Live data from Hacker News

A Case That Has Microsoft, Apple and Amazon Agreeing

bloomberg.com

21–30 of 190 posts

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#21
post #4

If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem. Furthermore, they wouldn't have to worry about deleting customer data either. The customer would have the power to simply deny access to the keys.

Tarsnap (a service that acts like your description) is quite nice, but the problem of "customer lost the keys" is a very real one. I love the idea, but someone really needs to come up with some decent key management (and offline backup and key migration) to make this consumer friendly.

>decent key management

What about Hashicorp's Vault?

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#22
post #13

Earlier quoted context omitted.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

> push key management to the user There is no other way. Unfortunately, there has been a serious lack of r&d in this area, so we have a lot of catching up to do. I believe it can be made to work, though, because this is not entirely a new idea for most people: they already understand physical keys and the problems associated with losing them. Moving to digital (public-)keys isn't a perfect match, but it is entirely p…

I generally agree with you, but there's one problem with the physical key analogy. The security of physical keys is weak enough that there's always a fallback if you lose all the copies of your key: you pay a locksmith to come pick the lock and rekey it.

You can't do this with digital keys because a digital key that is weak enough for this strategy to be usable is also too weak to protect you from the main class of attacks it's supposed to be protecting you from.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#23
post #4

If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem. Furthermore, they wouldn't have to worry about deleting customer data either. The customer would have the power to simply deny access to the keys.

If the data is opaque to the provider, then there are many services they won't be able to provide on it (without some major advances in homomorphic encryption). For example, spam detection or search. Sharing is also made much more difficult.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#24
post #13

Earlier quoted context omitted.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

> push key management to the user There is no other way. Unfortunately, there has been a serious lack of r&d in this area, so we have a lot of catching up to do. I believe it can be made to work, though, because this is not entirely a new idea for most people: they already understand physical keys and the problems associated with losing them. Moving to digital (public-)keys isn't a perfect match, but it is entirely p…

[deleted]

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#25
It's important to remember that this is the same company that snooped through the emails and files of one of their users while looking for evidence of piracy. They came clean about their snooping moments before court documents were publicly released that detailed what they did.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#26

Earlier quoted context omitted.

Tarsnap (a service that acts like your description) is quite nice, but the problem of "customer lost the keys" is a very real one. I love the idea, but someone really needs to come up with some decent key management (and offline backup and key migration) to make this consumer friendly.

Then, we need a good service to store keys, with a key to get to your key

And that will be a sweet, sweet target...

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#27
post #4

If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem. Furthermore, they wouldn't have to worry about deleting customer data either. The customer would have the power to simply deny access to the keys.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy.

Depending on your target market, that can be a selling point. Tell them early and tell them often that you don't keep copies of their keys and if they lose them, they won't be able to access the information. Remind them to make backups.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#28
post #13

Earlier quoted context omitted.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

> push key management to the user There is no other way. Unfortunately, there has been a serious lack of r&d in this area, so we have a lot of catching up to do. I believe it can be made to work, though, because this is not entirely a new idea for most people: they already understand physical keys and the problems associated with losing them. Moving to digital (public-)keys isn't a perfect match, but it is entirely p…

I guess that Ring can be replaced by a Smartphone or a Smartwatch.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#29
post #13

Earlier quoted context omitted.

The larger issue is that you now have to push key management to the user, and the support problems that go with that. Key management is hard and painful. Telling a customer that they can't access their data on your service because they broke their laptop is going to make them very unhappy. Otherwise, there'd be plenty of services competing with Drive, DropBox, etc, that did just that.

> push key management to the user There is no other way. Unfortunately, there has been a serious lack of r&d in this area, so we have a lot of catching up to do. I believe it can be made to work, though, because this is not entirely a new idea for most people: they already understand physical keys and the problems associated with losing them. Moving to digital (public-)keys isn't a perfect match, but it is entirely p…

People do lose their physical keys though. And in pretty much all cases, there is a recovery mechanism to get at whatever the physical keys are protecting. This may involve drilling a hole or the like, but there is a fallback. With any digital crypto worth using, there is no recovery mechanism.

Re: A Case That Has Microsoft, Apple and Amazon Agreeing

#30
post #4

If companies stored customer data encrypted by keys that are held by the customer, they wouldn't have this problem. Furthermore, they wouldn't have to worry about deleting customer data either. The customer would have the power to simply deny access to the keys.

Tarsnap (a service that acts like your description) is quite nice, but the problem of "customer lost the keys" is a very real one. I love the idea, but someone really needs to come up with some decent key management (and offline backup and key migration) to make this consumer friendly.

It's not really something that can be made "consumer friendly" as far as I can tell (But I'd love to be proven wrong!). How do you securely store the key to your securely stored data?

Admittedly, there are some recommendations on the Tarsnap site (http://www.tarsnap.com/gettingstarted.html):

"5. Keep your key file safe

Store your /root/tarsnap.key somewhere safe. If you lose tarsnap.key, you will not be able to access your archived data. The same encryption which ensures your data security also means that there is no way for anybody (including Tarsnap Backup Inc.) to restore your data without this key. There are many ways to keep it safe: Copy it to a different system. Put it on a USB disk. Give it to a friend. Print it out (it is printable text). Store it in a bank vault. Pick at least one and do it!"

The only other way I can think of to keep the key even safer would be to use Shamir's Secret Sharing to divide the key up and share it among trusted friends and family. (https://en.wikipedia.org/wiki/Shamir%27s_Secret_Sharing).

Post reply on HN