Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?
Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?
No, because cloud providers are one subpeona, court order or warrant away from surveillance and exfiltration of your data without your knowledge.
If the DHS deems you a threat, then all proceedings can happen through secret courts and you'll be none the wiser to it happening, and you'll get a gag order on top of it.
If that public Cloud is from an American company: obviously no. And whether you prefer some Chinese intelligence service having access to your data probably depends on what you want to do.
Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law.
1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc.
2. They might hand over your data in response to warrant, but their systems are designed to prevent covert extraction of data. The company should have a track-record of pushing back against overly broad warrants.
But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you if you can control its network traffic and construct crypt generation from basic arithmetic functions of the system in question.
Example of shared hosting providers not patching postfix fast enough or having a support person that chmodded the wrong thing on shared hosting server, customer with old wordpress install that was exploited to drop a webshell, etc.
> But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you
Do you have any references? I'd like to read more.
If this were generally true, attempts to make trusted enclaves like Intel SGX (though flawed) would not need to exist.