3 ms·
The safety of ciphertext stored in the cloud is entirely dependent on the lack of state level actors interfering in encryption research, cipher engine design, c
by manicdee 5y ago
The safety of ciphertext stored in the cloud is entirely dependent on the lack of state level actors interfering in encryption research, cipher engine design, chip manufacture, operation of cloud hardware, and day to day safety of cloud operator employees.
The USA has been shown to be quite willing to violate all those conditions: NSA directly influencing cipher design, interfering with chip manufacture, seizing hardware wholesale, and engaging in “enhanced interrogations” in attempts to extract information.
The threat level of this state action is 100% because they aren’t going o spend all that time and money on these tools and not use them. They aren’t focussed on cracking your password, they just crack everyone’s because that is easier to automate (see prior discussion regarding weakening encryption to suit the tools the TLAs already have access to).
At least with my secrets stored on my hardware I have the assurance that the TLAs will need to be targeting me directly in order to obtain my secrets (much less likely than getting caught up in a dragnet).