Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Cloud Encryption Security

Researchers Discover Flaws In 5 End-to-End Encrypted Cloud Services (scworld.com) 10

SC World reports: Several major end-to-end encrypted cloud storage services contain cryptographic flaws that could lead to loss of confidentiality, file tampering, file injection and more, researchers from ETH Zurich said in a paper published this month.

The five cloud services studied offer end-to-end encryption (E2EE), intended to ensure files can not be read or edited by anyone other than the uploader, meaning not even the cloud storage provider can access the files. However, ETH Zurich researchers Jonas Hofmann and Kien Tuong Truong, who presented their findings at the ACM Conference on Computer and Communications Security (CCS) last week, found serious flaws in four out of the five services that could effectively bypass the security benefits provided by E2EE by enabling an attacker who managed to compromise a cloud server to access, tamper with or inject files.

The E2EE cloud storage services studied were Sync, pCloud, Seafile, Icedrive and Tresorit, which have a collective total of about 22 million users. Tresorit had the fewest vulnerabilities, which could enable some metadata tampering and use of non-authentic keys when sharing files. The other four services were found to have more severe flaws posing a greater risk to file confidentiality and integrity.

BleepingComputer reports that Sync is "fast-tracking fixes," while Seafile "promised to patch the protocol downgrade problem on a future upgrade." And SC World does note that all 10 of the tested exploits "would require the attacker to have already gained control of a server with the ability to read, modify and inject data.

"The authors wrote that they consider this to be a realistic threat model for E2EE services, as these services are meant to protect files even if such a compromise was to occur."

Thanks to Slashdot reader spatwei for sharing the article.

Researchers Discover Flaws In 5 End-to-End Encrypted Cloud Services

Comments Filter:
  • They have proven time and again that they are not trustworthy. This is just one more example. At the very least get the encryption from somebody else.

    • by AmiMoJo ( 196126 )

      Only use cloud services where you do the encryption with your own tools on your end. Don't rely on their client.

      That's why E2E cloud is worthless. If you don't control the client you can't trust it.

      • by gweihir ( 88907 )

        Exactly. State-sponsored attacks (may be your own state) and corporate greed will ensure a massive conflict of interest if the cloud providers themselves get to "secure" the cloud.

    • So you believe that on-prem systems *are* trustworthy? How many on-prem systems truly put the necessary money and effort to make their systems secure? Not many.

      Cloud is not easier to compromise than on-prem systems, IF the on-prem system is connected to the internet. And just about all of them are.

      I'd say, don't trust any system that is *connected to the internet.*

  • by Anonymous Coward
    is that said cloud service provider unexpectedly shuts down in the middle of the night.
  • Now their playing the dead fish when they're exposed
  • “The vulnerabilities .. affect multiple providers in the same way, revealing common failure patterns in independent cryptographic designs.”

Been Transferred Lately?

Working...