Mylar: A platform for building secure web applications
css.csail.mit.edu
css.csail.mit.edu
* https://crypton.io/ a zero-knowledge web framework from SpiderOak
* http://hails.scs.stanford.edu/ a secure web platform framework for untrusted 3rd party plugins
Mylar protects data confidentiality even when an attacker gets full access to servers. Mylar stores only encrypted data on the server, and decrypts data only in users' browsers. Simply encrypting each user's data with a user key does not suffice, and Mylar addresses three challenges in making this approach work.
First, Mylar allows the server to perform keyword search over encrypted documents, even if the documents are encrypted with different keys. Second, Mylar allows users to share keys and data securely in the presence of an active adversary. Finally, Mylar ensures that client-side application code is authentic, even if the server is malicious.
I wonder if we're only a few years away where technologies and practices like this become standard?
For 90% of web use cases, encryption like this is overkill. Serving a blog or static page does not require this level of security, and most e-commerce redirects to a handful of payments providers.
Businesses that store your data would likely have to stop being predicated on the ability to mine your data.
For a specific example, see Section 8 of the paper (Building a Mylar Application) which starts with "To demonstrate how a developer can build a Mylar application, we show the changes that we made to the kChat application to encrypt messages."
Other than having a GUI and nice web interface, what are the advantages of Github over the git repo Mylar is using?
I don't expect other people in the research group to catch all of those types of errors, so a more openly collaborative environment would be an improvement. (I doubt R&R would set up an account for the UMass grad student who caught their error. The attempted replication that took him a month would have been much simpler if he could have git-cloned.) It doesn't have to be Github: Bitbucket would be fine. Even an academics-only or field-focused equivalent would get most of the way there, although it would exclude most interaction with the interested amateur public. Especially for those whose field is computer science, "maintaining" a Github account doesn't seem onerous.
I thought some big tech corporation owned the patent on that.
"Multi-Key Searchable Encryption - Raluca Ada Popa and Nickolai Zeldovich"