Live data from Hacker News

End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

brokencloudstorage.info

11–20 of 105 posts

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#12
post #11

The world changes once you realize why usually encryption is capped at AES256...

256 bit symmetric cryptography keys are a bit like picking one atom in the universe (10^80 atoms, or 100000000000000000000000000000000000000000000000000000000000000000000000000000000). Your opponent would have to test half of the atoms in the universe to have a reasonable chance of getting the right key.

That's generally understood to be not feasible.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#13
Nice to see that Tresorit didn't have any serious issues in this analysis, I've been using that for a long time and it works really great, also one of the few players that have a really good Linux client.

The two vulnerabilities they found seem pretty far-fetched to me, basically the first is that a compromised CA server will be able to create fake public keys, which I honestly don't know how one could defend against? Transparency logs maybe but even that wouldn't solve the issue entirely when sharing keys for the first time. The second one around unencrypted metadata is hard to assess without knowing what metadata is affected, it seems that it's nothing too problematic.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#15

Hmm, I wish the author had reviewed Proton. I think it's kind of seen as a meme here? But I heavily rely on it and generally the Proton ecosystem is getting better and better from a UX perspective

I think Proton is more viewed as a honeypot

I have not seen this take before, do you have any pointers to someone making this claim?

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#16
post #15

Earlier quoted context omitted.

I think Proton is more viewed as a honeypot

I have not seen this take before, do you have any pointers to someone making this claim?

From my reading, the “ProtonMail is a honey trap” meme seems to be a popular rumor. Seems like there might be some smoke, but I haven’t seen any fire.

Interesting breakdown[1] of one of the claims that E2E encryption on ProtonMail is broken.

I’m assuming that Proton storage is a product from the same team as ProtonMail.

[1] https://lemmygrad.ml/post/4177

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#17
post #15

Earlier quoted context omitted.

I think Proton is more viewed as a honeypot

I have not seen this take before, do you have any pointers to someone making this claim?

Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaScript on the client side, etc. To me, this smells like Crypto AG [3][4].

[1] https://proton.me/about/team

[2] https://steigerlegal.ch/2019/07/27/protonmail-transparenzber...

[3] https://en.wikipedia.org/wiki/Crypto_AG

[4] https://en.wikipedia.org/wiki/Operation_Rubicon

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#18
post #15

Earlier quoted context omitted.

I have not seen this take before, do you have any pointers to someone making this claim?

Founders with US affiliation/physicist creating crypto products [1], faulty claims how the relevant Swiss law (BÜPF) applies to them [2], doing crypto in JavaScript on the client side, etc. To me, this smells like Crypto AG [3][4]. [1] https://proton.me/about/team [2] https://steigerlegal.ch/2019/07/27/protonmail-transparenzber... [3] https://en.wikipedia.org/wiki/Crypto_AG [4] https://en.wikipedia.org/wiki/Operation…

Is the suggestion that founders who have US affiliation are automatically in bed with three letter agencies?

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#19

Hmm, I wish the author had reviewed Proton. I think it's kind of seen as a meme here? But I heavily rely on it and generally the Proton ecosystem is getting better and better from a UX perspective

I think Proton is more viewed as a honeypot

So what's the alternative?

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#20
post #14
post #11

The world changes once you realize why usually encryption is capped at AES256...

Care to enlighten us? What did you realize?

It's too CPU heavy and your webservers crash under load would be my guess, for no added benefit [1] of course.

[1] https://security.stackexchange.com/questions/14068/why-most-...

Post reply on HN