Posts

Showing posts with the label Data Protection

Data Masking Explained: Obfuscation Techniques for the Security+ Exam

Data masking replaces sensitive values with realistic but false substitutes, so a system can be used without exposing the real data. The card number displays as •••• •••• •••• 4471; the test database contains plausible names that belong to nobody. The exam tests it against the neighbouring techniques, because they are easy to confuse and the differences matter. Static versus dynamic Static data masking permanently replaces values in a copy of the data. You extract production data, mask it, and load it into development or test. The real values never exist in that environment, so a breach of the test system exposes nothing. Use it for non-production environments, analytics datasets and anything shared with third parties. The key point is that it is irreversible in the copy — and that the copy is what people work with. Dynamic data masking leaves the stored data intact and masks it at query time based on who is asking. A support agent sees the last four digits; a fraud investigator...

Sensitive Data Explained: PII, PHI and Classification for Security+

Sensitive data is any information that would cause harm if disclosed, altered or destroyed. The Security+ exam approaches it from three angles: recognising the categories, applying a classification, and matching controls to the state the data is in. The categories PII — personally identifiable information. Anything that identifies a specific person, alone or combined with other data: name, address, date of birth, government ID numbers, biometrics. Note the "combined with" part — a postcode alone identifies nobody, but postcode plus date of birth plus gender often identifies exactly one person. Questions about re-identification are testing that idea. PHI — protected health information. Health data tied to an individual: diagnoses, treatment, test results, insurance details. Regulated by HIPAA in the United States, and treated as a special category under GDPR. Cardholder data. Payment card information, governed by PCI DSS rather than by law. Financial information. Acco...

Data in Transit: TLS, Downgrade Attacks and Inspection Trade-offs

Data in transit is data moving across a network — between client and server, between services, between data centers. Unlike stored data, it passes through infrastructure you do not own, and every device along the path is a potential observer. What TLS Guarantees TLS provides three things, and it is worth naming them separately because attacks target them separately. Confidentiality — the content is encrypted. Integrity — modification in flight is detected. Authentication — the server proves its identity with a certificate. Client authentication is optional and comparatively rare. The handshake negotiates a cipher suite, validates the certificate chain against a trusted root, and agrees a session key. Bulk traffic is then encrypted symmetrically, since asymmetric operations are too slow for volume. TLS 1.3 removed the older key exchanges, made ephemeral keys mandatory so every session has perfect forward secrecy , and cut the handshake to one roun...

Data at Rest: Full Disk, File and Database Encryption Compared

Data at rest is data sitting in storage rather than moving across a network or being processed. Disks, databases, backups, archives, object storage, the flash in a phone that was left in a taxi. The useful question is never "is it encrypted" but "encrypted against whom". Each layer of encryption defeats a different attacker, and several of them defeat almost nobody once the system is running. Full Disk Encryption The entire volume is encrypted, and the operating system decrypts transparently as it reads. BitLocker, FileVault, LUKS. What it protects against: physical theft of the device or drive. Someone who pulls the disk and mounts it elsewhere gets ciphertext. What it does not protect against: anything at all once the system is booted and unlocked. Every process, every logged-in user, and any malware running on that machine sees plaintext, because the operating system is decrypting for them by design. This is the single most important point about FDE...

Tokenization Explained: Vaults, PCI Scope and Format Preservation

Tokenization replaces a sensitive value with a substitute — a token — that has no mathematical relationship to the original. The real value is held in a separate, heavily protected store, and the token is used everywhere else. The exam tests it mainly against encryption, and the difference is fundamental rather than a matter of degree. Tokenization versus encryption Aspect Encryption Tokenization Relationship to original Mathematical, reversible with the key None — a random substitute Reversal requires The key Access to the token vault Ciphertext / token is Still sensitive data Not sensitive on its own Key compromise Exposes all data encrypted with it No key to compromise Format Usually changes Can be preserved The row that matters most is the third. Encrypted card data is still card data — it is protected, but it is in scope for compliance and it becomes readable if the key is obtained. A token is a meaningless reference; stealing a database of tokens yields nothing, becau...