All the latest UK technology news, reviews and analysis

IPods and MP3 players threaten network security

by Robert Jaques

07 Jul 2004

Be the first to comment

  • Tweet this

Most companies are failing to address the serious security risks created by the proliferation of USB flash drives, MP3 players and similar portable storage devices, industry experts have warned.

Ruggero Contu, client research consultant at analyst Gartner, warned that the use of unauthorised portable storage devices poses several dangers, not least for the malicious code that they can introduce to corporate networks.

High data capacity and transfer rates mean that USB or FireWire devices have the capacity to download valuable corporate information which can be leaked to the outside world, according to the analyst.

"This underlying vulnerability has existed since the release of Windows 2000, the first widely deployed operating system able to mount a USB storage device automatically," said Contu.

Gartner warned that the danger comes from back doors being opened by portable devices including any kind of pocket-sized FireWire hard drive, like those from LaCie or Toshiba, or USB hard drive or keychain drives.

They also include disk-based MP3 players, such as Apple's iPod, and digital cameras with smart media cards and other memory media.

"Companies are at risk of losing intellectual property and other critical corporate data. Portable storage devices are ideal for anyone intending to steal sensitive and valuable data," said Contu.

"Employees may also be responsible for losing data if they inadvertently mislay these devices."

Gartner advised companies to forbid the use of uncontrolled, privately owned devices with corporate PCs. The prohibition should also extend to external contractors with direct access to corporate networks.

Companies should adopt a controlled approach with security measures that incorporate overall organisational security policy and specific technology tools.

"Managers should advise on the main procedures to be followed for the eventual use of such devices, for instance to confirm the need for password and security protection [encryption] of stored corporate data. This will also help mitigate risks from loss or theft," said Contu.

Gartner advised that general security best practice should include the implementation of a desktop lockdown policy.

Managers should also consider disabling universal plug and play after pre-installing any desired drivers to permit the use of authorised devices only.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

C++ GUI Developer - Financial Services - London

C++ GUI Developer - Financial Services - London Tech...

Java Web Developer, Greenfield Trading Application

This is an opportunity for a bright and talented Java...

C# Application Developer

C# Application Developer Location : Nottingham...

Senior HTML Developer

Experienced Web Developer Wanted for Financial Sector...

To send to more than one email address, simply separate each address with a comma.