4 ms·
The encryption key must reside only on trusted (client side) devices to allow your data to be hosted by a third party without them actually seeing your data.
by tommi 15y ago
The encryption key must reside only on trusted (client side) devices to allow your data to be hosted by a third party without them actually seeing your data.
- mooneater 15y ago(Golf clap)... and in practice how would one verify such a scheme?
- nl 15y agoWhat do you mean? Verifying that data going across the wire is encrypted is fairly easy to do. You check the data going out is encrypted and that it is encrypted when it comes back. Is that enough verification for you? Depending on how much you trust the vendor you can go further - run it in a debugger and check where it gets the key for example.
- deleted 15y ago[deleted]
- mooneater 15y agoOf course I agree with you, it is possible in theory. I was being cynical about the full picture -- you need to trust the client hardware and its software are completely malware-free. Which... is kinda hard to verify.
- BCM43 15y agoHow do you verify that the key is not being sent over the network by malicious software?
- nl 15y agoHow do you check if any malicious software is doing something? You check what files are being read, and you correlate with network traffic. You lock down access to files like private keys as much as possible to minimize the possibility of this.
- darklajid 15y agoTiny device on your keyring? For example (not affiliated): https://yubico.com/ https://yubico.com/