Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
michwill
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
91.
▲
by
michwill
12y ago
Nope, query logic happens on the client, so server doesn't know the key. Client is the one who records data and indexes encrypted, and who uses indexes from remote.
92.
▲
by
michwill
12y ago
Well, actually the server doesn't know the ordering and how pieces of B-Tree refer to each other, it doesn't even know which data form the index and which are the actual data. Though, observing access patterns, it could probably d
93.
▲
by
michwill
12y ago
Index sizes are pretty similar (consider the same). Having the index end-to-end encrypted imposes some limitations though. You have to do several requests when you want to do one query which is obviously slower. Though, still practical. And
94.
▲
by
michwill
12y ago
Right at the moment, we don't. The prototype is a proof-of-principle. And the first version will probably have index on pre-computed properties used instead of joins. But I think proper joins can be implemented with this idea
95.
▲
by
michwill
12y ago
Well, actually we don't use determenistic encryption, and the server knows nothing about ordering. It merely stores the trees and returns requested pieces (w/o knowing which piece is that or is it a piece of a tree at all). I find
96.
▲
by
michwill
12y ago
> I'm more concerned about the latency Very valid concern. That is the bottleneck, and that was the first thing we've checked. > Isn't a lot of normal db server side operation now a fetch-from-db + do-calculation-on-cli
97.
▲
by
michwill
12y ago
Sure. Will keep in touch!
98.
▲
by
michwill
12y ago
Re-read their paper about mOPE. Very similar indeed. The difference is that in our case the server doesn't know the tree structure, with cryptdb it does.
99.
▲
by
michwill
12y ago
Appications should be architected so that security-critical logic happens on the client. See how Mega and SpiderOak do that. This way, the attacker has to hack every computer of every client instead of one single server. Of course, this req
100.
▲
by
michwill
12y ago
Seems somewhat similar. Though seems like they use deterministic encryption (like AES with same IV), we don't have to do that.
101.
▲
by
michwill
12y ago
Yes, interesting. I wonder how did they implement search over there
102.
▲
by
michwill
12y ago
Ops, I thought I'm responding here. The server actually knows which pieces of B-Trees you access. But no more than that.
103.
▲
by
michwill
12y ago
The server knows which pieces of the trees are you reading. That's all it knows.
104.
▲
by
michwill
12y ago
Seems to be similar to ORAM, that's right. And practical enough to be implemented: fulltext search query to aws takes about 0.5 s (not slowing down when multiple clients do these queries in parallel)
105.
▲
by
michwill
12y ago
Your [pretty long] passphrase can be your key. Or you can take your key file with you. Having the key derived from your password is also possible, but I think not really that secure. SpiderOak and Mega deal with this problem as they have e2
106.
▲
by
michwill
12y ago
We support client-side search, that' the whole point. But we don't even have to download all the index, only log(index_size)
107.
▲
by
michwill
12y ago
Thanks a lot for the hints! :-)
108.
▲
by
michwill
12y ago
You've probably seen CryptDB from MIT. They make it possible to do certain types of queries (range etc) by making security compromises (giving some clues to hack encryption). We don't make such compromises (zero compromises, yes!)
109.
▲
by
michwill
12y ago
To be precise, when you dataset is large, you fetch about log(index_size)
110.
▲
by
michwill
12y ago
No, you don't fetch them all. In fact, we tested search over encrypted archives of linux kernel mailing list w/o downloading that :-)
111.
▲
by
michwill
12y ago
The use-cases could be, for example, payment processors storing customer data, encrypted webmail (where you're able to search w/o downloading all your emails), "encrypted evernote" :-) Yes, it will be open source once av
112.
▲
by
michwill
12y ago
No. It is possible to do it without HE! Full HE is 10^12 slower than normal computations, so impractical yet. In our case, the actual computations are done on the client
113.
▲
by
michwill
12y ago
We will release it open source once it's ready to be used, together with a whitepaper. Which, I hope, will happen pretty soon!
114.
▲
by
michwill
13y ago
Oops, the question wasn't actually formed as a question, so I ask in the comment. Amazon (+Audible) has made it possible to sync audiobooks with ebooks. 24k of "whispersync-capable" books are now available. Does anybody know if they do this
115.
▲
How does Amazon's Whispersync for Voice work?
(amazon.com)
2 points
by
michwill
13y ago
|
1 comments