ZeroDB (YC S16) Provides Security for Enterprise Big Data in the Cloud
themacro.com
themacro.com
https://arxiv.org/pdf/1602.07168v3.pdf
@ ZeroDB developers
I know the goal is to have the cloud provider untrusted in this model for storage/processing. However, have you considered them actively malicious in how they handle the protocol steps with the on-site client? As in, at each step (eg a query), they might try to attack the protocol or especially the implementation (a la OpenSSL infamy). Just make sure you have defenses for that sort of thing.
But as MacLane pointed out in another comment this is only the case for the standalone database described in the ArXiv paper. The Hadoop scheme works quite differently
I guess mysql is a legacy database, now. Someone should let all the committers know that they should transition to support roles and stop new feature development. Hadoop is the future of sql.
/s/legacy/structured
However, it is not the case for our Hadoop scheme (nor our future support for structured database). In these cases, there is no round-tripping required. In fact, it's significantly more performant than existing Transparent Data Encryption in Hadoop, from both a latency and key rotation perspective.
We'll likely release a paper describing this new scheme later in the year as well as publish at some conferences.
We avoid doing that because of questionable security of such method. Also we tend to publish what we do (stay tuned for Hadoop paper :-)
What's your expansion strategy for Oracle/DB2/MySQL?
- michael scott
random ex: https://docs.mongodb.com/manual/core/security-encryption-at-...
Which is more secure? Does zeroDb use non deterministic encryption?
But yeah, good point
p.s. if you change it to 0db perhaps you might be listed before any "a" company? Not sure if numbers precede letters in those lists.