D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OT: Crypto schmypto

 

On Sun, 1 Sep 2013, Phil Hudson wrote:

AFAICT what they're announcing is effectively a no-op from a security POV. What's the crypto equivalent of "greenwash"? Or am I being too harsh on Google?

http://googlecloudplatform.blogspot.co.uk/2013/08/google-cloud-storage-now-provides.html

That's how I read it too.

It protects your data in case Google's disks are stolen. Or taken away by the NSA.

It doesn't prevent the NSA from demanding the keys - which Google stores. Nor does it prevent Google from reading your data.

If you want the data to be stored securely, you should encrypt it locally.

There's probably an attack vector, other than the disks being taken away, that I've not thought of that this protects you against. But it doesn't protect you against the most 'attacks' that most people are worried about these days.

Martijn.


--
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq