3 ms·
I mean any cloud is trivial to secure if you just use strong encryption on anything you put on it.
by MaybeItsMia 4y ago
I mean any cloud is trivial to secure if you just use strong encryption on anything you put on it.
- rnd0 4y agoHere's the deal -is there an ecryption that's actually secure against state-level actors? Someone with the resources of the FBI etc? Now, before you say "I don't do anything illegal so it doesn't matter, I'm only worried about corporations" think for a minute about how often companies do have ties (even informal ones -like friends) with people who work in agencies with those resources. You still run the very real and likely risk of a quid-pro-quo ("hey, if you can give us a way to peek into these encrypted drives we'll leave the listings out for you /wink"). In the year of Our Lord 2022 I really would not trust cloud encryption -strong or otherwise; at least not for me personally and my personal/hobby data. If I was working for a company that has a legal department with teeth behind me and I was storing things on the cloud for them? That would be a different ballgame.
- newpavlov 4y ago>is there an ecryption that's actually secure against state-level actors Any modern symmetric encryption is extremely likely to be safe against state-level actors for the observable future assuming your encryption key is not compromised and has enough entropy in it. Even with quantum computers you only need twice longer keys. Roughly, AES-256 would provide AES-128 level of security in the presence of practical quantum computers. If you feel especially paranoid about potential backdoors in algorithms, you can chain several algorithms from different organizations (e.g. AES, Kuznyechik, ChaCha20, and SM4) initialized with different keys. Though such practice is frowned upon by cryptographers.
- ShredKazoo 4y ago
- bitwize 4y agoNo algorithm can stand up to rubber-hose cryptanalysis. Relevant xkcd: https://xkcd.com/538/ https://xkcd.com/538/
- Sohcahtoa82 4y ago> Here's the deal -is there an ecryption that's actually secure against state-level actors? Someone with the resources of the FBI etc? Yes. AES-256. One-Time Pads as well, but of course then you have the problem of how to securely store the pad.
- jbverschoor 4y agoFor now
- Sohcahtoa82 4y agoUnless some mathematics/cryptography genius finds a vulnerability in the AES algorithm, or we improve processing power by many orders of magnitude, AES-256 is going to be immune to nation-state actors for decades or even hundreds of years. Right now, trying to break something encrypted with AES-256 is pretty futile. Even if you pointed every processor in the world at breaking it, you're likely to reach the heat death of the universe several times before succeeding.
- jbverschoor 4y agoEncryption does not mean it can never be read. Just a matter of time
- sgent 4y agoI don't care who crack's my Excel spreadsheet years after the heat death of the universe.