3 ms·
"I will not store sensitive data in plain text" By this logic, Gmail would need to encrypt the contents of every email and every attachment, then encyrpt the f
by mapgrep 14y ago
"I will not store sensitive data in plain text"
By this logic, Gmail would need to encrypt the contents of every email and every attachment, then encyrpt the full-text indexes of those emails and attachments. Obviously my contacts should be encrypted too. Then they'd need to encrypt the names of all labels/tags, which can contain sensitive information. Then they'd need to encrypt their logs, since when I visit the service and from where is actually sometimes sensitive info.
This is basically endless. It's impossible to accurately asses the bounds of what an arbitrary user will consider sensitive. The core is reasonably easy -- passwords, CC numbers -- but there can be hugely sensitive data at the edges.
My favorite example of this at the moment is 1Password. 1Password does a very thorough job of encrypting their passwords file. You can go read a whole blog post and white paper they wrote on their keychain format. But it turns out (as I and others have raised in their forums) there is a cache they create in the clear in the filesystem where the cache files are named after the websites where you have an account and have recently visited.
Now MANY people will not consider this sensitive data. But some people will. The passwords are not leaking, but the names of sites where I have accounts IS leaking. No problem, unless you have an account at donkey-fetish-dot-xxx your partner doesn't know about or whatever. The guys who designed 1Password clearly didn't think this issue would come up because, to their credit, they probably don't spend a lot of time on sites like private-pirated-movie-trove-dot-info. Or they don't have spouses/bosses who know where to look for these cache files.
Anyway, this is a long way of saying that you'll go crazy trying to encrypt all sensitive info. I think the 1Password case is clear cut but, judging by the response from their support, they did not. You might think a users' bookmark tag is not sensitive info, but if it's named 'job-hunt' or 'divorce-lawyers' it probably is. In the end, everything is sensitive info to someone.
- tptacek 14y agoParticularly with web apps, this "encrypt all the sensitive data" stuff is usually masturbatory. If it's data your application needs to function, the server needs ready access either to the key, or at least to some online oracle that provides access to the data. So you end up with these silly systems that encrypt data under AES keys stored, at best, on the filesystem. "Encrypt all data" is something that sounds good in a message board thread, but really doesn't do much to shield you from the fact that to be secure, you just have to flush all the bugs out of your application.
- rickette 14y agoHow about storing the AES key in a HSM (Hardware Security Module) instead of a filesystem?
- gcr 14y agoDoes anyone else here in fact wish for gmail to do that?
- deleted 14y ago[deleted]