10 ms·
Is it worth encrypting?
- thinkxl 4y agoI have a hard time understanding the emojis as measurement units here. If you u se from 1 to 5 I can easily follow, but emojis are abstract and open to different interpretations.
- latexr 4y agoThere are only two emoji in the table: “Neutral Face” and “Face Screaming in Fear”. It’s a rough measurement of feeling, not a detailed pain scale. If it helps, consider (in the “Passwords” line) the leftmost one to be 1 (“meh, don’t really care”) and the rightmost to be 5 (“oh no, huge loss”).
- deleted 4y ago[deleted]
- kerblang 4y agoI would suggest using password-based encryption rather than anything that forces auto-generated keys or what-have-you (like an SSH private key). Can't guarantee you'll always remember that password, but you'll have a fighting chance. And if instead you still insist on using some gibberishy key, more than likely you'll end up using PBE to keep track of it in some sort of repo anyhow, right?
- tristor 4y agoThe answer to every single category is "yes" to whether its worth encrypting. The question isn't whether or not data is worth encrypting, it's whether it's worth encrypting in ways which have worse user ergonomics as a trade-off to potentially better security. There is literally no reason in 2023 why normal users should not have full-disk encryption enabled on every single device and be using a password manager, both tied to on-device secure biometrics (think TouchID).
- c0balt 4y agoThere is a reason to avoid full disk encryption for average, "normal", users: What happens when the user loses/ forgets their password? Most (in my experience) users don't have backups for their devices. Some data, like pictures, are maybe 'backed up" by the cloud provider of their choice via their phones. Further, some users may store important files in multiple places but most don't. And losing data is a real pita.
- andix 4y agoWindows stores the keys inside the cloud by default. This is not optimal, but reduces the lost key scenario a lot. But it also protects the data on a lost laptop, as long as the attacker doesn’t get access to your Microsoft account.
- hsbauauvhabzb 4y agoFirst I’m hearing of this, but I’m unsurprised given how it’s basically impossible to install windows without creating a Microsoft account. I really respect Microsoft core engineers, but wish they’d revolt and quit over the team focused on driving profits via toxic behaviours like online account requirements, and embedding one drive into everything. I even get spam emails *from* Microsoft on newly created corporate o365 accounts, like what the actual fuck is wrong with them to think that’s okay?
- andix 4y agoI think their strategy makes a lot of sense. If you want to live off the grid, you can use Linux. Since everything is now a web app (also Microsoft products), that’s easier then ever.
- hsbauauvhabzb 4y agoSpoken like a true Microsoft marketing department employee two cups deep into the koolaid arrogant enough to think the only two roads are ‘my way or the highway’
- robszumski 4y agoI think a great middle ground for embracing the cloud but retaining control over your data is the ability to bring your own encryption key. This makes it possible for the SaaS to do the thing that you pay them money to do, but retain control if you want to walk away. Plus it guarantees that they are doing some sort of field/row encryption to be able to mix in keys. The crux is that to do BYOK securely, you need guarantees that the key is handled correctly and in an ideal world, some sort of verification. That doesn't mean code auditing by every customer...I favor granting access to a key that can only be released into a secure enclave for sensitive SaaS operations to reside within.
- andix 4y agoYes?
- tptacek 4y agoBut for now, let’s just treat each piece of data as having a single copy that’s encrypted with a single text key No. Let's not. That's not how encryption works. It's barely how encryption worked in the 1990s. The author of this piece has built a disproportionately strong connection in their mental model between ciphertext and some singular key. But we don't need advanced techniques and horcruxes and whatnot to break that link: you can just encrypt the key with another key, or several different keys.
- TheDudeMan 4y agoYep. Another thing the author seems to have missed: You can distribute a key to multiple places in order to trade security for durability.
- forty 4y agoIf they assume they have a magic place to put their unencrypted priceless data which guarantees the data will never be lost, they could simply encrypt everything and put the key in the magic place.
- Spooky23 4y agoI disagree. The author is trying to classify the actual value and sensitivity of data. I don’t agree with all of his assessments, but it’s a thought experiment worth having. Crypto stuff is mostly bread and circus because the key isn’t controlled by the end user, and the end user usually isn’t qualified to handle the key. No commercial B2C service meets the standards required to store truly sensitive data, unless an informed user goes out of their way and has the discipline to do so. Encryption is emphasized because it’s critical to offering services, not because people need it or it does what we think it does. Losing the ability to have removable, storage that’s physically manageable created most of this problem for people, and the industry solved the problem that it created for us. Your medical records 20 years ago only existed in plaintext as paper in a folder in an office. Now they are in a document management system exposed to exponentially more risk. 9/10 times, the most secure backup available to an ordinary person is a USB key placed in a secure place in your home. Criminals can’t get it, and if the police are after you they need a warrant, service of which is known to you, and it easy to make copies, destroy or relocate it.
- bigbezet 4y agoThis is a bit of a non-article. It barely makes any point, and I'm not even sure who the target audience is. > But encryption may not be silver bullet we often treat it as. An encryption algorithm like AES doesn’t know if the file it’s concealing holds a wedding photo, a recipe, or a list of all your passwords. How's that a bad thing?
- deleted 4y ago[deleted]
- _Algernon_ 4y agoIs the author just ignoring the fact that you can (and should!) have multiple encrypted backups, including password protected versions of the encryption key? The entire premise falls apart the moment you assume a reasonable backup strategy.
- crazygringo 4y agoI would guess that less than 1% of the population has multiple encrypted backups, included password protected versions of the encryption key. To some HN'ers what you describe is a "reasonable backup strategy". But to every person I know who doesn't work in tech, what you're describing, not only are they unaware of even these concepts, but they wouldn't have the slightest idea of how to even go about them. Multiple encrypted backups? So if less than 1% of people do something, I don't think it's reasonable to call it reasonable. :)
- tristor 4y ago> I would guess that less than 1% of the population has multiple encrypted backups, included password protected versions of the encryption key. A quick search concludes that while the consumer-focused cloud backup market in the US is only seeing incremental growth (17% CAGR), it currently represents around $15B/yr. [1] If you just do some back of napkin math based on the yearly cost of a Backblaze subscription ($70)[2] you can pretty easily come out with a rough estimate of the amount of devices/users utilizing "encrypted backups" which roughly applies to all major players in the consumer/device cloud backup space. $15B / $70 = 200M devices. The population of the US is ~350M, so roughly 60% of Americans have an "encrypted cloud backup", and I'd say that is actually a /very/ conservative estimate, considering that iOS accounts for 55% of the mobile market share in the US currently and by default enables automated backups to iCloud for connected devices. It also doesn't capture variance in pricing structure, devices that are managed by businesses and have enforced backup policies, and non-cloud based backups (Time Machine, et al). Conservatively though, 2 out of every 3 computing devices (inclusive of tablets and smartphones) you interact with in the wild in the US have "encrypted backups" in addition to whatever default disk encryption is enabled. There's a lot of stuff being slung around in this subthread that makes me think people's mental models are still set in 2008, not in 2023. My 70s parents have full disk encrypted devices which are backed up via encrypted cloud backups and use a password manager, and I've done little to no coaching, because it's the DEFAULT state of many of their devices and heavily encouraged for enablement during onboarding for devices where it is not default. Have you gone through the OOBE on a new Macbook lately? You are encouraged to connect it to your iCloud account, then enable FileVault 2 with a recovery key stored in iCloud, and then to enable iCloud backups. Of course, there's some dark patterns associated due to the revenue model of iCloud for Apple, but it's also something directly beneficial to the end user. [1]: https://www.prnewswire.com/news-releases/cloud-backup-and-recovery-market-size-to-grow-by-usd-14-59-billion--33-of-the-market-growth-to-originate-from-apac--technavio-301556640.html https://www.prnewswire.com/news-releases/cloud-backup-and-re... [2]: https://www.backblaze.com/backup-pricing.html https://www.backblaze.com/backup-pricing.html
- Animats 4y agoWhat is that emoji? Person wearing headphones? (Emoji won't go through HN's system.)
- AtlasBarfed 4y agoSuper-good encryption seems to be something that is overkill. Obviously, a general flawed encryption scheme isn't good, hackers and states will collect it like crazy. I think what I'd like is a toolkit for DIY encryption that I could break it if I had to, that I accept that if someone smart SPECIFICALLY targets me they can break it with effort, but the general dragnets/sweeps won't work on. If the government wants the info, they can assign some cryptographer who can break it in a day or two on a single machine if they put eyes on it. Like here might be my personal encryption: Take some encryption scheme that can be cracked in a day (low bitrate DES or something) on a server. That I know how to break myself. Then maybe some one-off swap of the bit order or something that can be cracked if a human looks at it, but is so one-off that governments or crackers need to SPECIFICALLY target something. One of the things that would be great would obviously be hiding it in images and the like. There isn't a lot of guidance on this. IMO it's obviously better than unencrypted, and works in a lot of situations where X person is died, inheritor want to get to their Bitcoins but doesn't have the key. Inheritor knows from will to try X Y and Z to break it. So we either have AES-256, or you write your passwords on a paper in a safe deposit box. Can we have some guidance on options in the middle?
- giantrobot 4y agoKeep your keys in your physical wallet. You spend a lot of time managing your wallet and keeping it secure. You've also got strong legal protections over possessions on your person vs stored by a third party.
- paulpauper 4y agoYour encrypt something on your desktop and you leave the key on the same computer. the hacker simply steals both the file an the key and decrypts it. This explains a lot of encryption failures.
- gmoore 4y agoIf the data is important enough to you - can't you just guard against losing the key? write it down - put it in a saftey deposit box or something similar. Framing the choice around an inevitable loss of key seems unecessary to me.
- akerl_ 4y agoThere’s a lot of other things that are interesting about the article, but I’m personally intrigued by the idea that SSNs exist here at all, and are categorized in the way that they are. The social security numbers of a decent percentage of the population have already been leaked and are fully compromised, and the multitude of places that a person needs to provide the SSN means for everybody else, they’re about as secret as their checking account number.
- deafpolygon 4y agoNot to mention that the only place in the world that uses SSN is the US. Other places have a similar identification number scheme, but are not private or secret.
- deafpolygon 4y agoEverything is worth encrypting by default. It's the digital equivalent of putting a lock on your front door. In addition to having passwords (pass phrases), have multiple keys. Store master keys (for sets of disks) in a fireproof lockbox on a usb stick, refreshed occasionally. Store it in some secure third location. It's like having the key to your storage box or your house. Encryption doesn't prevent someone from absconding with your data on the web- it prevents someone with physical access from taking off with your data. Have multiple copies on different key chains. If it works in the real world, it works here just the same.
- hilbert42 4y agoI rarely encrypt my files because it's usually much easier to recover data from crashes, stuffed disks etc. when data isn't encrypted. Simlpy, encrypted gobbledygook cannot be easily sorted out from random data, coherent data—even when broken into small chunks—is more recognizable than broken encrypted bits. The most annoying aspect of many encryption programs is that they are not specified for recovery in cases when the encrypted data stream become broken. For example, you've a hard disk failure where a certain percentage of the sectors on the disk are irrecoverable then the question of how well the encryption program can recover the remaining data becomes important. In my experience, recovering the remaining data from the remanents of the encrypted data is essentially nigh on impossible. My rule is to not encrypt unless I've guaranteed multiple backups. I've often wondered why more attention isn't paid to this problem.