3 ms·
Do you know it doesn't leave the users machine? (I'm not asking that to be smart or anything.) My point is that you are trusting the backup providers that it d
by viper 17y ago
Do you know it doesn't leave the users machine?
(I'm not asking that to be smart or anything.)
My point is that you are trusting the backup providers that it doesn't.
My main point is that you are trying to protect your data from the backup providers or their sloppy security. You aren't trusting them on one hand yet trusting them on the other that they don't store or save the key on their servers.
One popular online backup product can recover the key if you use their generated key. Which of course means they store it on their servers.
Honestly implementing private key encryption is trivial. My hesitation is that it only adds a level of security if the backup providers are trustworthy. The lack of trust of the backup providers is kind of why it is there.
Here is the scenario I envisioned that made me question it.
Let's say client X performs backups of their computer using service Y.
Service Y provides private key encryption. Client X types in his secret phrase and thinks that his/her data is secure.
Service Y must either require the secret phrase to be typed in each time the software is run or must store the key locally. They store it locally.
Someone comes with a court order demanding every reasonable effort to release the data to the court. Service Y may WANT to comply to catch bad guy client X. Or they may just not want to be held in contempt of court and get fined etc. Can they reasonably recover the key? My answer is yes service Y can reasonably recover the key. I don't believe the answer is yes if it is encrypted with a third party tool.
There are of course holes in the above scenario. You might need to automatically update the software to upload the key for that user etc. Perhaps they don't do automatic updates. They could also require an update just for that users account to function. My main point again is you are back to trusting the backup provider.
I found it highly ironic to be writing code to protect my potential customers to gain their trust without disclosing the inherent holes in that process.
My hesitation to adding private key encryption was purely on the side of NOT wanting to pretend that backup software with private key encryption protects their data against all scenarios.
But having written this post and explaining it frequently. I think I probably should just add it in.
Thanks,
Rasch
- viper 17y agoOne more thought on a very high level. I thought, what would I want to be told if I was the customer? 1) The truth that there are holes in the process and here is a better solution if you need it. or 2) That it is super secure unbreakable private key encryption. I chose "1". I'll still stick to the story line but I will implement it in the next release.
- rg 17y agoWell, FWIW, I backup my machine every night via both of Connected Online Backup ($995/yr) and JungleDisk, (about $350 a year to Amazon) and I won't use any of their competitors who can recover their own keys--so the story of enhanced security sells me. (I do trust these vendors not to transmit my password from their client applications to their servers, that's easy; I don't trust them to secure my unencrypted data on lots of machines for decades, that's much harder.)
- CRASCH 17y agoFair enough and more than enough justification for me to implement it. BTW I really appreciate taking the time to share your point of view.