SAN DIEGO - Symitar will unveil a secure-communications option in an upcoming version of Episys that will, for the first time, protect confidential core data traveling back and forth between the Symitar host and its more than 600 CU clients, the data processing provider told Credit Union Journal.
Currently, unless an individual credit union is taking independent steps to encrypt transmissions with Symitar, member data is most likely traveling in “clear text” format, which can be intercepted and stolen, several Symitar credit unions have told Credit Union Journal.
Symitar clients will be able to opt to run Episys with or without the new secure communications tool, said John San Filippo, marketing manager, Symitar. Although the tool will be free as part of upcoming versions, “there is a cost in the form of performance, complexity, certificate management, and operational expense that each credit union will need to evaluate before turning this feature on,” he said.
Instead of waiting for Symitar, Numerica CU in Spokane, Wash., took matters into its own hands about two years ago. The $750-million CU knew that Episys data was traveling unprotected, but it wasn’t something to brag about–especially to examiners, said Chris Hyde, VP-IT.
“In the past, core system providers never would have thought that people would attach a sniffer to the network and grab packets of core data,” he said.
“We started looking around to see what we could do about it,” Hyde continued. Numerica revealed the vulnerability to TraceSecurity, a Baton Rouge, La.,-based provider of security compliance and risk management solutions, during an external security audit.
Working together, TraceSecurity and Numerica came up with TraceTunnel for Episys users, a Java-based tool that can encrypt all data flowing between CU workstations and the Symitar host. In fact, TraceTunnel can secure any TCP/IP communication between two systems, as long as the programs run on a Java Virtual Machine.
“It’s just a Java app that sits on the client PCs and the host system and creates a secure SSL connection between the client and host to encrypt all the traffic,” Hyde said. “We and the examiners were really happy about it.”
Numerica grabbed a 2007 Best Practices award from the CUNA Technology Council for its implementation of TraceTunnel, which it installed in 2006.
Like many applications, TraceTunnel is a diamond in the rough, Hyde said. “Some of the Symitar apps push out a lot of data, which slowed down communications at remote branches. We worked to tweak some of the Java code and speed it up. While we’ve done a lot of tweaking to get good performance out of it, we’re not finished yet, and we continue to work with Trace to improve the performance.”
Whereas Trace encryption is virtually impenetrable to the public and to most employees, there are some employees who are “power users” who would be able to turn off TraceTunnel and reconfigure the Symitar client, allowing data to flow unprotected once again, Hyde said.
“That’s one of the weak points,” he said. “An ideal solution is one that couldn’t be turned off.”
Symitar did not say why it hasn’t provided encryption capabilities up to this point. Said Hyde: “They probably have their reasons. It probably requires a large rewrite of their client software. But they could fix it before they release their next version by using a secure shell or SSH connection.”
When Symitar announces the release of its encryption offering, Hyde isn’t sure whether he’ll move away from TraceTunnel. “We’ll just have to wait and see which tool is better,” he said.
Credit unions concerned about data in transmission may want to consider an entire network encryption solution instead of any isolated communications tool, San Filippo added.
“Core processing represents only a portion of the traffic across any credit union network,” he said. “That’s why encryption has long been the function of the communications equipment and not necessarily any particular software application–because such an approach provides protection across the board. Thus, other options, such as an entire network encryption solution, may prove to be more desirable if the CU is looking for complete data protection.”
Hyde agreed that a full-network encryption appliance would be “nice,” but that such tools “haven’t worked well with Symitar’s client software in the past. However, we will probably reevaluate whole-network encryption, as well as Symitar’s solution when it becomes available.”
MORE
Read more about data encryption at cujournal.com and search the following bolded terms in the archive:
When Data Destruction Is Good
Encrypting Member Data
CU Questions Why Examiner Is Taking Member Data Home
For info on this story:
* www.numericacu.org
* www.symitar.com
* www.tracesecurity.com(c) 2008 The Credit Union Journal and SourceMedia, Inc. All Rights Reserved.http://www.cujournal.com http://www.sourcemedia.com











