Member Sign In
Not a member?

A Wired.com user account lets you create, edit and comment on Webmonkey articles. You will also be able to contribute to the Wired How-To Wiki and comment on news stories at Wired.com.


It's fast and free.

Sign in with OpenID
Sign In
Webmonkey is a property of Wired Digital.
processing...
Join Webmonkey

Please send me occasional e-mail updates about new features and special offers from Wired/Webmonkey.
Yes No

Please send occasional e-mail offers from Wired/Webmonkey affiliated web sites and publications, and carefully selected companies.
Yes No

I understand and agree that registration on or use of this site constitutes agreement to Webmonkey's User Agreement and Privacy Policy.
Webmonkey is a property of Wired Digital.
processing...

Retrieve Sign In

Please enter your e-mail address or username below. Your username and password will be sent to the e-mail address you provided us.

or
Webmonkey is a property of Wired Digital.
processing...

Welcome to Webmonkey

A private profile page has been created for you.
As a member of Webmonkey, you can now:
  • edit articles
  • add to the code library
  • design and write a tutorial
  • comment on any Webmonkey article
Close
Webmonkey is a property of Wired Digital.

Sign In Information Sent

An e-mail has been sent to the e-mail address registered in this account.
If you cannot find it in your in-box, please check your bulk or junk folders.
Sign In
Webmonkey is a property of Wired Digital.

Keeping Hosted Data Secure from Its Host

ClipperzAs more and more applications move online, the issue of keeping secret data secret remains important. Lots of attention is paid to keeping third parties from snooping or stealing your hosted data — force SSL for your Gmail connection — but much less attention is paid to keeping data hidden from the host.

Nobody seems to mind Gmail’s bots reading through their email, and it seems to be widely okay that, for the convenience of putting your data on someone else’s server, you trust them to play nice with it.

That seems like a bizarrely trusting security model. It reminds me of the trusting design of SMTP, which worked great at first but, as it turned out, did nothing to inhibit spam. I think distrust should be the default.


When I played around with gmailfs, a clever hack that lets you mount all six-plus gigs of free Gmail storage as a Linux filesystem, I didn’t like the idea of Google having my data. So I wrapped it in encfs, which transparently encrypted everything I put on Google’s servers.

Likewise, when backing up to a third-party host, I use duplicity, which encrypts incremental archives.

Before smart people would consider keeping their password database remotely hosted, they’d want to feel pretty secure. Clipperz, an online password manager, manages that by doing JavaScript encryption, in the browser, so that the host never has the unencrypted data, ever. They can’t use it themselves, they can’t leave it on a bus, and they can’t be subpoenaed for it.

The “zero-knowledge” algorithm and protocol are designed to be fully auditable by the user. Here is a detailed explanation of how it works. The JavaScript crypto library they use is open-licensed and freely available.

I’d love to see that sort of security become standard for any web application that stores user data! Till then, there’s FireGPG.

See Also:

Post Comment Comments Permalink Print
Reddit Digg

 
Subscribe now

Special Offer For Webmonkey Users

WIRED magazine:
The first word on how technology is changing our world.

Subscribe for just $10 a year