Live data from Hacker News

CipherCloud Responds to the Crypto StackExchange Controversy

blog.ciphercloud.com

61–65 of 65 posts

Re: CipherCloud Responds to the Crypto StackExchange Controversy

#62
post #29

This is a good example of bad legal/PR turning a company from a fairly well respected new security company to a joke. Tokenization, which CipherCloud does, could actually be done fairly securely if you had a decent amount of local storage. They IIRC use a FIPS HSM for local key storage in their local appliance (I talked to one of their founders as a security event a year or two ago and was initially suspicious of the…

It's nowhere like Stripe's tokenization because all tokens are not equal. Their tokens have inherent patterns which aid frequency analysis. That is exactly the point of the SE discussion which got the DMCA notice.

Re: CipherCloud Responds to the Crypto StackExchange Controversy

#63
post #62
post #29

This is a good example of bad legal/PR turning a company from a fairly well respected new security company to a joke. Tokenization, which CipherCloud does, could actually be done fairly securely if you had a decent amount of local storage. They IIRC use a FIPS HSM for local key storage in their local appliance (I talked to one of their founders as a security event a year or two ago and was initially suspicious of the…

It's nowhere like Stripe's tokenization because all tokens are not equal. Their tokens have inherent patterns which aid frequency analysis. That is exactly the point of the SE discussion which got the DMCA notice.

Yeah, I've never looked at CipherCloud's security in depth, but you could do tokenization in a fairly secure way. There's essentially a triangle of security, functionality-of-SaaS-app, and complexity of the proxy.

One issue is access patterns might leak information, so if you wanted maximum security you'd end up doing crazy things like heavily caching or accessing extra "chaff records" periodically. Well before that point you'd probably just give up on the SaaS app entirely.

Re: CipherCloud Responds to the Crypto StackExchange Controversy

#64

Earlier quoted context omitted.

An example needs to be set. They should be sued for issuing a DMCA notice in bad faith.

Actually, is a DMCA notice against something that's fair use technically bad faith? You are still violating their copyright, you just have a defense against it in court. Ultimately, whether something is fair use or not is the purview of the courts. Does the DMCA require you to make that judgement before submitting a notice? I would guess not. And unfortunately, you can't sue people just for being jerks.

You can sue anybody for anything. The outcome of such action is not guaranteed either way, however.
Post reply on HN