4 ms·
What the above says is: Your data is encrypted on your device before being sent to MS. MS knows the key Once received, MS decrypts your data, does whatever ser
by coffeeling 5y ago
What the above says is:
Your data is encrypted on your device before being sent to MS. MS knows the key
Once received, MS decrypts your data, does whatever serverside things it wants to on your data (OCR, NSA, search indexing), and then re-encrypts it with a key only they know. Protects your data from unauthorized rogues within Microsoft and random attackers, but not from Microsoft betraying your trust.
If you ask for your data, they decrypt it with their storage keys, re-encrypt it with their transfer keys (which you can decrypt) to guard against middlemen.
You receive the data, you decrypt it.
The model is secure, in that it's resilient against attackers, but requires you to trust the provider to be trustworthy and uncompromised.
That model is much better than some indie apps, which do encrypt your data between your machine and their server and the reverse, but store your data at rest on their server in a plain, unencrypted format. This means attackers and rogue employees have an easier time getting to your data.
True end-to-end or zero knowledge encryption encrypts the data on your device, and the provider's server only ever sees encrypted nonsense, they don't have the keys to undo the decryption even if they wanted to (thus the name zero knowledge). Your data is only decrypted on your device locally.
Edge stores passwords and some other data end to end encrypted, as far as I know, but only some data types. You can't make everything zero knowledge if you tried to. As far as I know, Chrome doesn't do zero knowledge by default, but can be set up to do it.
Firefox, Brave and Vivaldi all run their own sync services and all are (as far as I know) zero knowledge setups.