Live data from Hacker News

End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

brokencloudstorage.info

91–100 of 105 posts

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#91

Earlier quoted context omitted.

So what's the alternative?

Selfhosting

Actually I don't think self-hosting is a viable solution for many people. Most server hosts are not security experts. IT security is really hard due to the many possible attack vectors you have to be knowledgeable about. In this article they assume that an attacker has compromised a server and I don't see how a layman can keep a server safe if experts want to compromise it in the long term if you just follow the reccomend maintenance. One day you will slip up.

You might get a security related update late, did not hear about the last breach and are not aware how that relates to you, all sorts of scenarios. The only way to make it much more difficult to be compromised is if you don't connect your self-hosted cloud solution to the internet. But then it's not a really a cloud solution anymore.

And that's before you have to consider that not everyone has the knowledge, time, interest to self host.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#92
post #83

Earlier quoted context omitted.

KYC for a business is the smart legal move IMO whether it's technically required or not. Yes Proton is required to cooperate with law enforcement and government requests. Mullvad has been raided and Tutanota servers have been seized before too. Nobody is going to jail for you.

Knowing as little as legally possible about your customer is the actually smart move if your entire selling point is privacy. Mail providers aren't bound to specific KYC regulation, proton could simply collect... Nothing. But they still do, why? The only legitimate reason they've given is to prevent spam. Fair enough, spammers using them will impact all users. But then why not impose a captcha when sending emails unt…

> Knowing as little as legally possible about your customer is the actually smart move if your entire selling point is privacy.

Yes I agree, but Proton also provides paid services and it is often the law that you must retain certain records in cases of audits, fraud etc., so there is some necessary KYC in that sense, but perhaps you're right in that they could keep less information, possibly at the cost of increased spam and decreased reputation though, so I understand the struggle.

> But then why not impose a captcha when sending emails

I suppose you could, but perhaps they weighed that possibility against it turning people off to using the service entirely? Not sure.

> When it comes to mullvad I'm not sure what you're trying to say

I was not trying to imply any of those things, just pointing out that companies still have to answer to law enforcement sometimes, that they are not immune from the laws of their country... because I have seen that some people who are staunch privacy enthusiasts seem to think companies have the luxury or practical ability (without detriment to their business) to simply not know their customer at all, and I don't think that is often the case. There is also a balance between simplicity and privacy. If you want anonymous payments that's fine, but crypto isn't as easy to use as a credit card. But if you handle credit cards, you must keep some data by law usually. Things like that.

And some people might just want to sell your info to advertisers or data brokers, there's always that.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#93
post #86

The sad state of E2E encryption for cloud storage is a big part of why I wrote mobiletto [1]. It supports transparent client-side encryption for S3, B2, local storage and more. Rekeying is easy- set up a new volume, mirror to it, then remove old volume. [1] https://github.com/cobbzilla/mobiletto

> Rekeying is easy- set up a new volume, mirror to it, then remove old volume. Right, just have to transfer those 10TB every time a key needs to be rotated, no biggie! I think that is the reason why most systems use two levels of keys (user keys encrypting a master key. Rotating means ditching the user keys, not the master.)

Sure but at some point you need to rotate your master key. Copying is inevitable. At least your tooling can make it easy and reliable.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#94
post #73

Earlier quoted context omitted.

> Tresorit had a game-over vulnerability: I would still (for now, at least) trust Tresorit over any of the US jurisdiction services. I wouldn't put my data on US jurisdiction servers no matter how much money you gave me. I am, for now, tempted to say we should get a detailed explanation from Tresorit before jumping to conclusions. It seems to me the author of the website made many assumptions, it is not clear if they…

I really don't care about this jurisdiction stuff; I'm just here to talk about the cryptography, which, in the case of Tresorit, is not great.

The paper itself seems not to agree with you: “Tresorit’s design is mostly unaffected by our attacks due to a comparably more thoughtful design and an appropriate choice of cryptographic primitives.”

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#95
post #73

Earlier quoted context omitted.

I really don't care about this jurisdiction stuff; I'm just here to talk about the cryptography, which, in the case of Tresorit, is not great.

The paper itself seems not to agree with you: “Tresorit’s design is mostly unaffected by our attacks due to a comparably more thoughtful design and an appropriate choice of cryptographic primitives.”

They have a lot of attacks. Most of these systems are completely clownshoes. But Tresorit appears to be vulnerable to their most severe attack.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#96
post #79
post #74

Earlier quoted context omitted.

Indeed. Borg for example is e2e but able to dedupe. My bookmark archive is 10TB but deduped on-disk size is 100GB because most files are the same across backups! https://www.borgbackup.org/

That’s not the same thing at all.

Same thing as what?

Parent was asking about deduping encrypted data.

Someone said (wrongly) it’s impossible and I shared a popular project that does exactly that.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#97
post #82
post #27

Earlier quoted context omitted.

Correct. Anything higher is an order of magnitude more computationally expensive to do for no real reasonable gain. Multiple layers of encryption get you there far enough. Better to dig deeper into other cryptography methods than try increase AES beyond 256. Its already rather insane how quickly decryption happens.

Hmm, not sure how this was supposed to change my world. I thought you had some secret cabal conspiracy or something to share.

Sorry... I'm boring and easily excited :p

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#98
post #28

Earlier quoted context omitted.

https://www.schneier.com/blog/archives/2009/09/the_doghouse_... It's more than that. Simply incrementing your way through a 256 bit counter is impossible by the thermodynamic cost alone.

Correct. Better to get into other forms of cryptography than pointlessly increase the numbers. We need to think more about PQ proofing.

AES-256 is already post-quantum secure; what exactly are you suggesting?

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#99
post #96
post #79

Earlier quoted context omitted.

That’s not the same thing at all.

Same thing as what? Parent was asking about deduping encrypted data. Someone said (wrongly) it’s impossible and I shared a popular project that does exactly that.

“Not backing up the same file twice” is not the same thing as deduplicating encrypted data, as encryption has no relevance there. You can do that with or without encryption.

Re: End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem

#100
post #15

Earlier quoted context omitted.

I have not seen this take before, do you have any pointers to someone making this claim?

In account creation, requiring a phone number for “spam prevention” on Tor There was some deanonymizing like that, phone or credit card

it is possible to get google captchas as verification on some nodes however it is rare and was easier in the past.

I'm disappointed that they haven't used there own captchas but maybe they will in the future.

Post reply on HN