3 ms·
You’re saying that security isn‘t black and white, but trust somehow is, which I find a bit weird, since they‘re intimately related. Backblaze could easily red
by red0point 5y ago
You’re saying that security isn‘t black and white, but trust somehow is, which I find a bit weird, since they‘re intimately related.
Backblaze could easily reduce the trust required, which they‘re not doing, but have been promising to do for years, with nothing happening.
Also, given your threat model, I‘d say the risk-mitigation is not applicable. Attackers lying low and continuously collecting and exfiltrating data is nothing new. Especially if this data includes passwords, private keys and data „zipping-by“.
Or does your threat model include specifically only an attacker being advanced enough to compromise Backblaze, but somehow not being able to persist for a while?
No, it‘s Backblaze‘s job of keeping data safe the best way possible, it shouldn‘t be necessary for customers to find excuses for their bad encryption scheme or to add another layer of encryption, especially if the fix is quite obvious and has been promised for years.