34 ms·
As a potential user I disagree. I absolutely want to know that it doesn't matter if my storage provider is hacked because all the data is E2EE. Once everything
by ianopolous 6y ago
As a potential user I disagree. I absolutely want to know that it doesn't matter if my storage provider is hacked because all the data is E2EE. Once everything is encrypted then you can comfortably layer cryptographic access control on top.
- Vinnl 6y agoI think that intended to say that it's not important in the sense of being able to use Solid. It's up to you to choose who hosts your Pod (or you can do it yourself), and that's where you are able to decide whether the host encrypts your data at rest.
- pwdisswordfish4 6y ago> As a potential user I disagree. You can't disagree, at least not in an informed way, because your idea/position on the follow-on effects are based on a misunderstanding of what Solid is. Asking if "is the data in solid encrypted at rest" is like asking if email is encrypted at rest. It can't be answered, because it's the wrong question. The right question is "Does $PROVIDER keep my data encrypted at rest?"
- ianopolous 6y agoIt sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver plain text? That is not what I want as a consumer. I want something where I don't have to trust the server at all, i.e. everything is E2E encrypted - and if that's not true, that's not a protocol I want interacting with my personal data. The comparison with email is apt, because no one in their right mind would design email as it is today without E2E encryption baked into the protocol.
- Vinnl 6y agoKeep in mind that you can run your own server though.
- ianopolous 6y agoYep, and that can still get hacked, or a number of other failure modes.
- dijksterhuis 6y agoSo did Iran's air gapped nuclear enrichment plant. Nothing is ever 100% secure. Ever.
- ianopolous 6y agoIf Signal's servers are hacked the attacker can see exactly zero of my messages (even an active attacker that controls the server). E2E encryption protects against hacked servers.
- dijksterhuis 6y agoThere are much cheaper ways to get around end to end encryption. https://xkcd.com/538/ https://xkcd.com/538/
- dijksterhuis 6y ago> It sounds like SOLID the protocol requires the pod server to have access to your data, because it requires the server to both enforce access control and deliver plain text? Yes. Exactly. > That is not what I want as a consumer. Okay. Don't use it then. > I want [magic beans]. Good for you. I want Heather Graham as my wife. More seriously, what you want doesn't exist yet. Not in a useful way at least. Maybe go build it yourself if it's something you really want. Or maybe accept the fact that security is not an absolute, it inherently comes with tradeoffs. Like life, really. > The comparison with email is apt, because no one in their right mind would design email as it is today without E2E encryption baked into the protocol. Have you ever worked at a company where they were legally required to do audits or handle large financial transactions? Cos baked in E2E encryption would make detecting malicious employees (defrauding clients etc) really difficult to do, and prosecuting them nigh on impossible. Like I said, security comes with tradeoffs. Golden rule of security: it can't be 100% secure and usable. The one time pad is a classic case of this golden rule.
- ianopolous 6y agoNo need to be rude. I'm just trying to understand the limitations of the protocol. A group of us are actually building this ourselves. See https://book.peergos.org https://book.peergos.org or https://github.com/peergos/peergos https://github.com/peergos/peergos The key phrase relevant to this discussion is "trust-free servers".
- dijksterhuis 6y ago> No need to be rude. I wasn't. But I was sarcastic and facetious. There's a difference. > I'm just trying to understand the limitations of the protocol. It did not read like that in the slightest. It read like someone who wants to hit everything that looks like a nail with the end to end encryption hammer. > A group of us are actually building this ourselves. See https://book.peergos.org https://book.peergos.org or https://github.com/peergos/peergos https://github.com/peergos/peergos Great! All the best with that. > The key phrase relevant to this discussion is "trust-free servers". Not with the solid standard it isn't. That's a completely different use case/problem that you're talking about. Solid is attempting to solve the "all of my data is stored, pretty poorly, by thousands of different companies in hundreds of different ways, and I don't have any control over it" problem. It's about data ownership, not server trust.
- dijksterhuis 6y agoThere are more specific FAQs on this subject further down the page. > Is data in my Pod safe? Is the Pod encrypted while it is stored on a provider’s system? > It depends on the Pod Provider. Pod providers can be Solid compliant without encrypting the data stored on the Pod providers’ system. If this encryption is important to you, use a Pod provider that does encrypt you data. The Solid standard describes rules for controlling access to the data, but encryption is dependant on the storage system, which is controlled by the Pod Provider. > Is my data safe when I use a Solid application? > It depends on the app. Your data is always encrypted in transit from Pod to app and vice versa. You should always be conscious about which apps you are using the terms of those apps. Solid allows you to selectively share data with specific applications. Solid is just a new standard for data reuse. Who knows, maybe solid v2 will be E2EE. In the mean time, you can choose a pod provider that fits your crypto needs.