4 ms·
I’m just telling you what their client actually does based on a previous analysis I conducted, not the claims of their documentation. The private key is auto-g
by csnover 5y ago
I’m just telling you what their client actually does based on a previous analysis I conducted, not the claims of their documentation.
The private key is auto-generated by the Backblaze Client installer and gets sent to their server at install time. This is done before the user has any choice to set a passphrase. Setting a passphrase later does not generate a new keypair, it just sends that passphrase to their server so the server can re-encrypt the private key using the new passphrase.
Because the key is uploaded at install time and doesn’t ever change, they already have the private key in unencrypted form. When a user tries to protect it, now they also have the user’s passphrase. There is no technological way by which “PEK” shields your data from Backblaze, even at rest, as implemented.