Data Encryption Methods

Explore top LinkedIn content from expert professionals.

  • View profile for Laurie Kirk

    researcher @google; serial complexity unpacker

    93,514 followers

    Encryption is kind of a lie. Data can be encrypted at rest, and even in transit…but not “in use”. Fundamentally, CPUs execute arithmetic instructions on decrypted plaintext; even with secure enclaves. But what if we got *really* clever: — Mathematically, there is a solution. It’s just really, really slow. Fully Homomorphic Encryption allows for arithmetic computation *on* encrypted data. First published in 2009, each individual (x86) operation took 30 minutes!  AKA, about 10^12 times slower. — So why bother? Ignoring the performance costs, FHE opens up wild possibilities. Imagine being able to run ML models, Health Data processing, or financial transactions and not having to trust the cloud provider *at all*. — In 2025, we’ve gotten a million times faster; literally. Check out Google’s HEIR project as a quick way to play around with FHE in Python. As for accelerators themselves, there’s growing competition in this space!  Zama, Cornami, and Belfort Labs are doing a lot of interesting work in software, GPUs, FPGAs, and even custom silicon.

  • View profile for Alex Xu
    1,034,047 followers

    A Cheatsheet to Build Secure APIs An insecure API can compromise your entire application. Follow these strategies to mitigate the risk: 1 - Using HTTPS Encrypts data in transit and protects against man-in-the-middle attacks. This ensures that data hasn’t been tampered with during transmission. 2 - Rate Limiting and Throttling Rate limiting prevents DoS attacks by limiting requests from a single IP or user. The goal is to ensure fairness and prevent abuse. 3 - Validation of Inputs Defends against injection attacks and unexpected data format. Validate headers, inputs, and payload 4 - Authentication and Authorization Don’t use basic auth for authentication. Instead, use a standard authentication approach like JWTs Use a random key that is hard to guess as the JWT secret Make token expiration short For authorization, use OAuth 5 - Using Role-based Access Control RBAC simplifies access management for APIs and reduces the risk of unauthorized actions. Granular control over user permission based on roles. 6 - Monitoring Monitoring the APIs is the key to detecting issues and threats early. Use tools like Kibana, Cloudwatch, Datadog, and Slack for monitoring Don’t log sensitive data like credit card info, passwords, credentials, etc. Over to you: What else would you do to build a secure API? -- Subscribe to our weekly newsletter to get a Free System Design PDF (158 pages): https://bit.ly/bbg-social #systemdesign #coding #interviewtips .

  • View profile for Jen Easterly

    CEO, RSAC | Former Director, CISA | Cyber + AI | Leader | Speaker | Innovator | Optimist | #MoveFast&BuildThings

    128,553 followers

    On 13 Nov, the Cybersecurity and Infrastructure Security Agency & the Federal Bureau of Investigation (FBI) released a statement (https://lnkd.in/ezrFy_4j) on the US government's investigation into PRC targeting of telco infrastructure: “PRC-affiliated actors have compromised networks at multiple telecommunications companies to enable the theft of customer call records data, the compromise of private communications of a limited number of individuals who are primarily involved in government or political activity, and the copying of certain information that was subject to U.S. law enforcement requests pursuant to court orders. We expect our understanding of these compromises to grow as the investigation continues." With the investigation ongoing, folks should take basic steps now to protect their personal communications. With gratitude to CISA's Senior Technical Advisor Bob Lord (https://lnkd.in/e-WxWiFF) consider the below steps: - Enable FIDO authentication or FIDO https://lnkd.in/ezzyha7t for email & social media accounts - Migrate off SMS MFA for all other logins. Migrate to FIDO/passkeys if you can, otherwise to an authenticator app - Use a password manager for all passwords. Use a strong pass phrase (https://lnkd.in/ebPpTAU5) for the vault password. - Set a telco PIN to reduce chances of a SIM-swap attack - Update the OS and all apps and turn on auto update Additional tips: 1. Encrypt all text and voice communications (some options): - Signal works well on iPhones & Android phones. - iMessage is great if all your contacts are within the Apple ecosystem, though that’s limiting - Collaboration suites like Google Workspace or Teams can work but don’t always encrypt as you might assume. For example, Teams encrypts data point-to-point, meaning it’s decrypted on Microsoft’s servers before re-encrypting it to the recipient. If you want end-to-end encryption, there’s an option, but it’s off by default and only supports two people on the call. - WhatsApp might be ok for some people based on their threat model but understand metadata it keeps (https://lnkd.in/eQkP-Ety) & how it's used (https://lnkd.in/eiZmxgi4). 2. If you use an iPhone disable these carrier-provided services that increase the attack surface: - Disable: Settings > Apps > Messages > Send as Text Message - Disable: Settings > Apps > Messages > RCS Messaging > RCS Messaging 3. Protect DNS lookups (some options): - Apple iCloud Private Relay - Cloudflare’s 1.1.1.1 resolver - Quad9’s 9.9.9.9 resolver 4. Use recent hardware: Apple (13 or newer) or Google (Pixel 6 or newer) 5. Depending on your threat model, consider enabling Lockdown Mode on iPhones: It will disable some features, but it’s manageable

  • View profile for Joseph Church

    CEO/Founder

    3,368 followers

    📱 Mobile Forensics Breakthrough: The Case of the "Secure" Messaging App A corporate espionage case hinged on communications sent through an encrypted messaging app that claimed to leave "no trace." The suspect had deleted all conversations and performed a factory reset. Challenge: Extract evidence from a wiped device using an app designed for anonymity. Our approach: 🔧 Advanced physical extraction techniques 🔧 SQLite database reconstruction from unallocated space 🔧 Encryption key recovery from system partitions 🔧 Timeline correlation with network traffic analysis The breakthrough came when we discovered the app's "secure delete" function wasn't as secure as advertised. Hidden database fragments contained message metadata, contact information, and partial conversation threads. Result: Complete conversation recovery spanning 8 months, revealing the entire conspiracy network. This case demonstrates why mobile device forensics requires more than standard tools - it demands deep technical knowledge and creative problem-solving. Key lesson: No digital communication is ever truly "gone" if you know where to look and have the expertise to find it. Facing complex mobile evidence challenges? 📧 consulting@digitalshield.net #MobileForensics #DigitalForensics #CyberInvestigation #DataRecovery

  • View profile for Ali K.

    Cybersecurity Marketing | Cyber Resilience Act (CRA)

    4,436 followers

    🇪🇺 CBOM: The New Compliance Imperative by 2026 While most organizations manage a Software Bill of Materials (SBOM), a Cryptographic Bill of Materials (CBOM) remains largely overlooked. Yet, EU regulations are rapidly converging to make cryptographic inventory a mandatory requirement. ||| WHY THIS MATTERS NOW The EU's Cyber Resilience Act (CRA) and NIS2 Directive, alongside the EU PQC Roadmap, are creating a clear mandate for cryptographic transparency. By the end of 2026, understanding and managing your cryptographic assets will no longer be optional, shifting from a niche concern to a core compliance pillar. || WHY SHOULD YOU CARE ↳ Avoid significant non-compliance penalties and market access restrictions under new EU regulations. ↳ Mitigate critical vulnerabilities arising from unmanaged or outdated cryptographic implementations, especially with the advent of post-quantum cryptography. ↳ Prepare for operational overhauls in product development, supply chain management, and incident response requiring new tools and expertise. || ACTIONABLE STEPS ↳ Conduct a comprehensive audit of all cryptographic components within your products and systems. ↳ Develop a robust CBOM generation and management strategy, integrating it into your existing compliance frameworks. ↳ Invest in training and tools to ensure your teams can effectively identify, track, and update cryptographic assets. | RELEVANT STANDARDS AND REGULATIONS This shift is directly driven by the Cyber Resilience Act (CRA), NIS2 Directive, and the EU PQC Roadmap, making cryptographic inventory a critical component of cybersecurity compliance. If you build, certify, or sell connected products in Europe, cryptographic inventory is your new baseline for security and compliance. ♻️ Share this with your product development, security, and compliance teams. P.S. What are the biggest challenges you foresee in implementing a comprehensive CBOM strategy?

  • View profile for Dr. Rajesh Dhuddu, Ph.D

    Partner & Emerging Tech Leader, Leadership Team @CEDA, PWC| Forbes Blockchain 50| Most Inspiring Web 3 Leader| CXO Innovator of the Year| Tedx Speaker| Author| Passionate about Connecting People & Ideas|

    35,356 followers

    Lets Learn #Quantum – Post #16: Post-Quantum Cryptography (PQC) The Invisible Safe: Why Hackers Are Stealing Data They Can't Read Yet The biggest short-term impact of quantum computing isn't what it can create. It is what it can destroy. Right now, our digital world relies on encryption algorithms like RSA to protect banking, emails, and cloud data. Standard supercomputers would take thousands of years to crack them. But quantum computers change the rules. Running Shor’s Algorithm, a quantum computer could break today's encryption in hours. The Threat Happening Right Now Why care today if full-scale quantum computers are still year away? Because cybercriminals are actively executing a strategy known as Harvest Now, Decrypt Later (HNDL). Imagine a thief stealing a locked titanium safe. They cannot open it today, so they hide it in a basement and wait. Years from now, a new tool is invented that pops that safe open instantly. That is HNDL. Bad actors are intercepting and archiving sensitive enterprise data today, waiting for the day a quantum computer can unlock it. If your data needs to remain secret for the next decade, it is already at risk. Enter PQC: Upgrading the Locks Post-Quantum Cryptography (PQC) is the defense. It is a new generation of math shields designed to resist attacks from both conventional and quantum computers. The breakthrough? PQC runs seamlessly on your current servers, smartphones, and cloud platforms. Think of it as swapping out a traditional door lock for a multi-dimensional biometric scanner. The house stays the same; only the lock changes. Instead of traditional math, PQC relies on Lattice-Based Cryptography. Think of it like a maze with thousands of overlapping dimensions instead of two. Even a quantum computer gets completely lost trying to find the exit. The Strategic Reality You cannot swap out the security architecture of a global enterprise overnight. Migrating infrastructure takes years, which is why forward-thinking leaders are already auditing networks and testing PQC algorithms today using a hybrid approach. The quantum threat is not a future IT issue. It is a current strategic risk. The question for leadership is no longer: "When will a quantum computer be built?" The real question is: "Will our data still be secure when it arrives?" #QuantumTechnology #PostQuantumCryptography #PQC #QuantumSecurity #CyberSecurity #QuantumComputing #DigitalTransformation #DataProtection #TechnologyLeadership Co-authored with Atul Tripathi Sundar Ram, Sachin Arora, Himanshu Ghawri, Azizur Rahman, Shivendra singh, Prasun Nandy, Jaydeep Sarkar, Joydeep Roy, Arihant Garg, Amit Kumar, Hetal Shah, Arun Rangaraju, Sayantan Chatterjee, Rajesh Kumar Ojha, Dr. Raghav Manohar Narsalay, Praveen Sasidharan, Sundareshwar K (Sundar), Manu Dwivedi, Venkat Nippani, Himadri Ganguly, Ritesh Jain, Abhijit Chakraborty, Sumit Srivastav, Anit Shanker #soyoucan

  • View profile for The Hon. Victor Dominello
    The Hon. Victor Dominello The Hon. Victor Dominello is an Influencer

    Chief Executive Officer @ Future Government Institute | Co-Founder @ ServiceGen | Service Transformation Expert | Keynote Public Speaker 🎤

    98,751 followers

    🟪 Trust Exchange (TEx) One of the biggest frustrations with red tape is the lack of mutual recognition between states 🤦🏻♂️ We saw this firsthand in 2019 when digital driver’s licences were introduced. While the plastic versions were accepted nationwide, the digital ones were not 🤷🏻♂️ This issue echoes a problem from centuries ago when different rail gauges were installed across states, creating barriers to travel. It took years and significant cost to resolve ➡️ https://lnkd.in/gbpxUFyH We cannot afford to repeat this with Digital ID and verifiable credentials. That’s why the myGov MyGov team at Services Australia is developing the Trust Exchange (TEx) with an “open standards” approach ✅. There are two main international standards in this area: 🔹 ISO (International Standards Organization) 🔹 W3C (World Wide Web Consortium) In the coming months, several proof-of-concept (POC) trials will focus on: 🔹 Gov ➡️ Gov 🔹 Gov ➡️ Business 🔹 Gov ➡️ Customer By supporting multiple standards, TEx will ensure deeper interoperability between verifiable credentials, tested through these POCs in collaboration with stakeholders and jurisdictions. Will keep you updated as more information becomes available re the POCs 🙏

  • View profile for Shubham Palriwala

    CEO @ Agnost AI (YC S26) | We find where your AI agents silently fail, then train better models to run them

    17,661 followers

    Ever wonder how Cloudflare generates encryption keys? They use Lava Lamps. No, seriously. 100 lava lamps on a wall in their San Francisco lobby. The problem was that encryption keys need to be truly random aka unpredictable. Computers are designed to be logical and predictable, not random. If there's any pattern in encryption keys, attackers can guess them. Pattern = compromised data. Then they came up with the idea: Lava Lamps never take the same shape twice. Pure chaos. Cloudflare mounted a camera pointing at 100 lava lamps. It takes photos at regular intervals. Each image becomes a string of totally random numbers (pixel values). These feed into their cryptographic seed for generating encryption keys. It works well because real-world randomness beats computer-generated randomness. The physical world is unpredictable. When someone walks in front of the lamps lol? Even better. The obstruction adds more entropy. Cloudflare calls it the "Wall of Entropy." Millions of websites use Cloudflare's SSL/TLS encryption, protected by lava lamp randomness. Side note: Their London office uses a double-pendulum system (mathematically unpredictable motion). Singapore office measures radioactive decay of a uranium pellet. Each office has its own source of chaos for encryption. That's physical randomness securing the internet. Source: https://lnkd.in/dqym-SxN

  • View profile for Daniel Anderson

    Helping organisations turn AI investment into real outcomes | Microsoft MVP | M365, SharePoint & AI strategy consultant | Creator of Grounded AI, read by 9,000+ professionals weekly

    26,120 followers

    Your company's most sensitive files are one ChatGPT connection away from being exposed. ChatGPT now allows users to connect personal AND work OneDrive accounts directly. While it can't browse your files like Copilot, employees can manually upload any file they can access to ChatGPT for analysis. - That quarterly financial model? Uploaded. - Client contracts? Uploaded. - Strategic roadmaps? Also uploaded. The solution isn't blocking ChatGPT entirely—it's blocking the right way. Sensitivity labels with encryption are your best defense. → ChatGPT cannot authenticate with rights management services → Protected files remain unreadable even when uploaded → Same protection blocks unauthorized Copilot access Most organizations focus on preventing AI tools from connecting to their systems. The real threat is what employees can manually extract and upload. Your policies should account for human behavior, not just automated access.

Explore categories