8 ms·
> "First it is important to understand what this encryption module is actually supposed to do and understand the threat scenario. The encryption provides no sec
by schlowmo 11y ago
> "First it is important to understand what this encryption module is actually supposed to do and understand the threat scenario. The encryption provides no security against a malicious server operator, because the encryption happens on the server. The only scenario where this encryption helps is if one has a trusted server that is using an untrusted storage space."
While it's a good finding that even in this specific scenario the crypto-module is screwed up, I think an even bigger problem is that most people hosting owncloud either don't know or care about all threats not covered by this scenario.
I heard stuff like "Owncloud has crypto, so it must be secure." from people hosting owncloud on server they didn't have much control (especially physically) about. It's not only the "malicious server operator" but everyone with administrative access (legitimate or not) to this server.
But unfortunately I don't know a selfhosted easy-to-install-and-use alternative with strong client-side encryption, which boils down to: Dropbox (or any other cloud storage provider) with client-side encryption of your own choice is more secure than owncloud with only the crypto-module.
- fapjacks 11y agoI just want to add a big emphasis to "YOUR OWN CRYPTO" with Dropbox. Stuffing data into Dropbox without encrypting it first for example with VeraCrypt is a bad choice. Even Dropbox says their own employees "need" access to your data "occasionally". (Also, I meant to upvote you but I fat-fingered it on my phone, sorry!)
- drdaeman 11y agoVeraCrypt or other FDE-like tools (that are meant to be used on actual drives or their imitations using a file-backed device) are not so great idea for use with Dropbox or alike file/object storages. Here's why: http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/ http://sockpuppet.org/blog/2014/04/30/you-dont-want-xts/
- giovannibajo1 11y agoIs there a client side encryption tool that works with Dropbox and is usable by non technical people (plus for being available on both Windows and Mac)? I personally use encfs to create a partition within Dropbox, but I don't see that being easy to setup and manage...
- dublinben 11y agoEncFS is specifically not safe to use in situations where an attacker has multiple versions of your data.
- g_p 11y agoCryptomator [1] looks like it fits the bill for what you described. Seems to use a transparent mapped virtual WebDAV drive to make it usable. From my experiments at least, it seems it should be usable by non-technical people without significant demonstration or training. [1] https://github.com/cryptomator/cryptomator https://github.com/cryptomator/cryptomator
- netheril96 11y agoTime to promote my project `securefs` again (https://github.com/netheril96/securefs https://github.com/netheril96/securefs). Written specifically to address that XTS issue.
- schlowmo 11y agoYes, maybe I should've made this emphasis stronger in my comment. Also I didn't meant to say that using owncloud is worse than using dropbox in security terms - but you should use your own (client-side) crypto either way if you care about data security. For myself I use my selfhosted owncloud (running on a cheap VPS) with EncFS, encourage other users on that server to use client-side encryption as well and never lied about how secure their data is when they decide not to. But this isn't so easy as it should be.
- bigiain 11y agoI also use EncFS - on Dropbox/GoogleDrive/JottaCloud - but be aware it's got known flaws, don't rely on it if your data might be of interest to a nation state or high level law enforcement: https://defuse.ca/audits/encfs.htm https://defuse.ca/audits/encfs.htm
- drdaeman 11y agoFor those who aren't afraid of manual control (which can be a pro or con) and a bit cryptic CLI invocations, I'd say - give git-annex a try. It works with multiple remotes (hubiC, OneDrive and SFTP) flawlessly for me. A basic file management is well automated by git-annex-assistant (e.g. just moving a file to "archive" directory makes sure necessary number of remotes have a copy and a local one is then removed, etc etc.), but the initial setup has to be done by a tech-savvy person who had spent some time reading the docs.
- educar 11y agoWell, you can use client side encryption with Owncloud as well. What makes dropbox special?
- schlowmo 11y ago> "or any other cloud storage provider" I just wanted to point out that as long as you're not in full control of the server hosting Owncloud (and not connect your Owncloud to third party cloud spaces) you've to care about your own client-side crypto like on any other cloud provider (self hosted or not). So there's nothing special about Dropbox - but also not so much special in security terms about Owncloud. Anyway I would still recommend using Owncloud over any other cloud storage provider if you're able to host it or know someone hosting it. But you should consider the security implications if you care.
- JohnIcare 11y agoThere is seafile ( https://www.seafile.com/en/home/ https://www.seafile.com/en/home/ ) which provides client side encryption. Easy to install and to upgrade (except a small glitch in the last upgrade). For the community version, the source code is here : https://github.com/haiwen/seafile https://github.com/haiwen/seafile (see others haiwen projects). The Android client could be improved, but it does the job.
- dchest 11y agoThis issue in Seafile was lovely: https://github.com/haiwen/ccnet/issues/35 https://github.com/haiwen/ccnet/issues/35 /* truly random sequece read from /dev/urandom. */ static unsigned char salt[8] = { 0xdb, 0x91, 0x45, 0xc3, 0x06, 0xc7, 0xcc, 0x26 }; https://github.com/haiwen/seafile/issues/587 https://github.com/haiwen/seafile/issues/587 Enough to understand if people writing this software know how to apply cryptography. This was 2 years ago, so I hope they improved.
- Artemis2 11y agohttps://xkcd.com/221/ https://xkcd.com/221/
- krylon 11y agoThanks for saving me from having to look that one up. Incredible that people will actually do this in production code. I don't understand a lot about cryptography, and even I know this not a good idea.
- dspillett 11y agoAlso, though less exactly relevant: http://dilbert.com/strip/2001-10-25 http://dilbert.com/strip/2001-10-25
- Semaphor 11y agoWhat seems truly scary is how little the developer seemed to care about those security bugs (following related issues, you also find an exploit, SQL injection and so on) and being dismissive of the guy who found them.
- danieldk 11y agoBittorrent Sync does end to end encryption, and you can set up an encrypted read-only peer that never sees any plain text. The encrypted peer does contribute to the swarm.