Even the most goodhearted and the most talented teams can't reliably defend against a massively funded adversary.
Secrets are for keeping, not sharing.
Even the most goodhearted and the most talented teams can't reliably defend against a massively funded adversary.
Secrets are for keeping, not sharing.
I don't believe that's true.
1. Google (and others?) is already aggressively increasing the amount of encryption it does on traffic between its datacenters. So they have been addressing this problem before it was even brought to light.
2. We easily have the encryption abilities to do many more things than we do with secure cloud data; we'd just have to pay more for it. For instance, I can encrypt everything the minute it leaves my laptop, store it in the cloud, and not decrypt until it hits my laptop again. Nobody but me ever gets the secret key (heck, it could be a one-time-pad and thus unbreakable). If I trust the cloud computers themselves, then I can store different secret keys on each and use strong public-key encryption to protect all traffic between different machines in the cloud, and between my machine. Breaking the system requires compromising a machine, and even then you only get the key for that machine.
3. In theory, fully homomorphic encryption could allow the best of both worlds above. I completely encrypt my data on my machine --- nobody else has the key --- then send it into the cloud where cloud companies can do operations for me like searching, sorting, filtering, etc, all without ever decrypting the data or learning what it is. They send me back the results (securely), then I decrypt. Of course, right now this would be massively slow and expensive, but progress is being made.
Naturally all of the above are subject to the "5-dollar wrench" rule or the "secret court/FISA/warrants" rule. You cannot protect your data from the people making a law that says "give up your data". But it is technologically possible and even feasible to secure data from the NSA's snooping. The tradeoff is cost and time.
And homomorphic encryption is still far from being practical.
Can you explain this to me? I don't understand how you can search encrypted data.
The idea is this: I encrypt my data and give it to the cloud. I also encrypt the algorithm I want the cloud to use. In this case, it could be a search algorithm with the search query hardcoded. Right now, it would have to be encoded as a circuit and then encrpyted from there into a different circuit.
The cloud runs my encrypted data through this "transformed" circuit, yielding some encrypted output. The cloud tells me the output. I then decrypt it with my original key.
It's crazy that this works (longstanding open problem solved in 2005 or 06 I think). The name "homomorphic" comes from functions f, like homomorphisms, in which "order doesn't matter":
f(data) = f(Decrypt(Encrypt(data))) = Decrypt(f(Encrypt(data))).
Hope that makes some sense.If the NSA wanted your data, they could get into your network probably easier than they could get into Google's networks. Companies like Google have way smarter people (and working full time) securing data than most businesses.
For us to secure our networks as much as someone like Google would, we'd have to have a team of the best hackers around.
And by definition, the best hackers around are scarce. They're already working for Google, etc, and X Y Z security company.
While it's possible that the NSA has a system to automatically detect and wiretap hosts and private networks connected to the internet, it seems unlikely to not have been detected so far. I've taken to assuming that every packet send and received from my servers is being monitored, but that, barring specific interest in me by the NSA, the servers themselves are reasonably private.
Plus, in the world of "I can sift through terabytes of data in seconds" even a little lagoon isn't too little.
I know some of the people in the security team and they are pretty good, but arrogance will be their undoing.
Google has an internal team called the Orange Team that performs security audits and, so far, they have always been successful in penetrating Google's network. If they can, what makes you think the NSA hasn't done that already?
And the NSA, apparently.