3 ms·
Once it’s in the cloud, it’s already compromised. Best way to keep a secret is don’t share it. Cloud storage is by necessity sharing the secret with the cloud
by manicdee 5y ago
Once it’s in the cloud, it’s already compromised.
Best way to keep a secret is don’t share it. Cloud storage is by necessity sharing the secret with the cloud server and everyone with access to it.
- lokedhs 5y agoIn general, I agree with you about avoiding cloud storage, but it's important to remember that the secret is the cleartext data. The encrypted data is not secret, and that's the whole point of encryption. As long as you store the encrypted vault on a cloud service, your secrets are not shared. The problem in this case is that you are running the vendor's code on your local machine to perform the encryption, and that's where the real issue is. You have to trust that that code is completely bug free. This issue is made worse by the fact that things are uploaded to the cloud, but it's not the underlying problem.