4 ms·
Is the data in solid encrypted at rest? If your pod gets hacked does all your data get exposed?
by ianopolous 6y ago
Is the data in solid encrypted at rest? If your pod gets hacked does all your data get exposed?
- dijksterhuis 6y ago> When using Solid, how is data stored? > It depends on the Pod Provider. From a user point of view, how the data is stored is not as important as how it is accessed and controlled. No matter who the Pod Provider is, in order to be Solid compliant, it has to expose data the same way: as resources in folders. However,the implementors of the standard are free to pick the underlying technologies according to their own purposes and constraints. That is why performance may vary from one Pod Provider to another. > As any standard, Solid only describes the interaction model the system must be compliant with. The Pod Provider only exposes a REST read-write interface to the clients, to which the storage technology is irrelevant, as it is in most Web-based systems. How this interface binds with the storage is specific to each Pod Provider. https://solidproject.org/faqs#pod https://solidproject.org/faqs#pod Solid is just the standard. It's up to others (e.g. inrupt) to build the actual thing.
- ianopolous 6y agoAs a potential user I disagree. I absolutely want to know that it doesn't matter if my storage provider is hacked because all the data is E2EE. Once everything is encrypted then you can comfortably layer cryptographic access control on top.
- Vinnl 6y agoI think that intended to say that it's not important in the sense of being able to use Solid. It's up to you to choose who hosts your Pod (or you can do it yourself), and that's where you are able to decide whether the host encrypts your data at rest.
- pwdisswordfish4 6y ago> As a potential user I disagree. You can't disagree, at least not in an informed way, because your idea/position on the follow-on effects are based on a misunderstanding of what Solid is. Asking if "is the data in solid encrypted at rest" is like asking if email is encrypted at rest. It can't be answered, because it's the wrong question. The right question is "Does $PROVIDER keep my data encrypted at rest?"
- ianopolous 6y agoIt sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver plain text? That is not what I want as a consumer. I want something where I don't have to trust the server at all, i.e. everything is E2E encrypted - and if that's not true, that's not a protocol I want interacting with my personal data. The comparison with email is apt, because no one in their right mind would design email as it is today without E2E encryption baked into the protocol.
- Vinnl 6y agoKeep in mind that you can run your own server though.
- ianopolous 6y agoYep, and that can still get hacked, or a number of other failure modes.
- dijksterhuis 6y agoSo did Iran's air gapped nuclear enrichment plant. Nothing is ever 100% secure. Ever.
- ianopolous 6y agoIf Signal's servers are hacked the attacker can see exactly zero of my messages (even an active attacker that controls the server). E2E encryption protects against hacked servers.
- dijksterhuis 6y agoThere are much cheaper ways to get around end to end encryption. https://xkcd.com/538/ https://xkcd.com/538/
- 6y ago
- dijksterhuis 6y agoThere are more specific FAQs on this subject further down the page. > Is data in my Pod safe? Is the Pod encrypted while it is stored on a provider’s system? > It depends on the Pod Provider. Pod providers can be Solid compliant without encrypting the data stored on the Pod providers’ system. If this encryption is important to you, use a Pod provider that does encrypt you data. The Solid standard describes rules for controlling access to the data, but encryption is dependant on the storage system, which is controlled by the Pod Provider. > Is my data safe when I use a Solid application? > It depends on the app. Your data is always encrypted in transit from Pod to app and vice versa. You should always be conscious about which apps you are using the terms of those apps. Solid allows you to selectively share data with specific applications. Solid is just a new standard for data reuse. Who knows, maybe solid v2 will be E2EE. In the mean time, you can choose a pod provider that fits your crypto needs.