insiders;
I have access rights to a sensitive file. I open it in Word, save to PDF, send it to my  private Gmail account.

The second (and next severe) is malicious outsiders.   It&#039;s easy to socially manipulate a customer service person over time with minor compensation for non-critical data, gaining their trust. But - eventually - the time comes when the attacker will ask for more - for core company data - and get it.

The third (and most severe) is IT operations.   Riddled with buggy applications, poor integration and configuration - DRM will never mitigate this threat to data loss.


Danny Lieberman</description>
		<content:encoded><![CDATA[<p>You must be kidding.</p>
<p>Enterprise DRM as a way of protecting data loss???</p>
<p>Please - unauthorized use is not even close to being an internal threat.</p>
<p>By definition - data loss, is unauthorized network transfer of data that the user is ALREADY permitted to access.</p>
<p>There are really 3 sources of data loss, DRM is worthless security countermeasure for preventing data loss.   </p>
<p>The first (and mildest) is trusted insiders;<br />
I have access rights to a sensitive file. I open it in Word, save to PDF, send it to my  private Gmail account.</p>
<p>The second (and next severe) is malicious outsiders.   It's easy to socially manipulate a customer service person over time with minor compensation for non-critical data, gaining their trust. But - eventually - the time comes when the attacker will ask for more - for core company data - and get it.</p>
<p>The third (and most severe) is IT operations.   Riddled with buggy applications, poor integration and configuration - DRM will never mitigate this threat to data loss.</p>
<p>Danny Lieberman</p>
]]></content:encoded>
	</item>
</channel>
</rss>
