3 ms·
You will be able to comply with a surveillance request WHEN a customer has to restore. Also, you've done nothing to address the risk eavesdropping due to 'bleed
by CodeWriter23 9y ago
You will be able to comply with a surveillance request WHEN a customer has to restore. Also, you've done nothing to address the risk eavesdropping due to 'bleed style exploits while transmitting my passphrase to BB servers. The passphrase should stay on my hardware period.
- brianwski 9y ago> address the risk eavesdropping due to 'bleed style exploits while transmitting my passphrase to BB servers You are correct. There is a "window of decreased security" where IF there was a zero day hack on the same day you prepared a restore -> your data might be compromised. > The passphrase should stay on my hardware period. For some customers and some data, that is true. If you would PREFER to lose your data than to have even a 0.000001% chance of that data being read by hackers then I totally agree with you. A good example is if you will immediately be arrested and sent to jail for the rest of your life if the information in your files is ever discovered, then you should keep the passphrase on your hardware (or preferably only in your head and never written down). But let's say the data is simply all your pictures of your dogs and your vacations? That type of customer might value increasing the chance of getting the data back over the ultimate security solution. Having a recoverable password lowers security (because anybody who gains access to your email can now access your data) but it increases the chance of data recovery. People forget passwords sometimes. Different customers have different preferences, and Backblaze tries to offer several valid choices and let the customer decide which one to use.
- CodeWriter23 9y agoYou're really conflating issues. Yes, Store the Passphrase-protected private key on your server. No, do not send my passphrase to your server for a restore. Yes, send the private key to my client. No, do not decrypt my data server side. Yes decrypt it client side after I enter my passphrase into my client. No, don't transmit my passphrase anywhere at all. By arguing the passphrase should be sent to BB servers, you're unnecessarily violating two fundamental principles of security, least access and least privilege.