Can You Trust Your Encrypted Cloud? An Assessment of SpiderOakONE's Security

被引:3
|
作者
Dalskov, Anders P. K. [1 ]
Orlandi, Claudio [1 ]
机构
[1] Aarhus Univ, Aarhus, Denmark
关键词
D O I
10.1145/3196494.3196547
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
This paper presents an independent security review of a popular encrypted cloud storage service (ECS) SpiderOakONE. Contrary to previous work analyzing similar programs, we formally define a minimal security requirements for confidentiality in ECS which takes into account the possibility that the ECS actively turns against its users in an attempt to break the confidentiality of the users' data. Our analysis uncovered several serious issues, which either directly or indirectly damage the confidentiality of a user's files, therefore breaking the claimed Zero- or No -Knowledge property (i.e., the claim that even the ECS itself cannot access the users' data). After responsibly disclosing the issues we found to SpiderOak, most have been fixed.
引用
收藏
页码:343 / 355
页数:13
相关论文
共 50 条
  • [1] A Cloud You Can Trust
    Cachin, Christian
    Schunter, Matthias
    IEEE SPECTRUM, 2011, 48 (12) : 28 - 51
  • [2] Can You Trust Your Trust Measure?
    Chita-Tegmark, Meia
    Law, Theresa
    Rabb, Nicholas
    Scheutz, Matthias
    2021 16TH ACM/IEEE INTERNATIONAL CONFERENCE ON HUMAN-ROBOT INTERACTION, HRI, 2021, : 92 - 100
  • [3] Can You Your Trust Fridge?
    Grau, Alan
    IEEE SPECTRUM, 2015, 52 (03) : 51 - 56
  • [4] Can you trust your data?
    Lackey, J
    QUALITY PROGRESS, 2002, 35 (04) : 128 - 128
  • [5] Can you trust your dentist?
    Grace, M
    BRITISH DENTAL JOURNAL, 1998, 184 (02) : 55 - 55
  • [6] Can you trust your tariff?
    Ashenden, M
    COMMUNICATIONS NEWS, 1998, 35 (09): : 44 - 45
  • [7] Can you trust your journalist?
    Stephen Hancocks
    British Dental Journal, 2005, 198 : 119 - 119
  • [8] Can You Trust Your Robot?
    Hancock, P.
    Billings, D.
    Schaefer, K.
    ERGONOMICS IN DESIGN, 2011, 19 (03) : 24 - 29
  • [9] Can you trust your data?
    Orbaek, P
    TAPSOFT '95: THEORY AND PRACTICE OF SOFTWARE DEVELOPMENT, 1995, 915 : 575 - 589
  • [10] Can you trust your car?
    Berger, I
    IEEE SPECTRUM, 2002, 39 (04) : 40 - +