3 ms·
The site says "We currently do not offer private key encryption," and adds "You are giving the key to those intrusted (the online Backup provider) with encrypti
by rg 17y ago
The site says "We currently do not offer private key encryption," and adds "You are giving the key to those intrusted (the online Backup provider) with encrypting and storing your data."
But it isn't true that online backup requires giving the key to the backup provider.
There are two main security models: (1) All data is encrypted on the user's machine with a password known ONLY to the user that never leaves the user's machine, and the encrypted data is transmitted and written to backup exactly that way; on restores, the encrypted data is returned and then decrypted on the user's machine (Connected Online Backup from Iron Mountain and some ways of using JungleDisk work this way). Or (2) the data is transmitted securely, decrypted at the backup server, encrypted there with a key known to the backup service and saved; on restores, the data is decrypted at the backup server using the service's key, then returned securely to the user's machine (most other online backup services work this way).
The second model is, as you say, insecure--which is why it is a big competitive disadvantage.
The first model can be smart, of course, and employ the user's private encryption key which never leaves the client PC only for personal files, and use some other method on Windows system files, commercial application executables, and other files which are duplicated on millions of machines (identified on the client before encryption).
FWIW, Connected Online Backup does both incremental backups by changed file blocks and also does identification of files it already has seen and so doesn't need to send again (at all), while keeping the encryption key only on the client PC. You're right about the current price--Connected wants $995/yr for 50GB. Obviously that price level can't last much longer.
- viper 17y agoDo you know it doesn't leave the users machine? (I'm not asking that to be smart or anything.) My point is that you are trusting the backup providers that it doesn't. My main point is that you are trying to protect your data from the backup providers or their sloppy security. You aren't trusting them on one hand yet trusting them on the other that they don't store or save the key on their servers. One popular online backup product can recover the key if you use their generated key. Which of course means they store it on their servers. Honestly implementing private key encryption is trivial. My hesitation is that it only adds a level of security if the backup providers are trustworthy. The lack of trust of the backup providers is kind of why it is there. Here is the scenario I envisioned that made me question it. Let's say client X performs backups of their computer using service Y. Service Y provides private key encryption. Client X types in his secret phrase and thinks that his/her data is secure. Service Y must either require the secret phrase to be typed in each time the software is run or must store the key locally. They store it locally. Someone comes with a court order demanding every reasonable effort to release the data to the court. Service Y may WANT to comply to catch bad guy client X. Or they may just not want to be held in contempt of court and get fined etc. Can they reasonably recover the key? My answer is yes service Y can reasonably recover the key. I don't believe the answer is yes if it is encrypted with a third party tool. There are of course holes in the above scenario. You might need to automatically update the software to upload the key for that user etc. Perhaps they don't do automatic updates. They could also require an update just for that users account to function. My main point again is you are back to trusting the backup provider. I found it highly ironic to be writing code to protect my potential customers to gain their trust without disclosing the inherent holes in that process. My hesitation to adding private key encryption was purely on the side of NOT wanting to pretend that backup software with private key encryption protects their data against all scenarios. But having written this post and explaining it frequently. I think I probably should just add it in. Thanks, Rasch
- viper 17y agoOne more thought on a very high level. I thought, what would I want to be told if I was the customer? 1) The truth that there are holes in the process and here is a better solution if you need it. or 2) That it is super secure unbreakable private key encryption. I chose "1". I'll still stick to the story line but I will implement it in the next release.
- rg 17y agoWell, FWIW, I backup my machine every night via both of Connected Online Backup ($995/yr) and JungleDisk, (about $350 a year to Amazon) and I won't use any of their competitors who can recover their own keys--so the story of enhanced security sells me. (I do trust these vendors not to transmit my password from their client applications to their servers, that's easy; I don't trust them to secure my unencrypted data on lots of machines for decades, that's much harder.)
- CRASCH 17y agoFair enough and more than enough justification for me to implement it. BTW I really appreciate taking the time to share your point of view.