3 ms·
We've built a prototype that does this: https://cloudsweeper.cs.uic.edu/ https://cloudsweeper.cs.uic.edu/. It works for gmail only, doesn't require full account
by waitwhatwhoa 13y ago
We've built a prototype that does this: https://cloudsweeper.cs.uic.edu/ https://cloudsweeper.cs.uic.edu/. It works for gmail only, doesn't require full account access, and is completely server side.
Currently we only search for and redact/encrypt plaintext passwords, but the same workflow can work for whatever the user might decide to encrypt.
We get around the javascript cryptography issue by performing encryption server side. Very unintuitive for a privacy primitive, but our goals are (a) security at rest and (b) providing an improvement over what already exists (plaintext storage everywhere).
Our other design decision is to only encrypt the (as identified by the user) important passages. This allows server side search to (usually) still work which is nice. We're currently exploring other methods for identifying "lucrative" information in someone's cloud based data store.
I talked to Eric Grosse, VP Security @ Google, about trying to get a definite time limit on how long it takes for "old" versions of stored messages to no longer be accessible by Google. While there is a FAQ that states that old messages cannot be undeleted after 30 days (can't find the link right now), he wouldn't give me a straight answer for when the old email blobs are no longer accessible. It's anyone's guess regarding what the absolute security is here; regardless, for a non-state attacker, it's Probably Good Enough.
(please don't post this link to the front page, it's not currently engineered to handle HN style loads)