Severe flaws in E2EE cloud storage platforms used by millions (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 22 Oct 11:44
https://sh.itjust.works/post/26995582

#cybersecurity

threaded - newest

MostlyBlindGamer@rblind.com on 22 Oct 12:41 next collapse

Cryptographic analysis from ETH Zurich researchers Jonas Hofmann and Kien Tuong Turong revealed issue with Sync, pCloud, Icedrive, Seafile, and Tresorit services, collectively used by more than 22 million people. The analysis was based on the threat model of an attacker controlling a malicious server that can read, modify, and inject data at will, which is realistic for nation-state actors and sophisticated hackers.

Interesting stuff, but it’s worth noting the scope and circumstances.

synapse1278@lemmy.world on 22 Oct 15:40 collapse

Encrypt first, then upload. Of course, not always easily applicable.