4 ms·
What's the attack model under which this is better than what Google Photos does? - You still have to give the people who access the photos the key, they can sha
by tpolzer 7y ago
What's the attack model under which this is better than what Google Photos does?
- You still have to give the people who access the photos the key, they can share it (just like the secret link)
- By entering it on the site, they also implicitly share it with the hosting provider (who morally shouldn't grab it, but that's not a security guarantee).
- EmilStenstrom 7y agoOne attack model is the one described in the article, that the links leaks to someone where it shouldn't be. In that case, an encryption key that is set to expire[1], would limit the scope of that leak. Of course, if someone would screenshot the image it could be too late, so the attack model does not include people that know the key will expire... [1]: https://www.w3.org/TR/encrypted-media/#expiration-time https://www.w3.org/TR/encrypted-media/#expiration-time
- Dylan16807 7y agoUnless you change your clock?
- OJFord 7y agoWhy would the verifier change the clock? If 'you' here is the key holder, changing clock isn't going to help.
- Dylan16807 7y agoWhat verifier? The scenario here is embedding an encrypted blob inside a static web page, and having the user input a key to decrypt inside their browser, right? If you're going to have a server checking anything, you're on a whole different wavelength than this scheme. Why even use encryption at that point?
- macspoofing 7y agoOr you can make the link set to expire. Your approach isn't solving any problems, but adds to confusion. Keep in mind Google Photos is a consumer product meant to be used by everyone between tech savvy teenagers and your grandmother.